Skip to content
Threat Feed
medium advisory

Detection of Offensive Cloud Framework Execution

Adversaries utilize cloud enumeration and exploitation frameworks to perform reconnaissance and identify privilege escalation paths following the compromise of cloud credentials on endpoint devices.

Adversaries frequently deploy automated offensive cloud security frameworks on compromised endpoints after obtaining initial cloud access. These tools are used to map the compromised principal's effective permissions, discover privilege escalation paths, and pivot into cloud management consoles. While these frameworks are vital for authorized red team engagements and cloud audits, their presence on an endpoint often indicates a post-compromise activity where an attacker seeks to deepen their control over the cloud environment.

Observed frameworks include Pacu (S1091), CloudFox, ScoutSuite, PMapper, Stratus Red Team, Prowler, and others. Defenders must distinguish between authorized security assessments and unauthorized attacker activity. Because these tools often rely on existing cloud credentials (found in files like ~/.aws/credentials or environment variables) to perform bursts of enumeration calls, their execution is a high-signal indicator of active threat actor intent to escalate privileges or exfiltrate cloud-resident data.

Attack Chain

  1. Adversary gains initial access to an endpoint host via phishing or exploited web-facing services.
  2. Adversary searches the host for cloud access keys, identity files, or environment variables containing credentials.
  3. Adversary downloads or executes an offensive framework (e.g., Pacu or CloudFox) on the compromised host.
  4. The framework is launched via a script interpreter (Python, pipx, uv, or Go) to avoid detection by basic file-name filters.
  5. The tool queries cloud APIs (e.g., Describe*, List*, Get*) to inventory cloud resources and IAM policies.
  6. The tool performs automated simulation of privilege escalation paths or IAM permission testing (e.g., iam:Simulate*).
  7. Adversary uses discovered credentials or modified roles to pivot into the cloud console or perform data exfiltration.

Impact

Successful execution of these frameworks allows attackers to identify and exploit misconfigured IAM roles, escalate privileges to administrator-level access, and persist within the cloud environment. This often leads to the compromise of sensitive data, exfiltration of cloud secrets, and broader lateral movement across the organization's cloud infrastructure.

Recommendation

  1. Deploy the Sigma rules below to monitor for the launch of offensive cloud tools on sensitive endpoints.
  2. Correlate alerts with known red team engagement schedules and authorized security assessment windows to minimize noise.
  3. Investigate the parent process of any detected tool to determine if it was launched via manual interaction, an automated task, or an unexpected CI/CD pipeline component.
  4. Perform immediate rotation of any cloud credentials found on compromised hosts identified in the alerts.
  5. Review CloudTrail logs for the specific cloud principal used by the tool to identify unauthorized iam:CreateAccessKey or iam:AttachUserPolicy calls.

Immediate actions

Deploy Sigma detection rule to endpoints

Detection Engineering 48h

Threat Hunt

Search for unknown processes making extensive API calls to cloud providers

T1580 high high confidence hunt now

Data: CloudTrail API logs

Mitigations

Rotate cloud credentials found on compromised endpoints

immediate SOC

Credential theft

Detection coverage 1

Detect Execution of Offensive Cloud Frameworks

medium

Detects the execution of known cloud enumeration and offensive frameworks on an endpoint by process name or by searching command line arguments passed to script interpreters.

sigma tactics: discovery, execution techniques: T1059.006, T1580 sources: process_creation

Detection queries are available on the platform. Get full rules →