  • Ghostwriter can keep track of clients, projects, findings, and infrastructure.
  • Ghostwriter automates routine assessment reporting tasks allowing operators to focus their time on analysis and custom content creation rather than formatting.


For the past couple months, a few of us at SpecterOps have focused on updating Ghostwriter to improve usability, enhance reporting, and enable the project…


Given proper trust relationships, a role assumed with temporary credentials can be preserved indefinitely and give an attacker persistent access to an AWS environment by role chaining in a cyclical pattern.

On a recent red-team engagement, one of our objectives was to test the client AWS security posture and gain access to any/all AWS accounts. After a few weeks of pursuing other objectives, we were able to obtain STS credentials for federated users that were being written to a publicly accessible log whenever the STS credentials were being requested. This included the access key, secret key, and session token. Gaining…


