> For the complete documentation index, see [llms.txt](https://notes.tatusl.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.tatusl.dev/aws/security/attacks.md).

# Attacks against AWS infrastructure

## Attack types

### ECS Task Definition exploit

In their blog post, Rhino Security Labs describe how to weaponize ECS task definitions to steal access keys and other information: <https://rhinosecuritylabs.com/aws/weaponizing-ecs-task-definitions-steal-credentials-running-containers/>
