Skip to content

Pacu

AWS exploitation framework for offensive security testing and red teaming of AWS accounts.

Self-hostedNot yet verified
Report issue
BSD-3-Clause★ 4000Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse security tools →

What's next with Pacu?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Pacu?

Pacu is an open-source AWS exploitation framework designed for offensive security testing of Amazon Web Services (AWS) environments. Developed by Rhino Security Labs, it enables penetration testers to identify and exploit configuration vulnerabilities within AWS accounts. The tool is primarily used by ethical hackers, red teams, and security researchers to assess the security posture of cloud infrastructures. Pacu addresses the challenge of systematically testing AWS environments for misconfigurations, weak access controls, and potential attack vectors that could be exploited by adversaries. By leveraging modular architecture, it streamlines the process of validating security controls and demonstrating the impact of configuration flaws.

How it works

Pacu is a specialized tool for penetration testing AWS environments, focusing on exploiting misconfigurations and privilege escalation opportunities. It is maintained by Rhino Security Labs and is available under the BSD-3-Clause license. Its primary purpose is to simulate real-world attacks against AWS accounts, helping users understand how attackers might exploit weaknesses in IAM policies, S3 buckets, and other services. Pacu provides modules for tasks like enumerating IAM users, exploiting overly permissive policies, and escalating privileges through misconfigured roles. For example, it can automate the detection of AWS credentials in plaintext or insecure S3 bucket permissions.

How to use it

  1. 1Install Pacu via Poetry (Python dependency manager) using `poetry install`.
  2. 2Run the CLI with `poetry run pacu` to start the interactive prompt.
  3. 3Load modules using commands like `load iam` to enumerate IAM users.
  4. 4Execute actions such as `list iam-users` to identify potential targets. Practical tips: Use Docker containers for isolated testing and refer to the README.md for module-specific syntax.

What it can do

  • AWS exploitation framework

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/RhinoSecurityLabs/pacu
  • license: BSD-3-Clause — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Requires valid AWS credentials with elevated permissions to function
  • Limited to AWS-specific vulnerabilities and does not support other cloud providers
  • Depends on existing misconfigurations to exploit; no guarantees of finding vulnerabilities
  • Manual intervention may be needed for complex multi-step attacks
  • Lacks built-in automation for large-scale AWS environment scanning

Understanding the result

AWS exploitation framework for offensive security testing and red teaming of AWS accounts.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (BSD-3-Clause).
Built with
(RhinoSecurityLabs/pacu)
License
BSD-3-Clause
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with RhinoSecurityLabs/pacu. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
BSD-3-Clause
View source on GitHub

Open-source project

License: BSD-3-ClauseSource: this project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Pacu used for?

Pacu is used to test the security of AWS environments by identifying and exploiting misconfigurations. It helps penetration testers validate how attackers might leverage weaknesses in IAM policies, S3 buckets, and other AWS services. The tool is primarily used for offensive security research and red team exercises.

How does Pacu work?

Pacu operates by loading modular plugins that interact with AWS APIs. These modules perform tasks like enumerating IAM users, checking S3 bucket permissions, and testing for weak access controls. The tool relies on valid AWS credentials to authenticate requests and simulate an attacker's access to the environment.

How do I enumerate IAM users with Pacu?

To enumerate IAM users, start the Pacu CLI and load the IAM module using `load iam`. Then, execute the command `list iam-users` to retrieve a list of users. This module leverages AWS API calls to fetch user data and can identify users with excessive permissions.

How does Pacu compare to AWS IAM tools?

Unlike AWS IAM tools, which focus on managing and auditing access controls, Pacu is designed for offensive testing. It automates exploitation of misconfigurations, whereas IAM tools are primarily for compliance and policy management. Alternatives like AWS Config or CloudTrail are used for monitoring, while Pacu simulates attack scenarios.

What should I do if Pacu returns an authentication error?

Authentication errors in Pacu typically result from invalid AWS credentials. Verify that the access key and secret key are correct and have the necessary permissions (e.g., `iam:ListUsers`). Check the AWS region in your credentials file and ensure the IAM user has not been locked out or suspended.

Spotted something wrong with Pacu, or want to maintain it? See how to help.