Cloud Offensive Framework Execution
Identifies execution of well-known cloud exploitation, enumeration, and attack-simulation frameworks on an endpoint. Adversaries run these after obtaining cloud credentials to map the compromised principal's…
Description
Identifies execution of well-known cloud exploitation, enumeration, and attack-simulation frameworks on an endpoint. Adversaries run these after obtaining cloud credentials to map the compromised principal's effective permissions, discover privilege escalation paths, and pivot to the console. Pacu is tracked by MITRE as software S1091. Real-world use on compromised hosts is documented in the AWS customer incident catalog, where both the Unit 42 SugarCRM zero-day response and the AWS CIRT federated-user compromise record Pacu and ScoutSuite scanning from access keys found on EC2 hosts. Covered frameworks include: Pacu, CloudFox, ScoutSuite, PMapper, Stratus Red Team, WeirdAAL, enumerate-iam, Prowler, CloudMapper, CloudSplaining, cloud_enum, CloudBrute, SkyArk, Leonidas, Halberd, Barq, Cartography, Nimbostratus, AWSBucketDump, dsnap, aws_consoler, Redboto, cloudjack, s3scanner, CloudSploit, aws-enumerator, iam-vulnerable, Fog, and SmogCloud. Secret scanners such as TruffleHog and Gitleaks are intentionally excluded because they run routinely in CI and pre-commit hooks; their credential-validation use is covered by CloudTrail and GitHub user-agent rules. Authorized red team and cloud audit activity uses the same tooling, so alerts should be correlated with known assessment windows and operators.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 3 ATT&CK techniques it maps to.
- Log source category
- event_index
Known benign triggers
- Authorized red team engagements and cloud security assessments use the same frameworks. Correlate with known assessment windows, operator identities, and approved change records before escalating.
- Security engineers running Prowler, ScoutSuite, or Cartography on a schedule for compliance or asset inventory will trigger this rule. Add host or user exceptions for known security tooling environments.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| github.com/BishopFox/cloudfox | Only this detection cites it |
| github.com/FSecureLABS/leonidas | Only this detection cites it |
| github.com/RhinoSecurityLabs/pacu | Only this detection cites it |
| github.com/cyberark/SkyArk | Only this detection cites it |
| github.com/duo-labs/cloudmapper | Only this detection cites it |
| github.com/nccgroup/PMapper | Only this detection cites it |
| github.com/nccgroup/ScoutSuite | Only this detection cites it |
| github.com/prisma-cloud/dsnap | Only this detection cites it |
| github.com/ramimac/aws-customer-security-incidents | 2 |
| github.com/salesforce/cloudsplaining | Only this detection cites it |
| github.com/vectra-ai-research/Halberd | Only this detection cites it |
| stratus-red-team.cloud | Only this detection cites it |
| unit42.paloaltonetworks.com/sugarcrm-cloud-incident-black-hat/ | Only this detection cites it |
| www.uptycs.com/blog/threat-research-report-team/threat-actor-mitigation-with-cloud-security | Only this detection cites it |
From the source
- At source
- Open at source
- Upstream identifier
- 77c476eb-6a49-402a-a561-267ae66daa5e
- Tagged by the source as
- Data Source: Elastic DefendDomain: CloudDomain: EndpointOS: LinuxOS: macOSOS: WindowsPlatform: AWSPlatform: LinuxPlatform: macOSPlatform: WindowsResources: Investigation GuideRule Type: Custom Query (KQL)Tactic: DiscoveryTactic: ExecutionUse Case: Threat Detection
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Sep 29, 2026
- Version
- 1