Repository navigation
Add CloudTrail event logging across all exploit modules and identity add --from-profile alias - #87
Merged
Merged
Conversation
…nd discovery layer. Instruments all 81 exploit modules with logger.LogAWSCall() calls so every AWS API call made during exploitation is captured as a structured CloudTrail-aligned event. Threads DiscoveryLogger through pkg/discovery/ helpers so auto-discovery calls are also logged. Extends pkg/modules with the Logger interface and ExecutionContext.Logger field. Adds workspace report --output flag (HTML/Markdown export) and --module filter. Updates pkg/core session and REPL wiring, cleanup helpers, tab completion, and CLI adapter. Adds integration and unit tests for new report/cleanup behavior. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Accepts --from-profile as an alternative to --profile so the flag name is consistent with the other --from-* prefixed flags on the same command. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…v1.338. go get -u ./... upgraded the EC2 SDK from v1.325 to v1.338, which renamed types.BlobAttributeValue to types.SecureBlobAttributeValue. Update both call sites (ec2_modifyinstanceattribute module and cleanup_extra) to use the new name. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
logger.LogAWSCall()so every AWS API call made during exploitation is captured as a structured, CloudTrail-aligned event for purple team useDiscoveryLoggerthroughpkg/discovery/helpers so auto-discovery calls are also loggedpkg/report/package with HTML and Markdown export forworkspace report, plus--outputand--modulefilter flags on the CLI--from-profileas an alias for--profileonidentity add, consistent with the other--from-*flags on that command*.htmlto.gitignoreto avoid committing generated report artifactsTest plan
go test ./tests/unit/— unit tests for CloudTrail logger, report package, and REPLgo test ./tests/integration/— integration tests for CloudTrail report, report export, and cleanupmake build— confirmpkg/exploits/register.goregenerates and binary compiles cleanworkspace reportoutput includes logged AWS callspathrunner identity add --from-profile <name>loads the profile correctly🤖 Generated with Claude Code