Skip to content
Threat Feed

Product

AWS CloudShell

5 briefs RSS
high advisory

AWS Sensitive IAM Operations Performed via CloudShell

Attackers can leverage a compromised AWS console session to perform sensitive AWS IAM operations via AWS CloudShell, establishing persistence or escalating privileges, which can be detected by monitoring CloudTrail logs for specific user agent strings and high-risk IAM actions.

AWS CloudShell +2 cloud aws persistence privilege-escalation
1r 4t
high advisory

Adversaries Using AWS CloudShell Environment Creation

Adversaries with compromised AWS console access are leveraging AWS CloudShell by triggering the CreateEnvironment API call to execute commands, install tools, and interact with AWS services without requiring local CLI credentials, enabling post-compromise actions such as data exfiltration or resource modification.

AWS CloudShell aws cloud execution initial-access
1r 2t
low advisory

AWS CloudShell Environment Creation Detection

Detection of AWS CloudShell environment creation can indicate unauthorized command execution within AWS by an adversary leveraging a compromised console session to interact with AWS services.

AWS CloudShell aws cloudshell execution initial-access
2r 2t
medium advisory

AWS IAM Operations via Compromised CloudShell

Compromised AWS console sessions can lead to attackers performing sensitive IAM operations via CloudShell to establish persistence or escalate privileges.

AWS CloudShell +2 cloudshell aws iam persistence privilege-escalation
2r 4t
low advisory

AWS CloudShell Environment Created

The creation of a new AWS CloudShell environment is detected, potentially indicating unauthorized access for command execution within AWS by adversaries without needing local CLI credentials.

AWS CloudShell cloud aws cloudshell
2r 1t