Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New Technique: T1651 #3031

Open
wants to merge 5 commits into
base: master
Choose a base branch
from

Conversation

ryananicholson
Copy link
Contributor

Details:
This test uses Terraform to deploy an SSM-enabled AWS EC2 instance. The attack leverages either configured or stolen credentials to launch an attacker-controlled command (cat /etc/shadow) using an SSM Run Command. Due to infrastructure build, warmup, and tear down times, I recommend that a larger timeout than default is used (600 seconds seems to be a good number in my testing).

Testing:
Tested against my AWS account. Results shown below:

image

Associated Issues:
No issues fixed with this PR.

@ryananicholson ryananicholson changed the title T1651 New Technique: T1651 Jan 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants