Ross ROSS = Recommend OSS · open-source software intelligence for agents

RhinoSecurityLabs/pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments. observed · 2026-08-28

github.com/RhinoSecurityLabs/pacu · homepage · Python · BSD-3-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

73/100

  • Activity 83
  • Release rhythm 44
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 242
  • age_days: 3003
  • days_rel: 163
  • days_push: 106
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

5312 stars · 797 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Pacu is an open-source AWS exploitation framework for offensive security testing of Amazon Web Services environments. It provides a modular, Metasploit-like CLI where penetration testers can enumerate, exploit configuration flaws, escalate IAM privileges, backdoor users, and attack Lambda functions using compromised AWS keys.

Use cases

  • test the security of my AWS account with a simulated attacker
  • find IAM privilege escalation paths in an AWS environment
  • run an authenticated AWS penetration test
  • enumerate AWS resources using compromised credentials
  • backdoor IAM users and persist access during a red team engagement
  • audit exploitable AWS configuration flaws beyond compliance scanning

When to choose

  • you are a penetration tester or red teamer assessing an AWS environment
  • you need exploit-focused AWS testing rather than compliance auditing
  • you want a modular, extensible framework for cloud attack simulation

When to avoid

  • you need a defensive compliance or misconfiguration scanner rather than an offensive tool
  • you are testing clouds other than AWS
  • you lack authorization to test the target AWS account

Facets

framework · maturity active

penetration-testing security cli security penetration-testing cloud-computing developer-tools windows python cli cross-platform aws aws-security offensive-security red-team exploitation-framework iam-privilege-escalation cloud-pentesting linux macos docker

4 sources

Member repositories

RepositoryRoleHealth v2
RhinoSecurityLabs/pacumain73

For agents

markdown · JSON · MCP: product_card(name="RhinoSecurityLabs/pacu")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem