stratus-red-team icon indicating copy to clipboard operation
stratus-red-team copied to clipboard

New attack technique: SendSerialConsoleSSHPublicKey

Open christophetd opened this issue 1 year ago • 2 comments

see also #467

https://unit42.paloaltonetworks.com/cloud-lateral-movement-techniques/

christophetd avatar Mar 01 '24 08:03 christophetd

  • https://permiso.io/blog/lucr-3-scattered-spider-getting-saas-y-in-the-cloud

christophetd avatar Mar 08 '24 11:03 christophetd

Also mentioned in the following writeup for the "ec2-instance-connect:SendSerialConsoleSSHPublicKey" permission:

  • Login via Serial Ports: AWS: https://unit42.paloaltonetworks.com/cloud-virtual-machine-attack-vectors/

siigil avatar Jul 02 '24 14:07 siigil