The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
BSD 3-Clause "New" or "Revised" License
4.37k
stars
694
forks
source link
Updated the WiKi : The Permission Required for using Pacu. #416
Closed
cheahengsoon closed 6 months ago
Hi Team,
May I request to update the document for permission required in AWS by using Pacu.
IAM Permissions:
iam:ListUsers
iam:ListRoles
iam:ListPolicies
iam:ListGroups
iam:CreateUser
iam:CreatePolicy
iam:AttachUserPolicy
iam:PutUserPolicy
iam:UpdateAssumeRolePolicy
iam:AttachRolePolicy
iam:PutRolePolicy
iam:CreateGroup
iam:AddUserToGroup
iam:AttachGroupPolicy
iam:PutGroupPolicy
iam:CreateLoginProfile
EC2 Permissions:
ec2:DescribeInstances
ec2:RunInstances
ec2:StopInstances
ec2:TerminateInstances
ec2:DescribeSecurityGroups
ec2:AuthorizeSecurityGroupIngress
ec2:RevokeSecurityGroupIngress
ec2:DescribeKeyPairs
S3 Permissions:
s3:ListBucket
s3:GetObject
s3:PutObject
s3:DeleteObject
s3:ListAllMyBuckets
RDS Permissions:
rds:DescribeDBInstances
rds:CreateDBInstance
rds:DeleteDBInstance
rds:ModifyDBInstance
rds:ListTagsForResource
rds:AddTagsToResource
rds:CreateDBSnapshot
rds:DeleteDBSnapshot
CloudTrail Permissions:
cloudtrail:DescribeTrails
cloudtrail:GetTrailStatus
cloudtrail:LookupEvents
CloudFormation Permissions:
cloudformation:CreateStack
cloudformation:DeleteStack
cloudformation:DescribeStacks
Lambda Permissions:
lambda:ListFunctions
lambda:CreateFunction
lambda:DeleteFunction
lambda:InvokeFunction
Other Permissions:
sts:GetCallerIdentity
sns:ListTopics
sns:CreateTopic
sns:Subscribe
sns:Publish
route53:ListHostedZones
route53:ChangeResourceRecordSets
organizations:ListAccounts