AWS Enumeration for Purple Teams

No ratings

Presented at OrangeCon 2025 by

Designed for both Blue and Red teams, this hands-on workshop is designed to equip participants with a deep dive into AWS enumeration techniques and detection opportunities. Through guided labs, attendees will learn how attackers can use policy misconfigurations to identify paths to their objectives. For defenders, we will discuss real-world detection opportunities, log sources, and effective monitoring strategies to identify suspicious enumeration activity before it escalates into full-blown compromise. Along the way we introduce dAWShund, a new tool designed to map and visualize AWS resource relationships, helping Red Teams identify attack paths and Blue Teams strengthen defenses to help put a leash on naughty permissions. The idea is to hold an interactive workshop fostering and encouraging discussions among participants. By the end of the workshop, attendees would be able: - Understand the differences between AWS resources and policy types. (TL;DR it’s a hot mess) - Get a grasp of permissions validation (A bigger hot mess) - Spot detection opportunities for enumeration (We' ll use Sentinel and KQL) - Discuss areas of improvement for the future Technical requirements for the audience: - Don't forget to bring your own laptop - Basic knowledge of AWS; although all terminology will be explained.