first commit
This commit is contained in:
@@ -0,0 +1,113 @@
|
||||
- Using credentials with AWS CLI involves a file at `~/.aws/credentials`, with the following example format:
|
||||
```
|
||||
[<profile_name>]
|
||||
aws_access_key_id = <key>
|
||||
aws_secret_access_key = <secret>
|
||||
aws_session_token = <session_token>
|
||||
```
|
||||
- Add `--profile demo` to use the above with AWS CLI commands
|
||||
- List accounts belonging to organization
|
||||
- `aws organizations list-accounts`
|
||||
- Get information about IAM role
|
||||
- `aws iam get-role --role-name <role_name> --profile <profile_name>`
|
||||
- List details on instances
|
||||
- ` aws ec2 describe-instances --region=<region> --profile <profile_filename>`
|
||||
- List details on container repositories
|
||||
- `aws ecr describe-repositories --region=<region> --profile gretsch1`
|
||||
- Get user information
|
||||
- `aws iam get-user --profile <profile_name>`
|
||||
- `aws iam list-attached-user-policies --user-name=<username> --profile <profile_name>`
|
||||
- Get information on policy
|
||||
- ` aws iam get-policy --policy-arn mxrads-self-manage --profile kevin`
|
||||
- Version
|
||||
- ` aws iam iam get-policy --policy-arn <policy_arn> --profile <profile_name>`
|
||||
- Get Content
|
||||
- ` aws iam iam get-policy-version --policy-arn <policy_arn> --version <version> --profile <profile_name>`
|
||||
- List users and groups affiliated with default Administrator policy
|
||||
- `aws iam list-entities-for-policy --policy-arn arn:aws:iam::aws:policy/AdministratorAccess`
|
||||
- List current access keys for user (there can only be 2, so anything less allows you to add one)
|
||||
- `aws iam list-access-keys --user b.daniella | jq ".AccessKeyMetadata[].AccessKeyId"`
|
||||
- Create access key for user
|
||||
- `aws iam create-access-key --user b.daniella`
|
||||
- Change role policy
|
||||
- `aws iam update-assume-role-policy --role-name lambda-dmp-sync --policy-document file://new_policy.json`
|
||||
- Find roles capable of `assume-role` calls for `lambda.amazonaws.com`
|
||||
- `aws iam list-roles | jq -r '.Roles[] | .RoleName + ", " + .AssumeRolePolicyDocument.Statement[].Principal.Service' | grep "lambda.amazonaws.com"`
|
||||
- Check IAM policies for role
|
||||
- `aws iam list-attached-role-policies --role <role_name> --profile <profile_name>`
|
||||
- Look for roles with high permissions like `IAMFullAccess` and which lack write permissions to CloudWatch
|
||||
- Inspect security groups
|
||||
- `aws ec2 describe-security-groups --group-ids <id_1> <id_2>`
|
||||
- Assume role
|
||||
- `aws sts assume-role --role-arn arn:aws:iam::886371554408:user/lambda-dmp-sync --role-session-name AWSCLI-Session --duration-seconds 43200`
|
||||
- List existing lambda functions
|
||||
- `aws iam lambda list-functions -region=<region>`
|
||||
- Get information on Lambda function
|
||||
- `aws lambda get-function --function-name <lambda_func_name> --region <region> --profile <profile_name>`
|
||||
- Get information on Kubernetes cluster
|
||||
- `aws eks describe-cluster --name <cluster_name> --profile <profile_filename> --region=<region>`
|
||||
- Get information from Resource Groups Tagging API
|
||||
- `aws resourcegroupstaggingapi get-resources --region <region> --profile <profile_name>`
|
||||
- List secrets
|
||||
- `aws secretsmanager list-secrets --region <region> --profile <profile_name>`
|
||||
- Download secret
|
||||
- `aws secretsmanager get-secret-value --secret-id '<ID>' --region=eu-west-1 --profile it-role | jq -r .SecretString | base64 -d`
|
||||
- List buckets accessible with these credentials/this role:
|
||||
- `aws s3api listbuckets --profile <profile_name>`
|
||||
- List buckets and show bucket names only
|
||||
- `aws s3api list-buckets --profile <profile_name> --query "Buckets[].Name"`
|
||||
- Sync bucket
|
||||
- mounted locally
|
||||
- `aws s3 sync s3://<bucket_name> <filesystem_mount_point>`
|
||||
- With another bucket
|
||||
- `aws s3 sync s3://source-bucket/ s3://destination-bucket`
|
||||
- List keys inside a single bucket
|
||||
1. `aws s3api list-objects-v2 --profile <profile_name> --bucket <bucket_name> > list_objects_dl.txt`
|
||||
2. `grep '"Key"' list_objects_dl | sed 's/[",]//g' > list_keys_dl.txt`
|
||||
- Check for S3 bucket logging
|
||||
- `aws s3api get-bucket-logging --profile <profile_name> --bucket <bucket_name>`
|
||||
- Check bucket policy
|
||||
- `aws s3api get-bucket-policy --bucket <bucket_name>`
|
||||
- Get account ID
|
||||
- `aws sts get-caller-identity --profile <profile_name>`
|
||||
- Create a new bucket:
|
||||
- `aws s3api create-bucket --bucket <bucket_name> --region=<aws_region> --create-bucket-configuration LocationConstraint=<aws_region>`
|
||||
- Upload file to bucket:
|
||||
- ` aws s3api put-object --bucket <bucket_name> --key <key_name> --body <filename>`
|
||||
- Change file permissions in bucket:
|
||||
- `aws s3api put-bucket-policy --bucket <bucket_name> --policy file://<local_policy_file>`
|
||||
- Exchange service account token for IAM keys (only for proper service account tokens with OpenID info in AWS)
|
||||
1. `AWS_ROLE_ARN="<role_name>"`
|
||||
- e.g. `AWS_ROLE_ARN="arn:aws:iam::886477354405:role/api-core.ec2"`
|
||||
2. `TOKEN ="<token>"`
|
||||
3. `aws sts assume-role-with-web-identity --role-arn $AWS_ROLE_ARN --role-session-name sessionID --web-identity-token $TOKEN --duration-seconds 43200`
|
||||
- Exchange IAM key for Kubernetes token
|
||||
- `aws eks get-token --cluster-name <cluster_name> --profile <profile_name>`
|
||||
- Create kubectl config
|
||||
- `aws eks update-kubeconfig --name <cluster_name> --profile <profile_name>`
|
||||
- Get all instances that match a specific tag
|
||||
- `while read p; do instanceID=$(aws ec2 describe-instances --filter "Name=tag:Name,Values=*$p*" --query 'Reservations[0].Instances[].InstanceId' --region=eu-west-1 --output=text; echo $instanceID > list_ids.txt; done <services.txt`
|
||||
- Get user data from instance IDs in a file
|
||||
- `while read p; do userData=$(aws ec2 describe-instance-attribute --instance-id $p --attribute userData --region=eu-west-1 | jq -r .UserData.Value | base64 -d) echo $userData > $p.txt done`
|
||||
- Get launch configurations
|
||||
- `aws autoscaling describe-launch-configurations`
|
||||
- `aws ec2 describe-launch-templates`
|
||||
- Start instance with user data script that runs on startup:
|
||||
- `aws ec2 run-instances --image-id ami-<id> --count 1 --instance-type m3.medium --iam-instance-profile <profile_name> --subnet-id subnet-<id> --security-group-ids sg-<id> --tag-specifications 'ResourceType=instance,Tags=[{Key=Name,Value=spark-worker-5739ecea19a4}]' --user-data file://<startup_script> --profile <profile_name> --region <region>`
|
||||
- Redshift
|
||||
- Get info on clusters
|
||||
- `aws redshift describe-clusters`
|
||||
- Get credentials for cluster
|
||||
- `aws get-cluster-credentials --db-user root --db-name <database_name> --cluster-identifier <cluster_id> --duration-seconds 3600`
|
||||
- Check monitoring
|
||||
- Access Analyzer
|
||||
- `aws accessanalyzer list-analyzers --region=<region>`
|
||||
- CloudTrail
|
||||
- `aws cloudtrail describe-trails --region=<region>`
|
||||
- GuardDuty
|
||||
- `aws guardduty list-detectors --region=<region>`
|
||||
- Extract info from CloudTrail
|
||||
- `aws logs describe-log-groups --region=<region> --profile <profile_name>`
|
||||
- Filter for activity referring to a specific account
|
||||
- `aws logs filter-log-events --log-group-name "CloudTrail/DefaultLogGroup" --filter-pattern "<account_ID>" --max-items 10 --profile <profile_name> --region <region> | jq ".events[].message" | sed 's/\\//g'
|
||||
`
|
||||
Reference in New Issue
Block a user