Ross ROSS = Recommend OSS · open-source software intelligence for agents

dagrz/aws_pwn

A collection of AWS penetration testing junk observed · 2026-08-28

github.com/dagrz/aws_pwn · Python observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3606
  • days_rel: n/a
  • days_push: 1099
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1223 stars · 192 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A collection of Python scripts for penetration testing AWS environments, covering reconnaissance, exploitation, stealth, exploration, and privilege escalation. It uses boto3 and AWS credentials to enumerate accounts, validate access keys and principals, dump account data, and attempt lateral movement via role assumption.

Use cases

  • pentest an AWS account
  • validate leaked AWS access keys
  • enumerate IAM roles and attempt to assume them
  • dump EC2 instance user data for secrets
  • check whether S3 bucket names exist
  • disrupt CloudTrail logging during a red team engagement
  • take a snapshot of all resources in an AWS account

When to choose

  • you are doing authorized penetration testing or red teaming against AWS
  • you need quick ad-hoc scripts for AWS recon and privilege escalation
  • you want a grab-bag of AWS attack tooling to adapt rather than a polished framework

When to avoid

  • you need a maintained, well-tested cloud security tool - the code is self-described as 'horribly written' and scripts may break as AWS changes
  • you want vulnerability scanning or compliance auditing rather than offensive testing
  • you need a supported tool for production environments - there is no license and no guarantee of upkeep

Facets

cli-tool · maturity maintenance

penetration-testing security osint developer-tools security cloud-computing penetration-testing developer-tools python cli windows aws cloud-security red-team boto3 iam privilege-escalation reconnaissance linux macos

1 source

Member repositories

RepositoryRoleHealth v2
dagrz/aws_pwnmain32

For agents

markdown · JSON · MCP: product_card(name="dagrz/aws_pwn")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem