Non-Production Endpoints as an Attack Surface in AWS
ID: de81c072-034f-51a1-8f23-ced03c3832f8
STIX ID: report--de81c072-034f-51a1-8f23-ced03c3832f8
Feed Name: Datadog Security Labs
This Datadog Security Research blog documents how thousands of undocumented or non-production AWS API endpoints can be abused for defense evasion: some endpoints do not log to CloudTrail (allowing silent permission enumeration), some access account-level data while being isolated from production resources, and some cause CloudTrail events to show non-standard event sources or partially omit the invoked action. The authors describe discovery at scale using Certificate Transparency and automated fingerprinting, provide multiple proof-of-concept examples (ECR, Cost Explorer, Route53 Resolver, IVS), and disclose that AWS has remediated specific reported endpoints while encouraging further responsible disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
