The TrailShark Capture Utility seamlessly integrates with Wireshark, facilitating the capture of AWS CloudTrail logs directly into Wireshark for near-real-time analysis.
This tool can be used for debugging AWS API calls and played a pivotal role in our “Bucket Monopoly Research” project.
By leveraging this utility, we were able to understand the internal API calls made by AWS, leading to the discovery of critical vulnerabilities across different services.
This insight is invaluable for enhancing security measures and understanding AWS service interactions more deeply.
Note: The plugin has been tested on Linux and macOS, but it should work on Windows as well.
First, deploy the CloudFormation template to create the CloudTrail trail and configure S3 to store logs.
aws cloudformation create-stack --stack-name TrailShark --template-body aws/template.yaml --region {REGION} Run the following script to install the wireshark plugin
./install-plugin.sh The groupdel command in Linux removes a group from the system. It deletes the group's entry from /etc/group and /etc/gshadow,…
The wc command in Linux counts lines, words, characters, and bytes in files or standard input. It…
The top command in Linux provides a real-time view of running processes and system resource usage. From…
The usermod command in Linux modifies existing user account attributes. You can use it to manage group…
The sort command in Linux reads lines from files or standard input and writes them to standard…
The wall command in Linux sends a message to the terminals of all currently logged-in users. The…