
Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

IAM Vulnerable uses the Terraform binary and your AWS credentials to deploy over 250 IAM resources into your selected AWS account. Within minutes, you can start learning how to identify and exploit vulnerable IAM configurations that allow for privilege escalation.
Hey all. IAM Vulnerable is still immensely useful for understanding the basic building blocks of AWS IAM privilege escaltion. However, a few years after making IAM vulnerable, I created CloudFoxable, a CTF style version that teaches you the basics of cloud penetration testing more wholisisticlly. - @sethsec
Join us on the RedSec discord server
🦊 Currently supported privilege escalation paths: 31
Blog Post: IAM Vulnerable - An AWS IAM Privilege Escalation Playground
This quick start outlines an opinionated approach to getting IAM Vulnerable up and running in your AWS account as quickly as possible. You might have many of these steps already completed, or you might want to tweak things to work with your current configuration. Check out the Other Use Cases section in this repository for some additional configuration options.
aws sts get-caller-identity.git clone https://github.com/BishopFox/iam-vulnerablecd iam-vulnerable/terraform initexport TF_VAR_aws_local_profile=PROFILE_IN_AWS_CREDENTIALS_FILE_IF_OTHER_THAN_DEFAULTexport TF_VAR_aws_local_creds_file=FILE_LOCATION_IF_NON_DEFAULTterraform planterraform applycp ~/.aws/credentials ~/.aws/credentials.backuptail -n +7 aws_credentials_file_example | sed s/111111111111/$(aws sts get-caller-identity | grep Account | awk -F\" '{print $4}')/g >> ~/.aws/credentialsCleanup
Whenever you want to remove all of the IAM Vulnerable-created resources, you can run these commands:
cd iam-vulnerable/terraform destroyAlternative Cleanup (When Terraform State is Lost)
In a case where you have deployed iam-vulnerable using Terraform but no longer have access to the state file (and terraform destroy does not work), you can use the following cleanup scripts:
# Python version (requires boto3)
./cleanup-scripts/cleanup_iam_vulnerable.py --dry-run
# Bash version (requires AWS CLI and jq)
./cleanup-scripts/cleanup_iam_vulnerable.sh --dry-run
These scripts will:
Important: Always run with --dry-run first to see what would be deleted. See cleanup-scripts/CLEANUP_README.md for detailed usage instructions.
The Terraform binary just used your default AWS account profile credentials to create:
By default, every role created by this Terraform module is assumable by the user or role you used to run Terraform.
assume_role_policy ARN, see Other Use Cases.Deploying IAM vulnerable in its default configuration will cost nothing. See the next section to learn how to enable non-default modules that do incur cost, and how much each module will cost per month if you deploy it.
IAM Vulnerable groups certain resources together in modules. Some of the modules are enabled by default (the ones that don't have any cost implications), and others are disabled by default (the ones that incur cost if deployed). This way, you can enable specific modules as needed.
For example, when you are ready to play with the exploit paths like ssm:StartSession that involve resources outside of IAM, you can deploy and tear down these resources on demand by uncommenting the module in the iam-vulnerable/main.tf file, and re-running terraform apply: