Detection of Offensive Cloud Framework Execution
Adversaries utilize cloud enumeration and exploitation frameworks to perform reconnaissance and identify privilege escalation paths following the compromise of cloud credentials on endpoint devices.
Adversaries frequently deploy automated offensive cloud security frameworks on compromised endpoints after obtaining initial cloud access. These tools are used to map the compromised principal's effective permissions, discover privilege escalation paths, and pivot into cloud management consoles. While these frameworks are vital for authorized red team engagements and cloud audits, their presence on an endpoint often indicates a post-compromise activity where an attacker seeks to deepen their control over the cloud environment.
Observed frameworks include Pacu (S1091), CloudFox, ScoutSuite, PMapper, Stratus Red Team, Prowler, and others. Defenders must distinguish between authorized security assessments and unauthorized attacker activity. Because these tools often rely on existing cloud credentials (found in files like ~/.aws/credentials or environment variables) to perform bursts of enumeration calls, their execution is a high-signal indicator of active threat actor intent to escalate privileges or exfiltrate cloud-resident data.
Attack Chain
- Adversary gains initial access to an endpoint host via phishing or exploited web-facing services.
- Adversary searches the host for cloud access keys, identity files, or environment variables containing credentials.
- Adversary downloads or executes an offensive framework (e.g., Pacu or CloudFox) on the compromised host.
- The framework is launched via a script interpreter (Python, pipx, uv, or Go) to avoid detection by basic file-name filters.
- The tool queries cloud APIs (e.g.,
Describe*,List*,Get*) to inventory cloud resources and IAM policies. - The tool performs automated simulation of privilege escalation paths or IAM permission testing (e.g.,
iam:Simulate*). - Adversary uses discovered credentials or modified roles to pivot into the cloud console or perform data exfiltration.
Impact
Successful execution of these frameworks allows attackers to identify and exploit misconfigured IAM roles, escalate privileges to administrator-level access, and persist within the cloud environment. This often leads to the compromise of sensitive data, exfiltration of cloud secrets, and broader lateral movement across the organization's cloud infrastructure.
Recommendation
- Deploy the Sigma rules below to monitor for the launch of offensive cloud tools on sensitive endpoints.
- Correlate alerts with known red team engagement schedules and authorized security assessment windows to minimize noise.
- Investigate the parent process of any detected tool to determine if it was launched via manual interaction, an automated task, or an unexpected CI/CD pipeline component.
- Perform immediate rotation of any cloud credentials found on compromised hosts identified in the alerts.
- Review CloudTrail logs for the specific cloud principal used by the tool to identify unauthorized
iam:CreateAccessKeyoriam:AttachUserPolicycalls.
Immediate actions
Deploy Sigma detection rule to endpoints
Threat Hunt
Search for unknown processes making extensive API calls to cloud providers
Data: CloudTrail API logs
Mitigations
Rotate cloud credentials found on compromised endpoints
Credential theft
Detection coverage 1
Detect Execution of Offensive Cloud Frameworks
mediumDetects the execution of known cloud enumeration and offensive frameworks on an endpoint by process name or by searching command line arguments passed to script interpreters.
Detection queries are available on the platform. Get full rules →