Beginner Friendly blue team icon   aws

Intro to AWS IAM Enumeration

Shields up! Identify the blast radius in this  fun blue team scenario

Overview

We created this beginner-friendly lab to give an introduction to the AWS CLI as well as IAM user, role, group, and policy enumeration. This lab is good for red and blue looking to gain familiarity with AWS cloud!

Scenario

You are a security consultant hired by the global logistics company, Huge Logistics. Following suspicious activity, you are tasked with enumerating the IAM user dev01 and mapping out any potentially compromised resources. Your mission is to enumerate and evaluate IAM roles, policies, and permissions.

Lab prerequisites
Basic Linux command line knowledge
Learning outcomes
  • Familiarity with the AWS CLI
  • Understanding of the basic AWS IAM components
  • Ability to list, retrieve and interpret IAM policies
Real-world context

IAM (Identity and Access Management) is central to building, defending and attacking cloud services. Both offensive and defensive security practitioners need a solid understanding of IAM and how to enumerate permissions: attackers look for overly-permissive settings or misconfigurations in a potential attack chain, while defenders ensure need to enforce the principle of least privilege and identify any resources or services that are in the blast radius of a compromised IAM user.

platform mock(1)

Cloud Security Training To Protect Your Business

Pwned Labs for Business gives your team access to dedicated business content, including labs and cyber ranges.

We also offer in-person or remote workshops, and our cloud penetration services are helping businesses become more secure!