AWS Account ID and IAM Discovery
Techniques for enumerating AWS Account IDs and IAM principals using unauthenticated and authenticated methods to map cloud identity attack surface.
HackIndex
Language
AWS recon covering S3, IAM, CloudFront, and asset exposure mapping
Techniques for enumerating AWS Account IDs and IAM principals using unauthenticated and authenticated methods to map cloud identity attack surface.
Identify and enumerate publicly exposed AWS assets including S3 buckets, EC2 instances, APIs, and misconfigured IAM policies to map an organisation's attack surface.
Enumerate AWS Route53 DNS records and CloudFront distributions to map target infrastructure, identify origins, uncover misconfigurations, and expose hidden endpoints.
Techniques for discovering exposed AWS S3 buckets through permutation, DNS enumeration, and metadata analysis to identify misconfigured storage assets.
Guides covering AWS service enum across IAM, EC2, S3, and more
Enumerate AWS CloudFormation stacks, resources, outputs, and parameters to map infrastructure, expose sensitive configs, and identify attack paths.
Techniques for enumerating AWS Cognito User Pools and Identity Pools, uncovering misconfigured auth flows, exposed pool IDs, and unauthenticated access risks.
Enumerate AWS EC2 instances and security groups using CLI and SDK techniques to map attack surface, expose misconfigurations, and identify lateral movement opportunities.
Covers cred types, tool install, and CLI config for AWS pentests
Covers AWS credential types (keys, IAM roles, env vars) and the resolution chain order used by SDKs and CLI to authenticate requests.
Covers AWS pentesting environment setup, including tool installation, credential configuration, IAM permissions, and CLI/SDK preparation for cloud security assessments.
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.