Files
hacktricks-cloud/pentesting-cloud/aws-security/aws-permissions-for-a-pentest.md
2024-12-16 11:31:25 +00:00

3.1 KiB

AWS - Permissions for a Pentest

{% hint style="success" %} Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)

Support HackTricks
{% endhint %}

These are the permissions you need on each AWS account you want to audit to be able to run all the proposed AWS audit tools:

  • The default policy arn:aws:iam::aws:policy/ReadOnlyAccess
  • To run aws_iam_review you also need the permissions:
    • access-analyzer:List*
    • access-analyzer:Get*
    • iam:CreateServiceLinkedRole
    • access-analyzer:CreateAnalyzer
      • Optional if the client generates the analyzers for you, but usually it's easier just to ask for this permission)
    • access-analyzer:DeleteAnalyzer
      • Optional if the client removes the analyzers for you, but usually it's easier just to ask for this permission)

{% hint style="success" %} Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)

Support HackTricks
{% endhint %}