The TrailShark Capture Utility seamlessly integrates with Wireshark, facilitating the capture of AWS CloudTrail logs directly into Wireshark for near-real-time analysis.
This tool can be used for debugging AWS API calls and played a pivotal role in our “Bucket Monopoly Research” project.
By leveraging this utility, we were able to understand the internal API calls made by AWS, leading to the discovery of critical vulnerabilities across different services.
This insight is invaluable for enhancing security measures and understanding AWS service interactions more deeply.
Note: The plugin has been tested on Linux and macOS, but it should work on Windows as well.
First, deploy the CloudFormation template to create the CloudTrail trail and configure S3 to store logs.
aws cloudformation create-stack --stack-name TrailShark --template-body aws/template.yaml --region {REGION}
Run the following script to install the wireshark plugin
./install-plugin.sh
SeamlessPass is a specialized tool designed to leverage on-premises Active Directory Kerberos tickets to obtain…
PPLBlade is a powerful Protected Process Dumper designed to capture memory from target processes, hide…
HikPwn: Comprehensive Guide to Scanning Hikvision Devices for Vulnerabilities If you’re searching for an efficient…
What Are Bash Comments? Comments in Bash scripts, are notes in your code that the…
When you write a Bash script in Linux, you want it to run correctly every…
Introduction If you’re new to Bash scripting, one of the first skills you’ll need is…