{"adoption": {"forks": 797, "observed_at": "2026-08-28T04:09:15.419947+00:00", "stars": 5312}, "canonical_url": "https://ross.abutalabs.com/products/pacu", "card": {"archived": false, "artifact_type": "framework", "description": "The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.", "domain": ["security", "penetration-testing", "cloud-computing", "developer-tools"], "enriched": true, "function": ["penetration-testing", "security", "cli"], "health_score": 88, "homepage": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/", "language": "Python", "license": "BSD-3-Clause", "license_family": "permissive", "maturity": "active", "member_repos": ["RhinoSecurityLabs/pacu"], "name": "RhinoSecurityLabs/pacu", "platform": ["windows", "python", "cli", "cross-platform"], "pushed_at": "2026-05-19T22:31:37+00:00", "repo": "RhinoSecurityLabs/pacu", "stars": 5312, "tags": ["aws", "aws-security", "offensive-security", "red-team", "exploitation-framework", "iam-privilege-escalation", "cloud-pentesting", "linux", "macos", "docker"], "topics": ["aws-security", "penetration-testing", "aws", "security", "python"], "urls": [], "use_cases": ["test the security of my AWS account with a simulated attacker", "find IAM privilege escalation paths in an AWS environment", "run an authenticated AWS penetration test", "enumerate AWS resources using compromised credentials", "backdoor IAM users and persist access during a red team engagement", "audit exploitable AWS configuration flaws beyond compliance scanning"], "what_it_is": "Pacu is an open-source AWS exploitation framework for offensive security testing of Amazon Web Services environments. It provides a modular, Metasploit-like CLI where penetration testers can enumerate, exploit configuration flaws, escalate IAM privileges, backdoor users, and attack Lambda functions using compromised AWS keys.", "when_to_avoid": ["you need a defensive compliance or misconfiguration scanner rather than an offensive tool", "you are testing clouds other than AWS", "you lack authorization to test the target AWS account"], "when_to_choose": ["you are a penetration tester or red teamer assessing an AWS environment", "you need exploit-focused AWS testing rather than compliance auditing", "you want a modular, extensible framework for cloud attack simulation"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/pacu", "repo": "RhinoSecurityLabs/pacu", "role": "main", "score": 73}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T17:58:58.706721+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc21758b9a616f0137528254936d265a23a06de3b69092f19f9fa990b69ba534", "fetched_at": "2026-08-28T04:09:15.419947+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RhinoSecurityLabs/pacu"}, {"content_hash": "f844e3c3df083821926e3522dc2ec23fab1662b95749f59093903c24a0b9072a", "fetched_at": "2026-08-29T08:53:48.167581+00:00", "kind": "homepage", "missing": false, "url": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/"}, {"content_hash": "278a35fe25801248fff568a1b62b7943cbc2f1005d5d1afedfb27a64ca890db4", "fetched_at": "2026-08-29T08:53:48.176993+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq"}, {"content_hash": "e06bc29de2a65b77ae3e9e7071afe49ff77b0da95e99d6ac47af298c8522a283", "fetched_at": "2026-08-29T08:53:48.179003+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/company"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T17:58:58.706721+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc21758b9a616f0137528254936d265a23a06de3b69092f19f9fa990b69ba534", "fetched_at": "2026-08-28T04:09:15.419947+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RhinoSecurityLabs/pacu"}, {"content_hash": "f844e3c3df083821926e3522dc2ec23fab1662b95749f59093903c24a0b9072a", "fetched_at": "2026-08-29T08:53:48.167581+00:00", "kind": "homepage", "missing": false, "url": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/"}, {"content_hash": "278a35fe25801248fff568a1b62b7943cbc2f1005d5d1afedfb27a64ca890db4", "fetched_at": "2026-08-29T08:53:48.176993+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq"}, {"content_hash": "e06bc29de2a65b77ae3e9e7071afe49ff77b0da95e99d6ac47af298c8522a283", "fetched_at": "2026-08-29T08:53:48.179003+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/company"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T17:58:58.706721+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc21758b9a616f0137528254936d265a23a06de3b69092f19f9fa990b69ba534", "fetched_at": "2026-08-28T04:09:15.419947+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RhinoSecurityLabs/pacu"}, {"content_hash": "f844e3c3df083821926e3522dc2ec23fab1662b95749f59093903c24a0b9072a", "fetched_at": "2026-08-29T08:53:48.167581+00:00", "kind": "homepage", "missing": false, "url": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/"}, {"content_hash": "278a35fe25801248fff568a1b62b7943cbc2f1005d5d1afedfb27a64ca890db4", "fetched_at": "2026-08-29T08:53:48.176993+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq"}, {"content_hash": "e06bc29de2a65b77ae3e9e7071afe49ff77b0da95e99d6ac47af298c8522a283", "fetched_at": "2026-08-29T08:53:48.179003+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/company"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T17:58:58.706721+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc21758b9a616f0137528254936d265a23a06de3b69092f19f9fa990b69ba534", "fetched_at": "2026-08-28T04:09:15.419947+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RhinoSecurityLabs/pacu"}, {"content_hash": "f844e3c3df083821926e3522dc2ec23fab1662b95749f59093903c24a0b9072a", "fetched_at": "2026-08-29T08:53:48.167581+00:00", "kind": "homepage", "missing": false, "url": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/"}, {"content_hash": "278a35fe25801248fff568a1b62b7943cbc2f1005d5d1afedfb27a64ca890db4", "fetched_at": "2026-08-29T08:53:48.176993+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq"}, {"content_hash": "e06bc29de2a65b77ae3e9e7071afe49ff77b0da95e99d6ac47af298c8522a283", "fetched_at": "2026-08-29T08:53:48.179003+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/company"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T17:58:58.706721+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc21758b9a616f0137528254936d265a23a06de3b69092f19f9fa990b69ba534", "fetched_at": "2026-08-28T04:09:15.419947+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RhinoSecurityLabs/pacu"}, {"content_hash": "f844e3c3df083821926e3522dc2ec23fab1662b95749f59093903c24a0b9072a", "fetched_at": "2026-08-29T08:53:48.167581+00:00", "kind": "homepage", "missing": false, "url": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/"}, {"content_hash": "278a35fe25801248fff568a1b62b7943cbc2f1005d5d1afedfb27a64ca890db4", "fetched_at": "2026-08-29T08:53:48.176993+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq"}, {"content_hash": "e06bc29de2a65b77ae3e9e7071afe49ff77b0da95e99d6ac47af298c8522a283", "fetched_at": "2026-08-29T08:53:48.179003+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/company"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T17:58:58.706721+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc21758b9a616f0137528254936d265a23a06de3b69092f19f9fa990b69ba534", "fetched_at": "2026-08-28T04:09:15.419947+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RhinoSecurityLabs/pacu"}, {"content_hash": "f844e3c3df083821926e3522dc2ec23fab1662b95749f59093903c24a0b9072a", "fetched_at": "2026-08-29T08:53:48.167581+00:00", "kind": "homepage", "missing": false, "url": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/"}, {"content_hash": "278a35fe25801248fff568a1b62b7943cbc2f1005d5d1afedfb27a64ca890db4", "fetched_at": "2026-08-29T08:53:48.176993+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq"}, {"content_hash": "e06bc29de2a65b77ae3e9e7071afe49ff77b0da95e99d6ac47af298c8522a283", "fetched_at": "2026-08-29T08:53:48.179003+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/company"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:09:15.419947+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T17:58:58.706721+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc21758b9a616f0137528254936d265a23a06de3b69092f19f9fa990b69ba534", "fetched_at": "2026-08-28T04:09:15.419947+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RhinoSecurityLabs/pacu"}, {"content_hash": "f844e3c3df083821926e3522dc2ec23fab1662b95749f59093903c24a0b9072a", "fetched_at": "2026-08-29T08:53:48.167581+00:00", "kind": "homepage", "missing": false, "url": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/"}, {"content_hash": "278a35fe25801248fff568a1b62b7943cbc2f1005d5d1afedfb27a64ca890db4", "fetched_at": "2026-08-29T08:53:48.176993+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq"}, {"content_hash": "e06bc29de2a65b77ae3e9e7071afe49ff77b0da95e99d6ac47af298c8522a283", "fetched_at": "2026-08-29T08:53:48.179003+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/company"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T17:58:58.706721+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc21758b9a616f0137528254936d265a23a06de3b69092f19f9fa990b69ba534", "fetched_at": "2026-08-28T04:09:15.419947+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RhinoSecurityLabs/pacu"}, {"content_hash": "f844e3c3df083821926e3522dc2ec23fab1662b95749f59093903c24a0b9072a", "fetched_at": "2026-08-29T08:53:48.167581+00:00", "kind": "homepage", "missing": false, "url": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/"}, {"content_hash": "278a35fe25801248fff568a1b62b7943cbc2f1005d5d1afedfb27a64ca890db4", "fetched_at": "2026-08-29T08:53:48.176993+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq"}, {"content_hash": "e06bc29de2a65b77ae3e9e7071afe49ff77b0da95e99d6ac47af298c8522a283", "fetched_at": "2026-08-29T08:53:48.179003+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/company"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T17:58:58.706721+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc21758b9a616f0137528254936d265a23a06de3b69092f19f9fa990b69ba534", "fetched_at": "2026-08-28T04:09:15.419947+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RhinoSecurityLabs/pacu"}, {"content_hash": "f844e3c3df083821926e3522dc2ec23fab1662b95749f59093903c24a0b9072a", "fetched_at": "2026-08-29T08:53:48.167581+00:00", "kind": "homepage", "missing": false, "url": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/"}, {"content_hash": "278a35fe25801248fff568a1b62b7943cbc2f1005d5d1afedfb27a64ca890db4", "fetched_at": "2026-08-29T08:53:48.176993+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq"}, {"content_hash": "e06bc29de2a65b77ae3e9e7071afe49ff77b0da95e99d6ac47af298c8522a283", "fetched_at": "2026-08-29T08:53:48.179003+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/company"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T17:58:58.706721+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bc21758b9a616f0137528254936d265a23a06de3b69092f19f9fa990b69ba534", "fetched_at": "2026-08-28T04:09:15.419947+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RhinoSecurityLabs/pacu"}, {"content_hash": "f844e3c3df083821926e3522dc2ec23fab1662b95749f59093903c24a0b9072a", "fetched_at": "2026-08-29T08:53:48.167581+00:00", "kind": "homepage", "missing": false, "url": "https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/"}, {"content_hash": "278a35fe25801248fff568a1b62b7943cbc2f1005d5d1afedfb27a64ca890db4", "fetched_at": "2026-08-29T08:53:48.176993+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq"}, {"content_hash": "e06bc29de2a65b77ae3e9e7071afe49ff77b0da95e99d6ac47af298c8522a283", "fetched_at": "2026-08-29T08:53:48.179003+00:00", "kind": "site_page", "missing": false, "url": "https://rhinosecuritylabs.com/company"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 83, "longevity": 100, "rhythm": 44}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3003, "days_push": 106, "days_rel": 163, "gap_med": 242, "n_releases_24m": 2}, "score": 73, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}