Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.6 KiB

API Reference: Performing AWS Privilege Escalation Assessment

AWS IAM API (boto3)

Method Description
iam.list_users() Enumerate all IAM users
iam.list_attached_user_policies(UserName) List managed policies attached to user
iam.list_user_policies(UserName) List inline policies on a user
iam.get_policy_version(PolicyArn, VersionId) Get policy document for analysis
iam.list_roles() Enumerate all IAM roles
iam.list_attached_role_policies(RoleName) List managed policies on a role
iam.list_groups_for_user(UserName) List group memberships for a user
iam.simulate_principal_policy(PolicySourceArn, ActionNames) Test permissions

AWS STS API

Method Description
sts.get_caller_identity() Identify current principal (user/role/account)
sts.assume_role(RoleArn, RoleSessionName) Assume a role for privilege escalation test

Pacu Modules (CLI)

Module Description
iam__enum_users_roles_policies_groups Full IAM enumeration
iam__privesc_scan Scan for 21+ privilege escalation vectors
iam__backdoor_users_keys Test access key creation ability
lambda__backdoor_new_roles Test Lambda-based escalation

Key Libraries

  • boto3 (pip install boto3): AWS SDK for IAM, STS, and service enumeration
  • pacu (pip install pacu): AWS exploitation framework (CLI-based)
  • pmapper (Principal Mapper): Graph-based IAM privilege analysis
  • cloudfox: Cloud penetration testing tool for AWS enumeration

Dangerous IAM Actions

Action Escalation Vector
iam:CreatePolicyVersion Create new policy version with admin permissions
iam:AttachUserPolicy Attach AdministratorAccess to self
iam:PassRole + lambda:CreateFunction Create Lambda with privileged role
iam:PutUserPolicy Add inline admin policy to self
sts:AssumeRole Assume more-privileged role
iam:UpdateAssumeRolePolicy Modify role trust to allow self-assumption

Configuration

Variable Description
AWS_PROFILE AWS CLI profile with test credentials
AWS_DEFAULT_REGION Default AWS region for API calls

References