dAWShund - framework to put a leash on naughty AWS permissions
ID: 2961cb7f-5fe5-534a-b4a1-8ea4cccd2989
STIX ID: report--2961cb7f-5fe5-534a-b4a1-8ea4cccd2989
Feed Name: FalconForce
This blog describes dAWShund, a year-long research framework that enumerates AWS IAM principals and resource policies (via sAWSage), evaluates effective permissions using AWS SimulatePrincipalPolicy (Gerakina), and consolidates allow permissions into Neo4j for analysis (dAWShund). It explains policy types, enumeration strategies, operational considerations, and provides usage examples and Cypher queries, noting the potential for misuse by threat actors while positioning the toolkit primarily as a blue-team research aid.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
