carnal0wnage / weirdAAL

WeirdAAL (AWS Attack Library)
773 stars 92 forks source link

check 4 default permissions #29

Closed carnal0wnage closed 6 years ago

carnal0wnage commented 6 years ago

everyone seems to have elasticbeanstalk:DescribeApplications elasticbeanstalk:DescribeApplicationVersions elasticbeanstalk:DescribeEnvironments elasticbeanstalk:DescribeEvents opsworks:DescribeStacks route53:ListGeoLocations sts:GetCallerIdentity

but rarely have anything there, cept for sts one.

write a check that will check these specific things so it can be a suggested follow up.

carnal0wnage commented 6 years ago

added recon_defaults

Recon defaults that every account seems to have minus route53_geolocations (static data)
python3 -m recon_defaults -t demo