Cloud Security Researcher, AWS Offensive Security Expert, Co-founder and Director of R&D at OFFENSAI, Ethical Hacker, DEFCON speaker, Trainer and Cat Owner.
Social Profiles
All Sessions by Eduard Agavriloae 🇷🇴
Main Stage
11:50
AWS Eventual Persistence: Performing Actions with Deleted Identities
11:50 - 12:20
Every AWS IAM action has a ~4 seconds delay before coming into effect, but the data plane is instantly updated. This discrepancy can be weaponized for ensuring persistence. In this talk we'll explore how this consistency window can be abused, why the standard incident response playbooks fail (including AWS's own recommended approach), and what actually works. We'll also look at how this extends across multiple IAM resources and actions including detaching policies, using deleted identities and keys, and what CloudTrail actually logs when this happens. It's time to update the AWS incident response playbooks.