AWS Penetration Testing
Fail
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Provides detailed procedures and commands for unauthorized privilege escalation and system control.
sub-skills/attach-admin-policy.mdandsub-skills/add-inline-admin-policy.mdprovide commands to grant a userAdministratorAccessvia the IAM API.sub-skills/lambda-privilege-escalation.mdprovides a Python payload to automatically attach administrative policies when executed.sub-skills/mount-ebs-volume.mdincludes instructions for using AWS Systems Manager (SSM) to execute shell commands on managed EC2 instances.- [REMOTE_CODE_EXECUTION]: Facilitates the deployment of malicious code to maintain persistence and bypass controls.
sub-skills/lambda-privilege-escalation.mdandreferences/advanced-aws-pentesting.mddescribe how to update Lambda function code with backdoor logic.references/advanced-aws-pentesting.mdincludes instructions for building and pushing backdoored container images to Amazon ECR.- [CREDENTIALS_UNSAFE]: Contains extensive methods for extracting sensitive credentials and secrets.
sub-skills/step-3-metadata-ssrf-ec2.mdandsub-skills/example-1-ssrf-to-admin.mdprovide specific URLs and procedures for exploiting SSRF to steal IAM role credentials from the EC2 Instance Metadata Service (IMDSv1 and v2).references/advanced-aws-pentesting.mdprovides commands to retrieve secrets from AWS Secrets Manager and decrypt KMS-protected data.- [DATA_EXFILTRATION]: Outlines techniques for harvesting sensitive data from cloud resources.
references/advanced-aws-pentesting.mdincludes commands for downloading Lambda function source code and scanning S3 buckets for public access.sub-skills/shadow-copy-attack-windows-dc.mddescribes a process for extracting NTDS.dit (Active Directory database) from snapshots of Windows Domain Controller volumes.- [EXTERNAL_DOWNLOADS]: Promotes the installation of numerous third-party offensive security tools from unverified GitHub repositories.
SKILL.mdandreferences/advanced-aws-pentesting.mdlist installation commands for tools such as Pacu, SkyArk, weirdAAL, and cloudmapper.
Recommendations
- AI detected serious security threats
Audit Metadata