Back to directory
WRITEUP #1378

Bypassing CloudTrail in AWS Service Catalog, and Other Logging Research

CloudCloudTrail bypass
by@frichette_n(Nick Frichette)
Program
AWS
Published
Mar 20, 2023
Added to HackDex
Mar 23, 2023
Read Full Writeuphttps://securitylabs.datadoghq.com/articles/bypass-cloudtrail-aws-service-catalog-and-other/
RELATED WRITEUPS
The Hunt for ALBeast: A Technical Walkthrough
CloudAWS ALB
Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess
CloudOIDC
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD
CloudPrivilege escalation
Bucket Monopoly: Breaching AWS Accounts Through Shadow Resources
CloudRCE
UnOAuthorized: Privilege Elevation Through Microsoft Applications
CloudPrivilege escalation

Built with ❤️ by Shubham Rawat