logo

dAWShund - framework to put a leash on naughty AWS permissions

ID: 3c116c3e-4e37-5e1f-bfb8-16c6c0204415

STIX ID: report--3c116c3e-4e37-5e1f-bfb8-16c6c0204415

Feed Name: FalconForce

Date Published: 2025-04-11

Date Updated: 2026-04-27

Author: Nikos Mantas

...
...

This report presents dAWShund, a blue-team-oriented framework that enumerates AWS IAM identity and resource policies (sAWSage), evaluates effective permissions using AWS’s SimulatePrincipalPolicy API (Gerakina), and maps allowed relationships into Neo4j/BloodHound (dAWShund) for analysis; it explains AWS policy types, data collection tradeoffs, and provides example Cypher queries to identify risky configurations, highlighting how built-in AWS capabilities can expose misconfigurations while aiding defenders and red teams.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.