The TrailShark Capture Utility seamlessly integrates with Wireshark, facilitating the capture of AWS CloudTrail logs directly into Wireshark for near-real-time analysis.
This tool can be used for debugging AWS API calls and played a pivotal role in our “Bucket Monopoly Research” project.
By leveraging this utility, we were able to understand the internal API calls made by AWS, leading to the discovery of critical vulnerabilities across different services.
This insight is invaluable for enhancing security measures and understanding AWS service interactions more deeply.
Note: The plugin has been tested on Linux and macOS, but it should work on Windows as well.
First, deploy the CloudFormation template to create the CloudTrail trail and configure S3 to store logs.
aws cloudformation create-stack --stack-name TrailShark --template-body aws/template.yaml --region {REGION}
Run the following script to install the wireshark plugin
./install-plugin.sh
Ulfberht is a sophisticated shellcode loader designed to enhance operational security and evasion capabilities in…
The tool is written in Go, so make sure to install it on your system…
In today’s dynamic threat landscape, security leaders are under constant pressure to make informed choices…
DICOMHawk is a powerful and efficient honeypot for DICOM servers, designed to attract and log…
Stratus Red Team is a cutting-edge tool designed to enhance cloud security by simulating granular…
bomber is an application that scans SBOMs for security vulnerabilities. So you've asked a vendor…