Pacu

S1091

Tool.View on attack.mitre.org

About this tool

Pacu is an open-source AWS exploitation framework. The tool is written in Python and publicly available on GitHub.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1049
System Network Connections Discovery

Once inside a Virtual Private Cloud, Pacu can attempt to identify DirectConnect, VPN, or VPC Peering.

T1059.009
Cloud API

Pacu leverages the AWS CLI for its operations.

T1069.003
Cloud Groups

Pacu can enumerate IAM permissions.

T1078.004
Cloud Accounts

Pacu leverages valid cloud accounts to perform most of its operations.

T1087.004
Cloud Account

Pacu can enumerate IAM users, roles, and groups.

T1098.001
Additional Cloud Credentials

Pacu can generate SSH and API keys for AWS infrastructure and additional API keys for other IAM users.

T1119
Automated Collection

Pacu can automatically collect data, such as CloudFormation templates, EC2 user data, AWS Inspector reports, and IAM credential reports.

T1518.001
Security Software Discovery

Pacu can enumerate AWS security services, including WAF rules and GuardDuty detectors.

T1526
Cloud Service Discovery

Pacu can enumerate AWS services, such as CloudTrail and CloudWatch.

T1530
Data from Cloud Storage

Pacu can enumerate and download files stored in AWS storage services, such as S3 buckets.

T1546
Event Triggered Execution

Pacu can set up S3 bucket notifications to trigger a malicious Lambda function when a CloudFormation template is uploaded to the bucket. It can also create Lambda functions that trigger upon the creation of users, roles, and groups.

T1552
Unsecured Credentials

Pacu can search for sensitive data: for example, in Code Build environment variables, EC2 user data, and Cloud Formation templates.

T1555.006
Cloud Secrets Management Stores

Pacu can retrieve secrets from the AWS Secrets Manager via the enum_secrets module.

T1578.001
Create Snapshot

Pacu can create snapshots of EBS volumes and RDS instances.

T1580
Cloud Infrastructure Discovery

Pacu can enumerate AWS infrastructure, such as EC2 instances.

View all 21 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. GitHub Pacu Open source
    Rhino Security Labs. (2019, August 22). Pacu. Retrieved October 17, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.