Skip to content
Back to skills

Aws Penetration Testing

ASecurity

This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.

  • 508 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 7, 2026
developmentpythonawstestinggitsecurity

Works with

  • cli

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 17 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add Dokhacgiakhoa/antigravity-ide --skill aws-penetration-testing --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Aws Penetration Testing?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Aws Penetration Testing
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dokhacgiakhoa-aws-penetration-testing/badge)](https://www.skillsdirectory.com/skills/dokhacgiakhoa-aws-penetration-testing)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: AWS Penetration Testing
description: This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.
metadata:
  author: zebbern
  version: 4.1.0-fractal
---

# AWS Penetration Testing

## Purpose

Provide comprehensive techniques for penetration testing AWS cloud environments. Covers IAM enumeration, privilege escalation, SSRF to metadata endpoint, S3 bucket exploitation, Lambda code extraction, and persistence techniques for red team operations.

## Inputs/Prerequisites

- AWS CLI configured with credentials
- Valid AWS credentials (even low-privilege)
- Understanding of AWS IAM model
- Python 3, boto3 library
- Tools: Pacu, Prowler, ScoutSuite, SkyArk

## Outputs/Deliverables

- IAM privilege escalation paths
- Extracted credentials and secrets
- Compromised EC2/Lambda/S3 resources
- Persistence mechanisms
- Security audit findings

---

## Essential Tools

| Tool | Purpose | Installation |
|------|---------|--------------|
| Pacu | AWS exploitation framework | `git clone https://github.com/RhinoSecurityLabs/pacu` |
| SkyArk | Shadow Admin discovery | `Import-Module .\SkyArk.ps1` |
| Prowler | Security auditing | `pip install prowler` |
| ScoutSuite | Multi-cloud auditing | `pip install scoutsuite` |
| enumerate-iam | Permission enumeration | `git clone https://github.com/andresriancho/enumerate-iam` |
| Principal Mapper | IAM analysis | `pip install principalmapper` |

---

## Core Workflow

## 🧠 Knowledge Modules (Fractal Skills)

### 1. [Step 1: Initial Enumeration](./sub-skills/step-1-initial-enumeration.md)
### 2. [Step 2: IAM Enumeration](./sub-skills/step-2-iam-enumeration.md)
### 3. [Step 3: Metadata SSRF (EC2)](./sub-skills/step-3-metadata-ssrf-ec2.md)
### 4. [Shadow Admin Permissions](./sub-skills/shadow-admin-permissions.md)
### 5. [Create Access Key for Another User](./sub-skills/create-access-key-for-another-user.md)
### 6. [Attach Admin Policy](./sub-skills/attach-admin-policy.md)
### 7. [Add Inline Admin Policy](./sub-skills/add-inline-admin-policy.md)
### 8. [Lambda Privilege Escalation](./sub-skills/lambda-privilege-escalation.md)
### 9. [Bucket Discovery](./sub-skills/bucket-discovery.md)
### 10. [Bucket Enumeration](./sub-skills/bucket-enumeration.md)
### 11. [Public Bucket Search](./sub-skills/public-bucket-search.md)
### 12. [Mount EBS Volume](./sub-skills/mount-ebs-volume.md)
### 13. [Shadow Copy Attack (Windows DC)](./sub-skills/shadow-copy-attack-windows-dc.md)
### 14. [Disable CloudTrail](./sub-skills/disable-cloudtrail.md)
### 15. [Example 1: SSRF to Admin](./sub-skills/example-1-ssrf-to-admin.md)

Files in this skill

  • SKILL.md2.7 KB
  • references/advanced-aws-pentesting.md11.3 KB
  • sub-skills/add-inline-admin-policy.md164 B
  • sub-skills/attach-admin-policy.md146 B
  • sub-skills/bucket-discovery.md255 B
  • sub-skills/bucket-enumeration.md200 B
  • sub-skills/create-access-key-for-another-user.md99 B
  • sub-skills/disable-cloudtrail.md1.3 KB
  • sub-skills/example-1-ssrf-to-admin.md1.2 KB
  • sub-skills/lambda-privilege-escalation.md498 B
  • sub-skills/mount-ebs-volume.md428 B
  • sub-skills/public-bucket-search.md833 B
  • sub-skills/shadow-admin-permissions.md536 B
  • sub-skills/shadow-copy-attack-windows-dc.md521 B
  • sub-skills/step-1-initial-enumeration.md336 B
  • sub-skills/step-2-iam-enumeration.md535 B
  • sub-skills/step-3-metadata-ssrf-ec2.md1.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…