AWS: Assuming Access Key Compromise
ID: 23f1551d-f0bc-5be1-bd5f-d0d5e310ae4b
STIX ID: report--23f1551d-f0bc-5be1-bd5f-d0d5e310ae4b
Feed Name: Black Hills Infosec Blog
Threat Score
This Black Hills InfoSec blog demonstrates using Carnal0wnage's weirdAAL toolkit to audit privileges tied to stolen AWS credentials recovered from a compromised domain user; the walkthrough shows the account lacked IAM/root rights but had EC2 and other service access, illustrating how exposed keys can enable cloud reconnaissance and potential misuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
