Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
aws-vault — 一个用于在开发环境中安全存储和访问 AWS 凭据的保险库 | Kitploit
工具/GitHubGitHub/99designs/aws-vault
云基础设施安全通用工具加密/解密工具云安全DevSecOps秘密检测身份与访问管理 (IAM)身份验证
GitHub99designs/aws-vault

aws-vault

一个用于在开发环境中安全存储和访问 AWS 凭据的保险库

查看仓库
9.0k8279个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

AWS Vault

Downloads Continuous Integration

[!WARNING] 该项目已被废弃,不再接收任何更新。如果您希望继续接收更新 或做出贡献,请随时查看活跃分支:https://github.com/ByteNess/aws-vault

AWS Vault 是一款用于在开发环境中安全存储和访问 AWS 凭证的工具。

AWS Vault 将 IAM 凭证存储在操作系统的安全密钥库中,然后基于这些凭证生成临时凭证,以暴露给您的 shell 和应用程序。它旨在与 AWS CLI 工具互补,并能够识别 ~/.aws/config 中的配置文件和配置。

查看公告博客文章了解更多详情。

安装

您可以通过以下方式安装 AWS Vault:

  • 下载最新版本
  • 在 macOS 上使用 Homebrew:brew install aws-vault
  • 在 macOS 上使用 MacPorts:port install aws-vault
  • 在 Windows 上使用 Chocolatey:choco install aws-vault
  • 在 Windows 上使用 Scoop:scoop install aws-vault
  • 在 Linux 上使用 Homebrew on Linux:brew install aws-vault
  • 在 Arch Linux 上:pacman -S aws-vault
  • 在 Gentoo Linux 上:emerge --ask app-admin/aws-vault(需先启用 Guru)
  • 在 FreeBSD 上:pkg install aws-vault
  • 在 OpenSUSE 上:启用 devel:languages:go 仓库后执行 zypper install aws-vault
  • 使用 Nix:nix-env -i aws-vault
  • 使用 asdf-vm:asdf plugin-add aws-vault https://github.com/karancode/asdf-aws-vault.git && asdf install aws-vault <version>

文档

配置、用法、提示和技巧请参阅 USAGE.md 文件。

存储后端

支持的存储后端包括:

  • macOS Keychain
  • Windows Credential Manager
  • Secret Service(Gnome Keyring、KWallet)
  • KWallet
  • Pass
  • 加密文件

使用 --backend 标志或 AWS_VAULT_BACKEND 环境变量来指定。

快速开始

# Store AWS credentials for the "jonsmith" profile
$ aws-vault add jonsmith
Enter Access Key Id: ABDCDEFDASDASF
Enter Secret Key: %%%

# Execute a command (using temporary credentials)
$ aws-vault exec jonsmith -- aws s3 ls
bucket_1
bucket_2

# open a browser window and login to the AWS Console
$ aws-vault login jonsmith

# List credentials
$ aws-vault list
Profile                  Credentials              Sessions
=======                  ===========              ========
jonsmith                 jonsmith                 -

# Start a subshell with temporary credentials
$ aws-vault exec jonsmith
Starting subshell /bin/zsh, use `exit` to exit the subshell
$ aws s3 ls
bucket_1
bucket_2

工作原理

aws-vault 使用 Amazon 的 STS 服务,通过 GetSessionToken 或 AssumeRole API 调用来生成临时凭证。这些凭证会在短时间内过期,从而降低凭证泄露的风险。

然后,AWS Vault 通过以下两种方式之一将临时凭证暴露给子进程:

  1. 环境变量被写入子进程。请注意下面示例中 AWS 凭证是如何被写入的
    $ aws-vault exec jonsmith -- env | grep AWS
    AWS_VAULT=jonsmith
    AWS_DEFAULT_REGION=us-east-1
    AWS_REGION=us-east-1
    AWS_ACCESS_KEY_ID=%%%
    AWS_SECRET_ACCESS_KEY=%%%
    AWS_SESSION_TOKEN=%%%
    AWS_CREDENTIAL_EXPIRATION=2020-04-16T11:16:27Z
    
  2. 本地元数据服务器被启动。这种方式的优势在于,任何使用 Amazon SDK 的程序都会根据需要自动刷新凭证,因此会话时间可以尽可能短。
    $ aws-vault exec --server jonsmith -- env | grep AWS
    AWS_VAULT=jonsmith
    AWS_DEFAULT_REGION=us-east-1
    AWS_REGION=us-east-1
    AWS_CONTAINER_CREDENTIALS_FULL_URI=%%%
    AWS_CONTAINER_AUTHORIZATION_TOKEN=%%%
    

默认使用环境变量,但您可以通过 exec 命令上的 --server 标志选择使用本地实例元数据服务器。

角色和 MFA

最佳实践是创建角色来委派权限。为了安全起见,您还应要求用户提供由多因素认证(MFA)设备生成的一次性密钥。

首先,您需要在 IAM 中创建用户和角色,并设置 MFA 设备。然后您可以设置 IAM 角色以强制执行 MFA。

以下是一个使用角色和 MFA 的配置示例:

[default]
region = us-east-1

[profile jonsmith]
mfa_serial = arn:aws:iam::111111111111:mfa/jonsmith

[profile foo-readonly]
source_profile = jonsmith
role_arn = arn:aws:iam::22222222222:role/ReadOnly

[profile foo-admin]
source_profile = jonsmith
role_arn = arn:aws:iam::22222222222:role/Administrator
mfa_serial = arn:aws:iam::111111111111:mfa/jonsmith

[profile bar-role1]
source_profile = jonsmith
role_arn = arn:aws:iam::333333333333:role/Role1
mfa_serial = arn:aws:iam::111111111111:mfa/jonsmith

[profile bar-role2]
source_profile = bar-role1
role_arn = arn:aws:iam::333333333333:role/Role2
mfa_serial = arn:aws:iam::111111111111:mfa/jonsmith

以下是 aws-vault 的行为预期

CommandCredentialsCachedMFA
aws-vault exec jonsmith --no-sessionLong-term credentialsNoNo
aws-vault exec jonsmithsession-tokensession-tokenYes
aws-vault exec foo-readonlyroleNoNo
aws-vault exec foo-adminsession-token + rolesession-tokenYes
aws-vault exec foo-admin --duration=2hroleroleYes
aws-vault exec bar-role2session-token + role + rolesession-tokenYes
aws-vault exec bar-role2 --no-sessionrole + roleroleYes

开发

macOS 发布版本经过代码签名,以避免 Keychain 中出现额外提示。您可以通过以下方式验证:

$ codesign --verify --verbose $(which aws-vault)

如果您自己开发或编译 aws-vault 二进制文件,可以通过访问 Keychain Access > Certificate Assistant > Create Certificate -> Certificate Type: Code Signing 来生成自签名证书。然后您可以使用以下命令对二进制文件进行签名:

$ go build .
$ codesign --sign <Name of certificate created above> ./aws-vault

参考资料与灵感来源

  • https://github.com/pda/aws-keychain
  • https://docs.aws.amazon.com/IAM/latest/UserGuide/MFAProtectedAPI.html
  • https://docs.aws.amazon.com/IAM/latest/UserGuide/IAMBestPractices.html#create-iam-users
  • https://github.com/makethunder/awsudo
  • https://github.com/AdRoll/hologram
  • https://github.com/realestate-com-au/credulous
  • https://github.com/dump247/aws-mock-metadata
  • https://boto.readthedocs.org/en/latest/boto_config_tut.html
下载工具