Pacu is an open-source AWS exploitation framework. The tool is written in Python and publicly available on GitHub.
| Technique | Procedure example |
|---|---|
| T1049 System Network Connections Discovery |
Once inside a Virtual Private Cloud, Pacu can attempt to identify DirectConnect, VPN, or VPC Peering. |
| T1059.009 Cloud API |
Pacu leverages the AWS CLI for its operations. |
| T1069.003 Cloud Groups |
Pacu can enumerate IAM permissions. |
| T1078.004 Cloud Accounts |
Pacu leverages valid cloud accounts to perform most of its operations. |
| T1087.004 Cloud Account |
Pacu can enumerate IAM users, roles, and groups. |
| T1098.001 Additional Cloud Credentials |
Pacu can generate SSH and API keys for AWS infrastructure and additional API keys for other IAM users. |
| T1119 Automated Collection |
Pacu can automatically collect data, such as CloudFormation templates, EC2 user data, AWS Inspector reports, and IAM credential reports. |
| T1518.001 Security Software Discovery |
Pacu can enumerate AWS security services, including WAF rules and GuardDuty detectors. |
| T1526 Cloud Service Discovery |
Pacu can enumerate AWS services, such as CloudTrail and CloudWatch. |
| T1530 Data from Cloud Storage |
Pacu can enumerate and download files stored in AWS storage services, such as S3 buckets. |
| T1546 Event Triggered Execution |
Pacu can set up S3 bucket notifications to trigger a malicious Lambda function when a CloudFormation template is uploaded to the bucket. It can also create Lambda functions that trigger upon the creation of users, roles, and groups. |
| T1552 Unsecured Credentials |
Pacu can search for sensitive data: for example, in Code Build environment variables, EC2 user data, and Cloud Formation templates. |
| T1555.006 Cloud Secrets Management Stores |
Pacu can retrieve secrets from the AWS Secrets Manager via the enum_secrets module. |
| T1578.001 Create Snapshot |
Pacu can create snapshots of EBS volumes and RDS instances. |
| T1580 Cloud Infrastructure Discovery |
Pacu can enumerate AWS infrastructure, such as EC2 instances. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.