[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/teamtnt-operations-cloud-environments/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/teamtnt-operations-cloud-environments/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Cloud Cybersecurity Research](https://unit42.paloaltonetworks.com/category/cloud-cybersecurity-research/ "Cloud Cybersecurity Research")  
  [Cloud Cybersecurity Research](https://unit42.paloaltonetworks.com/category/cloud-cybersecurity-research/)

# TeamTNT Actively Enumerating Cloud Environments to Infiltrate Organizations

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 13 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Nathaniel Quist](https://unit42.paloaltonetworks.com/author/nathaniel-quist/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 4, 2021

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cloud Cybersecurity Research](https://unit42.paloaltonetworks.com/category/cloud-cybersecurity-research/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [AWS](https://unit42.paloaltonetworks.com/tag/aws/)
  * [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/)
  * [Cryptojacking](https://unit42.paloaltonetworks.com/tag/cryptojacking/)
  * [Google Cloud](https://unit42.paloaltonetworks.com/tag/google-cloud/)
  * [IAM](https://unit42.paloaltonetworks.com/tag/iam/)
  * [Scraping](https://unit42.paloaltonetworks.com/tag/scraping/)
  * [TeamTnT](https://unit42.paloaltonetworks.com/tag/teamtnt/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/teamtnt-operations-cloud-environments/?pdf=download&lg=en&_wpnonce=279fa6c5e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/teamtnt-operations-cloud-environments/?pdf=print&lg=en&_wpnonce=279fa6c5e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=TeamTNT%20Actively%20Enumerating%20Cloud%20Environments%20to%20Infiltrate%20Organizations&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fteamtnt-operations-cloud-environments%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fteamtnt-operations-cloud-environments%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fteamtnt-operations-cloud-environments%2F&title=TeamTNT%20Actively%20Enumerating%20Cloud%20Environments%20to%20Infiltrate%20Organizations "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fteamtnt-operations-cloud-environments%2F&text=TeamTNT%20Actively%20Enumerating%20Cloud%20Environments%20to%20Infiltrate%20Organizations "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fteamtnt-operations-cloud-environments%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=TeamTNT%20Actively%20Enumerating%20Cloud%20Environments%20to%20Infiltrate%20Organizations%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fteamtnt-operations-cloud-environments%2F "Share in Mastodon")

## Executive Summary

TeamTNT has been evolving their cloud-focused cryptojacking operations for some time now. TeamTNT operations have targeted and, after compromise, [exfiltrated AWS credentials](https://www.cadosecurity.com/post/team-tnt-the-first-crypto-mining-worm-to-steal-aws-credentials), targeted [Kubernetes clusters](https://unit42.paloaltonetworks.com/hildegard-malware-teamtnt/) and created new malware called Black-T that [integrates open source cloud native tools](https://unit42.paloaltonetworks.com/black-t-cryptojacking-variant/) to assist in their cryptojacking operations. TeamTNT operations are now using compromised AWS credentials to enumerate AWS cloud environments, via the AWS platform's API. These actions attempt to identify all [Identity and Access Management (IAM)](https://docs.aws.amazon.com/cli/latest/reference/iam/index.html) permissions, [Elastic Compute Cloud (EC2)](https://docs.aws.amazon.com/cli/latest/reference/ec2/index.html) instances, [Simple Storage Service (S3)](https://docs.aws.amazon.com/cli/latest/reference/s3/index.html) buckets, [CloudTrail](https://docs.aws.amazon.com/cli/latest/reference/cloudtrail/index.html) configurations and [CloudFormation](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/index.html) operations granted to the compromised AWS credential. TeamTNT operations are now also targeting the credentials of 16 additional applications, including those of AWS and Google Cloud credentials, which may be stored on the compromised cloud instance, if installed.

The presence of Google Cloud credentials being targeted for collections represents the first known instance of an attacker group targeting IAM credentials on compromised cloud instances outside of AWS. While it is still possible that Microsoft Azure, Alibaba Cloud, Oracle Cloud or IBM Cloud IAM credentials could be targeted using similar methods, Unit 42 researchers have yet to find evidence of credentials from these cloud service providers (CSPs) being targeted. TeamTNT first started collecting AWS credentials on cloud instances they had compromised as early as [August 2020](https://www.cadosecurity.com/post/team-tnt-the-first-crypto-mining-worm-to-steal-aws-credentials).

In addition to the targeting of 16 application credentials from cloud applications and platforms, TeamTNT has added the usage of the open-source Kubernetes and cloud penetration toolset [Peirates](https://github.com/inguardians/peirates) to their reconnaissance operations. With these techniques available, TeamTNT actors are increasingly more capable of gathering enough information in target AWS and Google Cloud environments to perform additional post-exploitation operations. This could lead to more cases of lateral movement and potential privilege escalation attacks that could ultimately allow TeamTNT actors to acquire administrative access to an organization's entire cloud environment.

That said, TeamTNT operations are still focused on cryptojacking. The TeamTNT cryptojacking operations represented within this writing have collected 6.52012192 Monero coins, which at the time of this writing equaled $1,788 USD. The mining operation was found to be operating at an average speed of 77.7KH/s across eight mining workers. Operations using this Monero wallet address have continued for 114 days as of the time of this writing.

Palo Alto Networks [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud) customers are protected from these threats through the Runtime Protection feature, Cryptominer Detection feature and the Prisma Cloud Compute Kubernetes Compliance Protection, which alerts on an insufficient Kubernetes configuration and provides secure alternatives. Additionally, Palo Alto Networks [VM-Series](https://www.paloaltonetworks.com/prisma/vm-series) and [CN-Series](https://www.paloaltonetworks.com/network-security/cn-series) products offer cloud protections that can prevent network connections from cloud instances toward known malicious IP addresses and URLs.

## Enumeration Techniques

Unit 42 researchers identified one of TeamTNT's malware repositories, hxxp://45.9.148\[.\]35/chimaera/sh/, which contained several bash scripts designed to perform cryptojacking operations, exploitation, lateral movement and credential scraping operations, as shown in Figure 1. This malware repository, referred to as the Chimaera Repository, highlights the expanding scope of TeamTNT operations within cloud environments as well as a target set for current and future operations.
![This malware repository, referred to as the Chimaera Repository, highlights the expanding scope of TeamTNT operations within cloud environments as well as a target set for current and future operations.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image.png) Figure 1. TeamTNT's Chimaera Repository.

Within the Chimaera repository, there were three scripts that specifically highlight TeamTNT's expanding cloud targeting capabilities and intent. The first script is grab\_aws-data.sh, (SHA256: a1e9cd08073e4af3256b31e4b42f3aa69be40862b3988f964e96228f91236593), which focuses on enumerating AWS cloud environments using known AWS IAM credentials. The second script, bd\_aws.sh, (SHA256: de3747a880c4b69ecaa92810f4aac20fe5f6d414d9ced29f1f7ebb82cd0f3945) scrapes all known Secure Shell Protocol (SSH) keys from an AWS instance and identifies all executable programs currently running on that instance. Finally, the script search.sh (SHA256: ed40bce040778e2227c869dac59f54c320944e19f77543954f40019e2f2b0c35) performs a search for configuration files containing application credentials stored on a given host. These scripts are newly discovered and directly highlight the targeting of cloud native applications within both AWS and Google Cloud environments.

#### Enumerating AWS Environments

The bash script, grab\_aws-data.sh, contains 70 unique AWS CommandLine Interface ([AWS CLI](https://aws.amazon.com/cli/)) commands designed to enumerate seven AWS services, [IAM configurations](https://docs.aws.amazon.com/cli/latest/reference/iam/index.html), [EC2 instances](https://docs.aws.amazon.com/cli/latest/reference/ec2/index.html), [S3 buckets](https://docs.aws.amazon.com/cli/latest/reference/s3/index.html), [support cases](https://docs.aws.amazon.com/cli/latest/reference/support/index.html) and [direct connections](https://docs.aws.amazon.com/cli/latest/reference/directconnect/index.html), in addition to any [CloudTrail](https://docs.aws.amazon.com/cli/latest/reference/cloudtrail/index.html) and [CloudFormation](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/index.html) operations available to a given AWS IAM credential. As seen in Figure 2, all enumerated values obtained through the AWS enumeration process will be stored within the local directory /var/tmp/.../...TnT.../aws-account-data/ on the compromised system.
![All enumerated values obtained through the AWS enumeration process will be stored within the local directory /var/tmp/.../...TnT.../aws-account-data/ on the compromised system.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-1.png) Figure 2. TeamTNT's grab\_aws.sh script.

Navigate to the Appendix for a list of all 70 unique AWS CLI commands present within the TeamTNT script grab\_aws-data.sh. As a summary, the TeamTNT script contained commands for the following seven AWS services:

* 44 EC2 instance commands.
* 14 IAM commands.
* 4 Direct Connect commands.
* 4 CloudFormation commands.
* 2 CloudTrail commands.
* 1 S3 command.
* 1 Support command.

#### Credential Scraping

TeamTNT actors have also expanded their credential scraping capabilities to include the identification and collection of 16 unique applications, which may be present on the compromised cloud endpoint and for any of the known user accounts on the cloud instance, including the root account. There has been [additional research](https://www.trendmicro.com/en_us/research/21/e/teamtnt-extended-credential-harvester-targets-cloud-services-other-software.html) involving this particular script. These applications were listed within the script search.sh:

* SSH keys.
* AWS keys.
  * S3 clients.
    * [s3backer](https://github.com/archiecobbs/s3backer)
    * [s3proxy](https://github.com/gaul/s3proxy)
    * [s3ql](https://github.com/s3ql/s3ql) (Google Cloud capable as well)
    * [passwd-s3fs](https://github.com/s3fs-fuse/s3fs-fuse)
    * [s3cfg](https://s3tools.org/kb/item14.htm)
* Docker.
* GitHub.
* Shodan.
* Ngrok.
* [Pidgin](https://developer.pidgin.im/wiki/ConfigurationFiles).
* [Filezilla](https://filezilla-project.org/).
* [Hexchat](https://hexchat.github.io/).
* Google Cloud.
* [Project Jupyter](https://jupyter.org/).
* Server Message Block (SMB) clients.

Several of these applications are noteworthy. The presence of Google Cloud credentials tops the list as this is the first known instance of an attacker group targeting IAM credentials outside of AWS (see Figure 3). It is possible that Microsoft Azure, Alibaba Cloud, Oracle Cloud or IBM Cloud environments could be targeted using similar techniques, but Unit 42 researchers have yet to find evidence of these CSPs being targeted. Researchers believe that it is only a matter of time before TeamTNT will develop functionality similar to that of grab\_aws-data.sh described above, but targeting Google Cloud environments.
![The light blue box highlights the section of code that shows TeamTNT's search.sh script searching for Google Cloud credentials, the first known instance of an attacker group targeting IAM credentials outside of AWS, potentially for the purpose of enumerating cloud environments](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-2.png) Figure 3. TeamTNT's search.sh script searching for Google Cloud credentials.

## Lateral Movement Operations

In addition to the 16 applications listed above, the following applications are specifically targeted for lateral movement operations.

#### Weaveworks

Within the search.sh script, there are several applications identified which display evolving attack patterns for TeamTNT operations. Within the Chimaera repository, Unit 42 researchers identified several scripts that single out specific applications. One of those applications is [Weaveworks](https://www.weave.works/docs/net/latest/overview/) (see Figure 4). Weave is a microservice network mesh application developed for container infrastructures such as Docker and Kubernetes, and allows for microservices to be running on one or multiple hosts while simultaneously maintaining network connectivity. By targeting Weave installations, TeamTNT operations have the potential to move laterally within a container infrastructure using the Weave network mesh application. As can be seen within the base64 encoded code in the script setup\_scope.sh, (SHA256: 584c6efed8bbce5f2c52a52099aafb723268df799f4d464bf5582a9ee83165c1), TeamTNT is targeting Docker user accounts that contain Weave container information.
![As can be seen within the base64 encoded code in the script setup\_scope.sh, (SHA256: 584c6efed8bbce5f2c52a52099aafb723268df799f4d464bf5582a9ee83165c1), TeamTNT is targeting Docker user accounts that contain Weave container information.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-3.png) Figure 4. TeamTNT script setup\_scope.sh base64 decode code. ![This shows one way TeamTNT is able to target Docker for the purpose of cryptojacking.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-4.png) Figure 5. Local Docker image creation for Monero mining.

#### Project Jupyter

Additionally, the Project Jupyter application is listed as a target of TeamTNT operations through two sources within the Chimaera repository, first within the search.sh script as the target for credential scraping, and as a beta lateral movement script, spread\_jupyter\_tmp.sh (SHA256: 0d7912e62bc663c9ba6bff21ae809e458b227e3ceec0abac105d20d5dc533a22).

Unit 42 researchers also found reference to Project Jupyter within a known TeamTNT actor's Twitter account. The Twitter account, @HildeTnT, posted the following image (Figure 6) on their Twitter feed, replying to a potentially compromised Jupyter endpoint. The German-language text translates to "Hahaha we take that as a compliment ^^ btw blocking the shell alone brings 0% security ..." The presence of this Twitter exchange highlights the fact that TeamTNT is actively using the scripts listed within the Chimaera repository and targeting these additional cloud applications.
![The German-language text translates to “Hahaha we take that as a compliment ^^ btw blocking the shell alone brings 0% security …” The presence of this Twitter exchange highlights the fact that TeamTNT is actively using the scripts listed within the Chimaera repository and targeting these additional cloud applications.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-5.png) Figure 6. TeamTNT actor replying to a message from a potentially compromised Jupyter endpoint.

## Peirates

Unit 42 researchers have identified that TeamTNT actors are using the open source container and cloud penetration tool [Peirates](https://github.com/inguardians/peirates). As seen in Figure 7, Peirates allows actors to perform several attack functions against AWS and Kubernetes instances. This tool could enable TeamTNT actors to investigate and identify misconfigurations or potential vulnerabilities within Kubernetes and Cloud environments and could allow TeamTNT to perform additional compromising actions against cloud infrastructure.
!["Peirates penetration testing options are shown here. Peirates allows actors to perform several attack functions against AWS and Kubernetes instances. This tool could enable TeamTNT actors to investigate and identify misconfigurations or potential vulnerabilities within Kubernetes and Cloud environments and could allow TeamTNT to perform additional compromising actions against cloud infrastructure. "](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-6.png) Figure 7. Peirates penetration testing options.

## Monero Mining Operations

TeamTNT operations are still focused on cryptojacking. The previous sections presented the findings of new techniques used by TeamTNT actors to expand their cryptojacking infrastructure. The following section will focus on the findings related to the processes of mining applications TeamTNT uses to perform their cryptojacking operations.

#### Local Docker Image

Of interest is the script file docker.container.local.spread.txt, which lists the name of a local Docker image, as shown in Figure 8. The Docker image is a local Docker image, meaning it is not hosted and downloaded from an external docker repository such as Docker Hub. Researchers did search Docker Hub for the presence of this Docker image and none were found.
![Of interest is the script file docker.container.local.spread.txt, which lists the name of a local Docker image. The Docker image is a local Docker image, meaning it is not hosted and downloaded from an external docker repository such as Docker Hub.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-7.png) Figure 8. Contents of the docker.container.local.spread.txt.

The Docker container is created to provide a host for TeamTNT's Monero (XMR) mining operation. Shown in Figure 5, a Docker image is created with the name mangletmpuser/fcminer. This image is then started and directed to navigate to the Chimaera repository file setup\_xmr.sh, (SHA256: 5ddd226d400cc0b49d0175ba06a7e55cb2f5e9586111464bcf7b3bd709417904), which will initiate the Docker cryptomining process, using the open source [XMRig](https://github.com/xmrig/xmrig) application within a Docker container.

#### New Monero Wallet

Unit 42 researchers identified a new Monero wallet address that has never before been witnessed in relation to TeamTNT operations, 46EPFzvnX5GH61ejkPpNcRNm8kVjs8oHS9VwCkKRCrJX27XEW2y1NPLfSa54DGHxqnKfzDUVW1jzBfekk3hrCVCmAUrFd3H. This Monero wallet address was associated with the Monero public mining pool pool.supportxmr\[.\]com:3333, as shown in Figure 9.

![Unit 42 researchers identified a new Monero wallet address that has never before been witnessed in relation to TeamTNT operations, 46EPFzvnX5GH61ejkPpNcRNm8kVjs8oHS9VwCkKRCrJX27XEW2y1NPLfSa54DGHxqnKfzDUVW1jzBfekk3hrCVCmAUrFd3H. This Monero wallet address was associated with the Monero public mining pool pool.supportxmr\[.\]com:3333.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-8.png) Figure 9. SupportXMR public mining pool configuration. In Figure 10, this mining pool address displays that the TeamTNT mining operation has collected 6.52012192 Monero coins, which at the time of this writing equaled $1,788 USD. The mining operation was found to be operating at 77.7KH/s, across eight mining workers at the time of this writing, and operations using this Monero wallet address have continued for 114 days. At an operating speed of 77.7KH/s, this operation is considered to be a small mining operation for a group like TeamTNT.

![This mining pool address displays that the TeamTNT mining operation has collected 6.52012192 Monero coins, which at the time of this writing equaled $1,788 USD.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/06/word-image-9.png) Figure 10. SupportXMR mining pool dashboard.

## Conclusion

Given TeamTNT's integration of tools such as Peirates, their targeting of cloud native network mesh applications such as Weave, their operations around Kubernetes and Black-T, and their targeting and subsequent taunting of organizations using Project Jupyter, TeamTNT actors are suspected to be employing all tools listed within this blog on a regular basis. TeamTNT actors are specifically targeting cloud platforms in an attempt to circumvent future security detection tools and embed themselves into the organization's cloud environment.

We recommend that organizations operating with cloud environments monitor for and block all network connections associated with TeamTNT's Chimaera repository, as well as historic Command and Control (C2) endpoints. Using a cloud native security platform will significantly reduce the cloud infrastructure's attack surface and allow organizations to monitor for risks.

The following tips are highly recommended by Unit 42 researchers to assist in the protection of cloud infrastructure.

* Enforce least-privilege IAM access policies to all cloud IAM roles and permissions. Where applicable, use short-lived or one-time-use IAM credentials for service accounts.
* Monitor and block network traffic to known malicious endpoints.
* Only deploy vetted container images within production environments.
* Implement and use Infrastructure as Code (IaC) scanning platforms to prevent insecure cloud instances from being deployed into production environments.
* Use cloud infrastructure configuration scanning tools that enable governance, risk management and compliance (GRC) to identify potentially threatening misconfigurations.
* Use cloud endpoint agents to monitor and prevent the running of known malicious applications within cloud infrastructure.

Palo Alto Networks [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud) customers are protected from these threats through the Runtime Protection feature, Cryptominer Detection feature and the Prisma Cloud Compute Kubernetes Compliance Protection, which alerts on an insufficient Kubernetes configuration and provides secure alternatives. Additionally, Palo Alto Networks [VM-Series](https://www.paloaltonetworks.com/prisma/vm-series) and [CN-Series](https://www.paloaltonetworks.com/network-security/cn-series) products offer cloud protections that can prevent network connections from cloud instances toward known malicious IP addresses and URLs.

#### Indicators of Compromise

###### Chimaera Repository Files

|------------------------------------------------------------------|--------------------------------------------------------|
| **SHA256**                                                       | **File**                                               |
| a698562d56715c138750163c84727a1f2edb9d92f231994abf7ae82ef62006bf | chimaera/bin/1.0.4.tar.gz                              |
| bcd43d4046c64d15da4e87984306dd14dc80daa904a6477ad2b921c49c2f414d | chimaera/bin/64bit/aws\_zig                             |
| 3aae4a2bf41aedaa3b12a2a97398fa89a9818b4bec433c20b4e724505277af83 | chimaera/bin/64bit/bob                                 |
| 134e9ab62a8efe80a27e2869bd6e98d0afe635e0e0750eb117ff833dc9447c28 | chimaera/bin/64bit/docker-escape                       |
| 45aabbda369956ff04ba4e6bf345cbaa072d49dd4b90c35c7be8c0c96a115733 | chimaera/bin/64bit/hawkeye                             |
| e673ef9910a9d6319be598be72430f1b04c299b48e5cd95ce7ccafac273072f3 | chimaera/bin/64bit/index.html                          |
| 456041c34e7a992e76320121b7a6b5a47f12b1ed069e1de735543f5b2a1f1a68 | chimaera/bin/64bit/pei                                 |
| bcd43d4046c64d15da4e87984306dd14dc80daa904a6477ad2b921c49c2f414d | chimaera/bin/64bit/TNT\_AWS                             |
| d5063df016a6af531ed4e6dd222ff4dbbb5b3b0c9075ad642e94adde8e481cbe | chimaera/bin/64bit/TNT\_Kubernetes\_e\_u                  |
| 9504b74906cf2c4aba515de463f20c02107a00575658e4637ac838278440d1ae | chimaera/bin/64bit/TNT\_MassPwn                         |
| 15f8cf9c0ed9891f20be37130c1d0e30946e4e14e00a1b2824da22c6c94b8fe3 | chimaera/bin/64bit/wget.rpm.tar.gz                     |
| efdf041abcb93f97a3b46624d18d1c8153711f939298c46a4a48388e7ec1bd1e | chimaera/bin/64bit/xmr                                 |
| ee7799a42c2f487df7405d0aac06496c9a5bb58daecfb135f6f58e3b3aeedf69 | chimaera/bin/64bit/xmr.xz                              |
| 900b17ae0081052fb63a7d74232048cfbc2716cdedbe0ab14cf64b7d387d4329 | chimaera/bin/64bit/xmrig                               |
| 84078b10ad532834eb771231a068862182efb93ce1e4a8614dfca5ae3229ed94 | chimaera/bin/64bit/xmrig\_ps\_e                          |
| 825c60dd1bb32cd6b7e6686f425c461532093b1e9f6ca662c1ea9b07ec7e470b | chimaera/bin/64bit/xmrig-6.8.1-linux-static-x64.tar.gz |
| 99211429717c686167c1bcda6c5e55dc0e45f46bfdfe34f3bb272ce1378a47a3 | chimaera/bin/64bit/zgrab                               |
| 8373c0e8abdd962f46d3808fb10589e4961e38cd96d68a4464d1811788a4f2b7 | chimaera/bin/64bit/zmap                                |
| 73a4e43a50c533dffdce6575a630be808780d1b408a6dda335106de0c48926ac | chimaera/bin/aarch64/bob                               |
| 24c75a2f86d3c0f13f77b453d476787607a87c1033dca501351846524a4e8ff6 | chimaera/bin/aarch64/index.html                        |
| e842c810b6ecb9c7634f1cfbf81b6245094528ac5584179eb8e6932eaa34f421 | chimaera/bin/aarch64/traitor                           |
| 1e565e0672c4cd60b7db32c0ecc1abace6dfd8b6c2e0623c949d31536940fd62 | chimaera/bin/aarch64/zgrab                             |
| 12466d33f1d0e9114b4c20e14d51ca3e7e374b866c57adb6ba5dfef3ee34ee5b | chimaera/bin/irc\_bot.c                                 |
| 2287e71c5707ebb2885cd6afd0bff401e4465ca59c8c2498439859e6c8ec5175 | chimaera/bin/mass.tar                                  |
| b6ddd29b0f74c8cfbe429320e7f83427f8db67e829164b67b73ebbdcd75d162d | chimaera/bin/p.tar                                     |
| 2f4ffa0e687b4e18e45770812a14ad4fc1ae3f735b4f8280f0dd241e045838fe | chimaera/bin/pnscan\_1.12+git20180612.orig.tar.gz       |
| 5f1c9e8dc98ff3e7cf32096225cbae96dacead6af82986d69bbc0032d0e8da84 | chimaera/bin/rpm\_deb\_apk/i386-curl                     |
| 3d2481edc5fe122bae2fe316d803e131837606e38a7a3158f7cddc7b436dc6c2 | chimaera/bin/rpm\_deb\_apk/setup\_apps.sh                 |
| f26f805c3a1c01ab4717cc3b4c91581249482b00bd29712ab0c36ba7ce74147c | chimaera/bin/x86\_64/bob                                |
| 0cdad862a1a695fe9cbf35592f92111e31ac848881fcd1deaa3c6ecd7c241ad7 | chimaera/bin/x86\_64/bot                                |
| 456041c34e7a992e76320121b7a6b5a47f12b1ed069e1de735543f5b2a1f1a68 | chimaera/bin/x86\_64/pei                                |
| d2fff992e40ce18ff81b9a92fa1cb93a56fb5a82c1cc428204552d8dfa1bc04f | chimaera/bin/x86\_64/tmate                              |
| 3cb401fdba1a0e74389ac9998005805f1d3e8ed70018d282f5885410d48725e1 | chimaera/bin/x86\_64/traitor                            |
| 84078b10ad532834eb771231a068862182efb93ce1e4a8614dfca5ae3229ed94 | chimaera/bin/x86\_64/xmrig                              |
| 4e4e01830dc64466683735d32778d17cfbffc7be75d647322240ecf9e2f9d700 | chimaera/bin/x86\_64/zgrab                              |
| 900b17ae0081052fb63a7d74232048cfbc2716cdedbe0ab14cf64b7d387d4329 | chimaera/bin/xmr/xmrig\_u                               |
| 11b45924f96844764c7ae56ce0b6ac3c43d3a732bc7101d7ce85ea52d0455afd | chimaera/bin/xmrig                                     |
| 825c60dd1bb32cd6b7e6686f425c461532093b1e9f6ca662c1ea9b07ec7e470b | chimaera/bin/xmrig-6.8.1-linux-static-x64.tar.gz       |
| acea877b5e4eb9a4f89c0607872bd718e818775dd70044ba6bcede26b481d079 | chimaera/data/docker.container.local.spread.txt        |
| d4084c84b21a24ec7a75b1700c65835edea55ac146e86f874941f9ea4bc30ecd | chimaera/init.sh                                       |
| 43545f6cd370e6f200347bd9bbafdc3d94240775d816cd5e24dc8072d0f1c9b5 | chimaera/pl/scan.pl                                    |
| 55a53f325a46f0da8a15ce001595b9d27eeb03262a62c40f169a3c855c5e8319 | chimaera/py/punk.base64.txt                            |
| c2491f9b1f6eb9b1b31e84b0dd5505c5959947c47230af97dce18a49aab90e6b | chimaera/py/punk.py                                    |
| de3747a880c4b69ecaa92810f4aac20fe5f6d414d9ced29f1f7ebb82cd0f3945 | chimaera/sh/bd\_aws.sh                                  |
| 5265a344fd3d3c91d1e9169678e9dadf6296331ccf91132b99c728761bffb011 | chimaera/sh/clean\_aegis.sh                             |
| 0a8499cebddd96af4634e85be50e4f64c9d2c7c616677de171df99691239526b | chimaera/sh/clean\_crontab.sh                           |
| 881530fb9634cbf5cf12080f5d13e69cb9497c7ea223a4ac29e0d3c81de3053a | chimaera/sh/clean\_docker.sh                            |
| 5f845e765947c4568e1c201fdfeb016c19c940ca2f1636d1393a65a9ee367e8c | chimaera/sh/clean\_quartz.sh                            |
| 44cbddf5092818092439734cd478a0fd80f93949e4fec32553b78064029266af | chimaera/sh/clean\_tmp.sh                               |
| d708b28231ef70edc707d3cfc1f9ed72aa06a6db15b7903a22b2cdba435e41f7 | chimaera/sh/clean\_v2.sh                                |
| 1946ddf0ade98a69650cdf5c6951d26abbb2ddb5224ea95279e1372a772a0f9c | chimaera/sh/clean.sh                                   |
| b1f38b8648351bb7c743eed838658ea38975db40358c2af62d4e36905555a332 | chimaera/sh/first\_touch.sh                             |
| a1e9cd08073e4af3256b31e4b42f3aa69be40862b3988f964e96228f91236593 | chimaera/sh/grab\_aws-data.sh                           |
| 4e059d74e599757226f93ea8ddcfb794d4bcda605f0e553fbbef47b8b7c82d2b | chimaera/sh/init.sh                                    |
| 484d09b34cb7fb075647402b52f174b2645c6b2c7e8b271e648421893aacdfb4 | chimaera/sh/kube.lateral.sh                            |
| 49b185d1a03124fd5f664fe908fe833d932124344216535b822a044e9d115234 | chimaera/sh/lateral/\_sort.sh                           |
| ed40bce040778e2227c869dac59f54c320944e19f77543954f40019e2f2b0c35 | chimaera/sh/search.sh                                  |
| 4a6a31b867ce9033691a6638997b0e46d89462d677e9a1f7d757e9f2efbd4c79 | chimaera/sh/setup\_bot.sh                               |
| e9a58f006e5335d806da5fc772fb2b5dedcd977d6484f462169f7a64a636fb44 | chimaera/sh/setup\_crontab.sh                           |
| 61e94f41187a3ce31fd8ac0ae3798aaa0e8984e8ff76debe623e41fecf8d7a12 | chimaera/sh/setup\_hide.sh                              |
| 7270416ff49d679f123f560f135b25afe1754a370b0a4bf99368f1ebbc86cbb1 | chimaera/sh/setup\_mo.sh                                |
| 584c6efed8bbce5f2c52a52099aafb723268df799f4d464bf5582a9ee83165c1 | chimaera/sh/setup\_scope.sh                             |
| ec92f9a98e2c5449693792aa7fd77d0c7a5a98af13b0595ad3c46da739c44c80 | chimaera/sh/setup\_tmate.sh                             |
| 642551b7f4e088797cd37b19280261668c8b381dcf667ea7d0dafed1ec94e460 | chimaera/sh/setup\_unhide.sh                            |
| 5ddd226d400cc0b49d0175ba06a7e55cb2f5e9586111464bcf7b3bd709417904 | chimaera/sh/setup\_xmr.sh                               |
| 57689b87b6830411046d7bda19936707a0797bec9dffe03874d1a364c4f29c35 | chimaera/sh/setup\_xmr2.sh                              |
| f9b5bd4372daf78346e4bb34677633a7795876a3c89c5965eb76f137a0fba448 | chimaera/sh/setup\_zmap\_zgrab\_jq\_masscan.sh             |
| f194d5901d64811c72a2cf3a035b7c36ea36d444ea6291f64138d1e88929349d | chimaera/sh/setup.sh                                   |
| 30e35e225f23495f92c417337d205056c4fd2f8dd9e958365e84b522c3adc851 | chimaera/sh/spread\_docker\_local.sh                     |
| 2e34f88bacc50e0ec06681d6857163b99046fec775a75297f774edd1f6b452c1 | chimaera/sh/spread\_docker\_loop.sh                      |
| 0d7912e62bc663c9ba6bff21ae809e458b227e3ceec0abac105d20d5dc533a22 | chimaera/sh/spread\_jupyter\_tmp.sh                      |
| 5ac76e1edfda445548c35364ba0c3dbb0bcb8a0236c303d2a4e2a94a7073a716 | chimaera/sh/spread\_kube\_local.sh                       |
| 3ae9e772a025d192a689358e263445a8d953e090b1bbe62f83567034938e75b5 | chimaera/sh/spread\_kube\_loop.sh                        |
| 9c7f2644e02cb48ab5ff17d541c07f11fd85e5e13cdc210faf34994771a4ca29 | chimaera/sh/spread\_ssh.sh                              |
| fece70a9f33c2ed77a5833dba5b7188d5ec00a30fb00e43983e6939cac87fb99 | chimaera/sh/xmr.sh.sh                                  |
| 5bb45f372fb4df6a9c6a5460fa1845f5e96af53aa41939eb251cbe989a5cac6c | chimaera/so/systemd.so                                 |
| e8cd937239d6bf43cb34c7947321a197b0d1067f05c3b21508bffa35a953a3c3 | chimaera/so/tmate.so                                   |
| 0af1b8cd042b6e2972c8ef43d98c0a0642047ec89493d315909629bcf185dffd | chimaera/so/xmrig.so                                   |
| 3b14c84525f2e56fe3ae7dec09163a4a9c03f11e6a8d65b021c792ad13ed2701 | chimaera/spread/redis/b.sh                             |
| dc8e4e45a46a65e70e3d67315ca76127b20ef4dcda2fd012a826b73ee26ab941 | chimaera/up/aws\_in.php                                 |
| 6175648ebbe658e3d5984d5c45d5221bf8f8875599d9ce2d62d279b7bba5eeea | chimaera/up/grabbed\_data.php                           |
| e6e1656ac258318e8226db00dbacdf6914f2dac2d174b1470903b096b7fbecff | chimaera/up/tmate\_in.php                               |
| 9cd9549e8b80ee3230bdb1130676ac2396de5e99428b45f14d93b705b157465a | chimaera/up/working\_tmp\_dir/results\_kubernetes.txt     |
| 79c7a022d2c807dea005fb5c0433eb984eea053d07123754acd864bede03be00 | chimaera/working.txt                                   |

###### Monero Wallet

46EPFzvnX5GH61ejkPpNcRNm8kVjs8oHS9VwCkKRCrJX27XEW2y1NPLfSa54DGHxqnKfzDUVW1jzBfekk3hrCVCmAUrFd3H

###### URL Address

45\.9.148\[.\]35/chimaera/bin/

45\.9.148\[.\]35/chimaera/data/

45\.9.148\[.\]35/chimaera/init/

45\.9.148\[.\]35/chimaera/pl/

45\.9.148\[.\]35/chimaera/py/

45\.9.148\[.\]35/chimaera/sh/

45\.9.148\[.\]35/chimaera/spread/

45\.9.148\[.\]35/chimaera/up/

pool.supportxmr\[.\]com

###### Appendix

|-------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|
| **IAM command**                           | **AWS Link**                                                                                                                     | **Function Description**                                                                                                                                  |
| aws iam get-account-authorization-details | [get-account-authorization-details](https://docs.aws.amazon.com/cli/latest/reference/iam/get-account-authorization-details.html) | Retrieves information about all IAM users, groups, roles and policies in your AWS account, including their relationships to one another.                  |
| aws iam get-account-password-policy       | [get-account-password-policy](https://docs.aws.amazon.com/cli/latest/reference/iam/get-account-password-policy.html)             | Retrieves the password policy for the AWS account.                                                                                                        |
| aws iam get-account-summary               | [get-account-summary](https://docs.aws.amazon.com/cli/latest/reference/iam/get-account-summary.html)                             | Retrieves information about IAM entity usage and IAM quotas in the AWS account.                                                                           |
| aws iam list-account-aliases              | [list-account-aliases](https://docs.aws.amazon.com/cli/latest/reference/iam/list-account-aliases.html)                           | Lists the account alias associated with the AWS account. (Note: You can have only one.)                                                                   |
| aws iam list-groups                       | [list-groups](https://docs.aws.amazon.com/cli/latest/reference/iam/list-groups.html)                                             | Lists the IAM groups that have the specified path prefix.                                                                                                 |
| aws iam list-instance-profiles            | [list-instance-profile](https://docs.aws.amazon.com/cli/latest/reference/iam/list-instance-profiles.html)s                       | Lists the instance profiles that have the specified path prefix.                                                                                          |
| aws iam list-open-id-connect-providers    | [list-open-id-connect-providers](https://docs.aws.amazon.com/cli/latest/reference/iam/list-open-id-connect-providers.html)       | Lists information about the IAM OpenID Connect (OIDC) provider resource objects defined in the AWS account.                                               |
| aws iam list-policies                     | [list-policies](https://docs.aws.amazon.com/cli/latest/reference/iam/list-policies.html)                                         | Lists all the managed policies that are available in your AWS account, including your own customer-defined managed policies and all AWS managed policies. |
| aws iam list-roles                        | [list-roles](https://docs.aws.amazon.com/cli/latest/reference/iam/list-roles.html)                                               | Lists the IAM roles that have the specified path prefix.                                                                                                  |
| aws iam list-saml-providers               | [list-saml-providers](https://docs.aws.amazon.com/cli/latest/reference/iam/list-saml-providers.html)                             | Lists the SAML provider resource objects defined in IAM in the account.                                                                                   |
| aws iam list-server-certificates          | [list-server-certificates](https://docs.aws.amazon.com/cli/latest/reference/iam/list-server-certificates.html)                   | Lists the server certificates stored in IAM that have the specified path prefix.                                                                          |
| aws iam list-users                        | [list-users](https://docs.aws.amazon.com/cli/latest/reference/iam/list-users.html)                                               | Lists the IAM users that have the specified path prefix.                                                                                                  |
| aws iam list-virtual-mfa-devices          | [list-virtual-mfa-devices](https://docs.aws.amazon.com/cli/latest/reference/iam/list-virtual-mfa-devices.html)                   | Lists the virtual MFA devices defined in the AWS account by assignment status.                                                                            |
| aws iam get-credential-report             | [get-credential-report](https://docs.aws.amazon.com/cli/latest/reference/iam/get-credential-report.html)                         | Retrieves a credential report for the AWS account.                                                                                                        |

^*Table 1. Enumerating AWS IAM configurations.*^

|---------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------|
| **IAM command**                                   | **AWS Link**                                                                                                                                     | **Function Description**                                                                                                                  |
| aws ec2 describe-account-attributes               | [describe-account-attributes](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-account-attributes.html)                             | Describes attributes of your AWS account.                                                                                                 |
| aws ec2 describe-addresses                        | [describe-addresses](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-addresses.html)                                               | Describes the specified Elastic IP addresses or all of your Elastic IP addresses.                                                         |
| aws ec2 describe-bundle-tasks                     | [describe-bundle-tasks](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-bundle-tasks.html)                                         | Describes the specified bundle tasks or all of your bundle tasks.                                                                         |
| aws ec2 describe-classic-link-instances           | [describe-classic-link-instances](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-classic-link-instances.html)                     | Describes one or more of your linked EC2-Classic instances.                                                                               |
| aws ec2 describe-conversion-tasks                 | [describe-conversion-tasks](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-conversion-tasks.html)                                 | Describes the specified conversion tasks or all your conversion tasks.                                                                    |
| aws ec2 describe-customer-gateways                | [describe-customer-gateway](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-customer-gateways.html)s                               | Describes one or more of your VPN customer gateways.                                                                                      |
| aws ec2 describe-dhcp-options                     | [describe-dhcp-options](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-dhcp-options.html)                                         | Describes one or more of your DHCP options sets.                                                                                          |
| aws ec2 describe-export-tasks                     | [describe-export-tasks](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-export-tasks.html)                                         | Describes the specified export instance tasks or all of your export instance tasks.                                                       |
| aws ec2 describe-flow-logs                        | [describe-flow-logs](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-flow-logs.html)                                               | Describes one or more flow logs.                                                                                                          |
| aws ec2 describe-host-reservations                | [describe-host-reservations](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-host-reservations.html)                               | Describes reservations that are associated with Dedicated Hosts in your account.                                                          |
| aws ec2 describe-hosts                            | [describe-hosts](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-hosts.html)                                                       | Describes the specified Dedicated Hosts or all your Dedicated Hosts.                                                                      |
| aws ec2 describe-images                           | [describe-images](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-images.html)                                                     | Describes the specified images (AMIs, AKIs and ARIs) available to you or all of the images available to you.                              |
| aws ec2 describe-import-image-tasks               | [describe-import-image-tasks](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-import-image-tasks.html)                             | Describes an import image task.                                                                                                           |
| aws ec2 describe-import-snapshot-tasks            | [describe-import-snapshot-tasks](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-import-snapshot-tasks.html)                       | Describes your import snapshot tasks.                                                                                                     |
| aws ec2 describe-instance-status                  | [describe-instance-status](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-instance-status.html)                                   | Describes the status of the specified instances or all of your instances.                                                                 |
| aws ec2 describe-instances                        | [describe-instances](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-instances.html)                                               | Describes the specified instances or all instances.                                                                                       |
| aws ec2 describe-internet-gateways                | [describe-internet-gateways](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-internet-gateways.html)                               | Describes one or more of your internet gateways.                                                                                          |
| aws ec2 describe-key-pairs                        | [describe-key-pairs](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-key-pairs.html)                                               | Describes the specified key pairs or all of your key pairs.                                                                               |
| aws ec2 describe-moving-addresses                 | [describe-moving-addresses](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-moving-addresses.html)                                 | Describes your Elastic IP addresses that are being moved to the EC2-VPC platform, or that are being restored to the EC2-Classic platform. |
| aws ec2 describe-nat-gateways                     | [describe-nat-gateways](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-nat-gateways.html)                                         | Describes one or more of your NAT gateways.                                                                                               |
| aws ec2 describe-network-acls                     | [describe-network-acls](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-network-acls.html)                                         | Describes one or more of your network ACLs.                                                                                               |
| aws ec2 describe-network-interfaces               | [describe-network-interfaces](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-network-interfaces.html)                             | Describes one or more of your network interfaces.                                                                                         |
| aws ec2 describe-placement-groups                 | [describe-placement-groups](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-placement-groups.html)                                 | Describes the specified placement groups or all of your placement groups.                                                                 |
| aws ec2 describe-reserved-instances               | [describe-reserved-instances](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-reserved-instances.html)                             | Describes one or more of the Reserved Instances that you purchased.                                                                       |
| aws ec2 describe-reserved-instances-listings      | [describe-reserved-instances-listings](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-reserved-instances-listings.html)           | Describes your account's Reserved Instance listings in the Reserved Instance Marketplace.                                                 |
| aws ec2 describe-reserved-instances-modifications | [describe-reserved-instances-modifications](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-reserved-instances-modifications.html) | Describes the modifications made to your Reserved Instances.                                                                              |
| aws ec2 describe-route-tables                     | [describe-route-tables](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-route-tables.html)                                         | Describes one or more of your route tables.                                                                                               |
| aws ec2 describe-scheduled-instances              | [describe-scheduled-instances](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-scheduled-instances.html)                           | Describes the specified Scheduled Instances or all your Scheduled Instances.                                                              |
| aws ec2 describe-security-groups                  | [describe-security-groups](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-security-groups.html)                                   | Describes the specified security groups or all of your security groups.                                                                   |
| aws ec2 describe-snapshots                        | [describe-snapshots](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-snapshots.html)                                               | Describes the specified EBS snapshots available to you or all of the EBS snapshots available to you.                                      |
| aws ec2 describe-spot-datafeed-subscription       | [describe-spot-datafeed-subscription](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-spot-datafeed-subscription.html)             | Describes the data feed for Spot Instances.                                                                                               |
| aws ec2 describe-spot-fleet-requests              | [describe-spot-fleet-requests](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-spot-fleet-requests.html)                           | Describes your Spot Fleet requests.                                                                                                       |
| aws ec2 describe-spot-instance-requests           | [describe-spot-instance-requests](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-spot-instance-requests.html)                     | Describes the specified Spot Instance requests.                                                                                           |
| aws ec2 describe-subnets                          | [describe-subnets](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-subnets.html)                                                   | Describes one or more of your subnets.                                                                                                    |
| aws ec2 describe-tags                             | [describe-tags](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-tags.html)                                                         | Describes the specified tags for your EC2 resources.                                                                                      |
| aws ec2 describe-volume-status                    | [describe-volume-status](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-volume-status.html)                                       | Describes the status of the specified volumes.                                                                                            |
| aws ec2 describe-volumes                          | [describe-volumes](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-volumes.html)                                                   | Describes the specified EBS volumes or all of your EBS volumes.                                                                           |
| aws ec2 describe-vpc-classic-link                 | [describe-vpc-classic-link](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpc-classic-link.html)                                 | Describes the ClassicLink status of one or more VPCs.                                                                                     |
| aws ec2 describe-vpc-classic-link-dns-support     | [describe-vpc-classic-link-dns-support](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpc-classic-link-dns-support.html)         | Describes the ClassicLink DNS support status of one or more VPCs.                                                                         |
| aws ec2 describe-vpc-endpoints                    | [describe-vpc-endpoints](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpc-endpoints.html)                                       | Describes one or more of your VPC endpoints.                                                                                              |
| aws ec2 describe-vpc-peering-connections          | [describe-vpc-peering-connections](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpc-peering-connections.html)                   | Describes one or more of your VPC peering connections.                                                                                    |
| aws ec2 describe-vpcs                             | [describe-vpcs](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpcs.html)                                                         | Describes one or more of your VPCs.                                                                                                       |
| aws ec2 describe-vpn-connections                  | [describe-vpn-connections](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpn-connections.html)                                   | Describes one or more of your VPN connections.                                                                                            |
| aws ec2 describe-vpn-gateways                     | [describe-vpn-gateways](https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpn-gateways.html)                                         | Describes one or more of your virtual private gateways.                                                                                   |

^*Table 2. Enumeration Amazon EC2 instances.*^

|-----------------|-------------------------------------------------------------------|-----------------------------------------------------------------------|
| **IAM command** | **AWS Link**                                                      | **Function Description**                                              |
| aws s3 ls       | [ls](https://docs.aws.amazon.com/cli/latest/reference/s3/ls.html) | List S3 objects and common prefixes under a prefix or all S3 buckets. |

^*Table 3. Enumerating available Amazon S3 buckets*^

|-----------------------------------------------------|------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------|
| **IAM command**                                     | **AWS Link**                                                                                   | **Function Description**                                                             |
| aws support describe-cases --include-resolved-cases | [describe-cases](https://docs.aws.amazon.com/cli/latest/reference/support/describe-cases.html) | Lists the interconnects owned by the AWS account or only the specified interconnect. |

^*Table 4. Enumerating open AWS support cases.*^

|-----------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------|
| **IAM command**                               | **AWS Link**                                                                                                                   | **Function Description**                                                             |
| aws directconnect describe-connections        | [describe-connections](https://docs.aws.amazon.com/cli/latest/reference/directconnect/describe-connections.html)               | Displays the specified connection or all connections in this Region.                 |
| aws directconnect describe-interconnects      | [describe-interconnects](https://docs.aws.amazon.com/cli/latest/reference/directconnect/describe-interconnects.html)           | Lists the interconnects owned by the AWS account or only the specified interconnect. |
| aws directconnect describe-virtual-gateways   | [describe-virtual-gateways](https://docs.aws.amazon.com/cli/latest/reference/directconnect/describe-virtual-gateways.html)     | Lists the virtual private gateways owned by the AWS account.                         |
| aws directconnect describe-virtual-interfaces | [describe-virtual-interfaces](https://docs.aws.amazon.com/cli/latest/reference/directconnect/describe-virtual-interfaces.html) | Displays all virtual interfaces for an AWS account.                                  |

^*Table 5. Enumerating available AWS network connections.*^

|---------------------------------|-------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------|
| **IAM command**                 | **AWS Link**                                                                                          | **Function Description**                                                                                       |
| aws cloudtrail describe-trails  | [describe-trails](https://docs.aws.amazon.com/cli/latest/reference/cloudtrail/describe-trails.html)   | Retrieves settings for one or more trails associated with the current region for your account.                 |
| aws cloudtrail list-public-keys | [list-public-keys](https://docs.aws.amazon.com/cli/latest/reference/cloudtrail/list-public-keys.html) | Returns all public keys whose private keys were used to sign the digest files within the specified time range. |

^*Table 6. Enumerating AWS CloudTrail operations.*^

|--------------------------------------------|-------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------|
| **IAM command**                            | **AWS Link**                                                                                                            | **Function Description**                                                                                                                     |
| aws cloudformation describe-account-limits | [describe-account-limits](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/describe-account-limits.html) | Retrieves your account's AWS CloudFormation limits, such as the maximum number of stacks that you can create in your account.                |
| aws cloudformation describe-stacks         | [describe-stacks](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/describe-stacks.html)                 | Returns the description for the specified stack. If no stack name was specified, then it returns the description for all the stacks created. |
| aws cloudformation list-exports            | [list-exports](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/list-exports.html)                       | Lists all exported output values in the account and Region in which you call this action.                                                    |
| aws cloudformation list-stacks             | [list-stacks](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/list-stacks.html)                         | Returns the summary information for stacks whose status matches the specified StackStatusFilter.                                             |

^*Table 7. Enumerating AWS CloudFormation operations.*^

Back to top

### Tags

* [AWS](https://unit42.paloaltonetworks.com/tag/aws/ "AWS")
* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")
* [Cryptojacking](https://unit42.paloaltonetworks.com/tag/cryptojacking/ "cryptojacking")
* [Google Cloud](https://unit42.paloaltonetworks.com/tag/google-cloud/ "Google Cloud")
* [IAM](https://unit42.paloaltonetworks.com/tag/iam/ "IAM")
* [Scraping](https://unit42.paloaltonetworks.com/tag/scraping/ "scraping")
* [TeamTnT](https://unit42.paloaltonetworks.com/tag/teamtnt/ "TeamTnT")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Docker Honeypot Reveals Cryptojacking as Most Common Cloud Threat](https://unit42.paloaltonetworks.com/docker-honeypot/ "Docker Honeypot Reveals Cryptojacking as Most Common Cloud Threat")

### Table of Contents

* 

### Related Articles

* [Pass the Passkey: A Novel Attack Surface in Passwordless Authentication](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ "article - table of contents")
* [The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)](https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/ "article - table of contents")
* [The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration](https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/ "article - table of contents")

## Related Cloud Cybersecurity Research Resources

![Pictorial representation of bucket hijacking technique for cloud data exfiltration. Digital illustration of Europe map highlighting network connections and nodes, depicted as glowing points and lines on a dark blue background, emphasizing major cities and connectivity across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/09_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 22, 2026 [#### The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration](https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/)

* [AWS](https://unit42.paloaltonetworks.com/tag/aws/ "AWS")

* [Bucket hijacking](https://unit42.paloaltonetworks.com/tag/bucket-hijacking/ "bucket hijacking")

* [Cloud data exfiltration](https://unit42.paloaltonetworks.com/tag/cloud-data-exfiltration/ "cloud data exfiltration")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/ "The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration")  
  ![Pictorial representation of Vertex AI model uploads. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_1270203474-1-786x354.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 16, 2026 [#### Pickle in the Middle -- Hijacking Vertex AI Model Uploads for Cross-Tenant RCE](https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/)

* [Bucket squatting](https://unit42.paloaltonetworks.com/tag/bucket-squatting/ "bucket squatting")

* [Google Cloud](https://unit42.paloaltonetworks.com/tag/google-cloud/ "Google Cloud")

* [Joblib](https://unit42.paloaltonetworks.com/tag/joblib/ "joblib")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/ "Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE")  
  ![Pictorial representation of Cloud Logging services for defense evasion. A vibrant digital illustration depicting a glowing, neon blue cloud symbol positioned over a circuit board landscape. The cloud symbolizes cloud computing technology, and the landscape features intricate electronic circuits with glowing lines and nodes, suggesting high-tech data transfer and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/11_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 9, 2026 [#### Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility](https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/)

* [AWS CloudTrail](https://unit42.paloaltonetworks.com/tag/aws-cloudtrail/ "AWS CloudTrail")

* [Cloud logging](https://unit42.paloaltonetworks.com/tag/cloud-logging/ "cloud logging")

* [Defense evasion](https://unit42.paloaltonetworks.com/tag/defense-evasion/ "defense evasion")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/ "Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility")  
  ![Pictorial representation of ROADtools framework in the cloud. An Asian man wearing glasses sits in front of a computer screen. Reflecting in the glasses are lines indicating analysis. Bright blue city lights illuminate the rest of the image.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/10_Cloud_cybersecurity_research_Overview_1920x900-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) May 22, 2026 [#### Paved With Intent: ROADtools and Nation-State Tactics in the Cloud](https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/)

* [Curious Serpens](https://unit42.paloaltonetworks.com/tag/curious-serpens/ "Curious Serpens")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/ "Paved With Intent: ROADtools and Nation-State Tactics in the Cloud")  
  ![Pictorial representation of autonomous AI attack in cloud environments. Digital illustration of a glowing blue brain connected to a network of lines and lights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/12_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 23, 2026 [#### Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System](https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Cloud](https://unit42.paloaltonetworks.com/tag/cloud/ "Cloud")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/ "Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System")  
  ![Pictorial representation of passwordless authentication. Futuristic cityscape with skyscrapers surrounded by glowing, neon-lit pathways and digital clouds. The sky is vibrant with pink and orange hues, giving a surreal, cyberpunk aesthetic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/02_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 23, 2026 [#### Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentication](https://unit42.paloaltonetworks.com/passwordless-authentication/)

* [Google](https://unit42.paloaltonetworks.com/tag/google/ "Google")

* [Google authenticator](https://unit42.paloaltonetworks.com/tag/google-authenticator/ "google authenticator")

* [Google Chrome](https://unit42.paloaltonetworks.com/tag/google-chrome/ "Google Chrome")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/passwordless-authentication/ "Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentication")  
  ![Close-up of a black woman with glasses examining colorful computer code on a screen. The scene is illuminated by various lights, creating a focused and analytical atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/13_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) February 6, 2026 [#### Novel Technique to Detect Cloud Threat Actor Operations](https://unit42.paloaltonetworks.com/tracking-threat-groups-through-cloud-logging/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [IAM](https://unit42.paloaltonetworks.com/tag/iam/ "IAM")

* [MITRE](https://unit42.paloaltonetworks.com/tag/mitre/ "MITRE")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/tracking-threat-groups-through-cloud-logging/ "Novel Technique to Detect Cloud Threat Actor Operations")  
  ![Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 20, 2026 [#### DNS OverDoS: Are Private Endpoints Too Private?](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/)

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")

* [Networking](https://unit42.paloaltonetworks.com/tag/networking/ "networking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/ "DNS OverDoS: Are Private Endpoints Too Private?")  
  ![Pictorial representation of cloud discovery with AzureHound. A digital representation of a cloud composed of blue light particles, superimposed over a blurred background of server racks in a data center.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/08_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 24, 2025 [#### Cloud Discovery With AzureHound](https://unit42.paloaltonetworks.com/threat-actor-misuse-of-azurehound/)

* [Control plane](https://unit42.paloaltonetworks.com/tag/control-plane/ "control plane")

* [Curious Serpens](https://unit42.paloaltonetworks.com/tag/curious-serpens/ "Curious Serpens")

* [Data plane](https://unit42.paloaltonetworks.com/tag/data-plane/ "data plane")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-actor-misuse-of-azurehound/ "Cloud Discovery With AzureHound")  
  ![Pictorial representation of a gift card fraud campaign. A glowing skull and crossbones on a circuit board.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/07_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 22, 2025 [#### Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign](https://unit42.paloaltonetworks.com/cloud-based-gift-card-fraud-campaign/)

* [CL‑CRI‑1032](https://unit42.paloaltonetworks.com/tag/cl-cri-1032/ "CL‑CRI‑1032")

* [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/ "Microsoft")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cloud-based-gift-card-fraud-campaign/ "Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
