Cloud Offensive Framework Execution

Last updated a day ago on 2026-09-28
Created 15 days ago on 2026-09-14

About

Identifies execution of well-known cloud exploitation, enumeration, and attack-simulation frameworks on an endpoint. Adversaries run these after obtaining cloud credentials to map the compromised principal's effective permissions, discover privilege escalation paths, and pivot to the console. Pacu is tracked by MITRE as software S1091. Real-world use on compromised hosts is documented in the AWS customer incident catalog, where both the Unit 42 SugarCRM zero-day response and the AWS CIRT federated-user compromise record Pacu and ScoutSuite scanning from access keys found on EC2 hosts. Covered frameworks include: Pacu, CloudFox, ScoutSuite, PMapper, Stratus Red Team, WeirdAAL, enumerate-iam, Prowler, CloudMapper, CloudSplaining, cloud_enum, CloudBrute, SkyArk, Leonidas, Halberd, Barq, Cartography, Nimbostratus, AWSBucketDump, dsnap, aws_consoler, Redboto, cloudjack, s3scanner, CloudSploit, aws-enumerator, iam-vulnerable, Fog, and SmogCloud. Secret scanners such as TruffleHog and Gitleaks are intentionally excluded because they run routinely in CI and pre-commit hooks; their credential-validation use is covered by CloudTrail and GitHub user-agent rules. Authorized red team and cloud audit activity uses the same tooling, so alerts should be correlated with known assessment windows and operators.
Tags
Domain: EndpointDomain: CloudPlatform: AWSPlatform: LinuxPlatform: macOSPlatform: WindowsOS: LinuxOS: macOSOS: WindowsUse Case: Threat DetectionTactic: DiscoveryTactic: ExecutionData Source: Elastic DefendRule Type: Custom Query (KQL)Language: kuery
Severity
medium
Risk Score
47
MITRE ATT&CK™

Discovery (TA0007)(external, opens in a new tab or window)

Execution (TA0002)(external, opens in a new tab or window)

False Positive Examples
Authorized red team engagements and cloud security assessments use the same frameworks. Correlate with known assessment windows, operator identities, and approved change records before escalating. Security engineers running Prowler, ScoutSuite, or Cartography on a schedule for compliance or asset inventory will trigger this rule. Add host or user exceptions for known security tooling environments.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Query (Kibana Query Language)
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-endpoint.events.process*
Related Integrations

endpoint(external, opens in a new tab or window)

Query
text code block:
event.category : "process" and event.type : "start" and event.action:(start or exec) and ( process.name : ( pacu or pacu.exe or cloudfox or cloudfox.exe or weirdaal or "enumerate-iam" or enumerate_iam or scoutsuite or pmapper or prowler or prowler.exe or cloudmapper or cloudsplaining or cloud_enum or cloudbrute or cloudbrute.exe or nimbostratus or "aws-enumerator" or "aws-enumerator.exe" or skyark or awsbucketdump or dsnap or aaia or aws_consoler or awsconsoler or redboto or cloudjack or s3scanner or s3scanner.exe or cloudsploit or "iam-vulnerable" or smogcloud ) or (process.name : (stratus or stratus.exe) and process.args : (detonate or warmup or revert or cleanup)) or (process.name : cartography and process.args : ("--aws-sync-all-profiles" or "--aws-requested-syncs")) or ( process.name : (python* or pipx or uv or uvx or go or node) and process.command_line : ( *cloudfox* or *enumerate_iam* or *enumerate-iam* or *weirdAAL* or *aws_consoler* or *-m pacu* or *pacu.py* or *aws_escalate* or *scoutsuite* or *pmapper* or *cloudmapper* or *cloudsplaining* or *nimbostratus* or *leonidas-framework* or *cloud_enum* or *halberd* or *skyark* or *awsbucketdump* or *stratus-red-team* or *prowler* or *cloudsploit* or *cloudbrute* or *fog-aws* or *barq* ) ) ) and not process.command_line : ( *pip install* or *pip3 install* or *pipx install* or *uv pip install* or *uv tool install* or *go get* or *go install* or *go build* or *go test* or *npm install* or *--help* or *--version* or *git clone* or *pytest* or "*site-packages/pip*" ) and not process.parent.name : (dpkg or rpm or apt or yum or dnf or brew or pip or pip3)

Install detection rules in Elastic Security

Detect Cloud Offensive Framework Execution in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).