logo

FalconFriday — Detecting enumeration in AWS — 0xFF25 OrangeCon 25 Edition

ID: 52706051-ed06-55c7-b341-8e809341032f

STIX ID: report--52706051-ed06-55c7-b341-8e809341032f

Feed Name: FalconForce

Threat Score
40/100

Date Published: 2025-09-19

Date Updated: 2026-06-15

Author: Nikos Mantas

...
...

This FalconFriday blog explains how attackers can leverage the AWS IAM Policy Simulator (via console or the SimulatePrincipalPolicy/SimulateCustomPolicy APIs) and AWS-native tools (Credential Report, Access Analyzer) to enumerate permissions and find escalation paths, describes unique CloudTrail footprints left by such simulation activity, and provides detection guidance and KQL hunting queries to identify misuse and related reconnaissance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.