Breaking free from the chains of fate - Bypassing AWSCompromisedKeyQuarantineV2 Policy
ID: 185b784a-3940-5c1d-9aa5-66bcf1ae2c5e
STIX ID: report--185b784a-3940-5c1d-9aa5-66bcf1ae2c5e
Feed Name: Cloud Chronicles
Permiso analyzed AWS's AWSCompromisedKeyQuarantineV2 quarantine policy and identified numerous bypasses that allow attackers with leaked credentials to enumerate IAM/EC2/S3, exfiltrate secrets, escalate privileges via roles, Lambda, Glue, SageMaker and other services, and perform disruptive actions (SSM commands, stop/terminate instances, invoke/delete Lambdas, tamper with GuardDuty/CloudTrail). The report includes a detection set and an open-source tool (DetentionDodger) to find leaked identities and failed quarantine attachments, and notes AWS released policy updates (v3) to address many, but not all, of the findings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
