RhinoSecurityLabs/pacu
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments. observed · 2026-08-28
Health v2 · maintenance only
73/100
- Activity 83
- Release rhythm 44
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 242
- age_days: 3003
- days_rel: 163
- days_push: 106
- n_releases_24m: 2
Adoption not part of the score
5312 stars · 797 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Pacu is an open-source AWS exploitation framework for offensive security testing of Amazon Web Services environments. It provides a modular, Metasploit-like CLI where penetration testers can enumerate, exploit configuration flaws, escalate IAM privileges, backdoor users, and attack Lambda functions using compromised AWS keys.
Use cases
- test the security of my AWS account with a simulated attacker
- find IAM privilege escalation paths in an AWS environment
- run an authenticated AWS penetration test
- enumerate AWS resources using compromised credentials
- backdoor IAM users and persist access during a red team engagement
- audit exploitable AWS configuration flaws beyond compliance scanning
When to choose
- you are a penetration tester or red teamer assessing an AWS environment
- you need exploit-focused AWS testing rather than compliance auditing
- you want a modular, extensible framework for cloud attack simulation
When to avoid
- you need a defensive compliance or misconfiguration scanner rather than an offensive tool
- you are testing clouds other than AWS
- you lack authorization to test the target AWS account
Facets
framework · maturity active
penetration-testing security cli security penetration-testing cloud-computing developer-tools windows python cli cross-platform aws aws-security offensive-security red-team exploitation-framework iam-privilege-escalation cloud-pentesting linux macos docker
4 sources
- readme: https://github.com/RhinoSecurityLabs/pacu · fetched 2026-08-28 · bc21758b9a61
- homepage: https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/ · fetched 2026-08-29 · f844e3c3df08
- site_page: https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq · fetched 2026-08-29 · 278a35fe2580
- site_page: https://rhinosecuritylabs.com/company · fetched 2026-08-29 · e06bc29de2a6
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| RhinoSecurityLabs/pacu | main | 73 |
For agents
markdown · JSON · MCP: product_card(name="RhinoSecurityLabs/pacu")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem