logo

dAWShund - framework to put a leash on naughty AWS permissions

ID: 2961cb7f-5fe5-534a-b4a1-8ea4cccd2989

STIX ID: report--2961cb7f-5fe5-534a-b4a1-8ea4cccd2989

Feed Name: FalconForce

Threat Score
50/100

Date Published: 2025-04-11

Date Updated: 2026-06-15

Author: Nikos Mantas

...
...

This blog describes dAWShund, a year-long research framework that enumerates AWS IAM principals and resource policies (via sAWSage), evaluates effective permissions using AWS SimulatePrincipalPolicy (Gerakina), and consolidates allow permissions into Neo4j for analysis (dAWShund). It explains policy types, enumeration strategies, operational considerations, and provides usage examples and Cypher queries, noting the potential for misuse by threat actors while positioning the toolkit primarily as a blue-team research aid.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.