Secrets & Notification Services
Enumerate and exploit Secrets Manager, SNS topics, or other services that may leak sensitive data.
Secrets Manager Enumeration & Exfiltration
List All Secrets (if permitted)
Retrieve Secret Valuesnote
If a role or user attached to the instance (via IMDS) has secretsmanager:GetSecretValue, you can retrieve high-value secrets (API keys, database credentials, etc.).
Simple Notification Service (SNS) Enumeration
Identify Topic ARNs If you’ve discovered an SNS topic ARN (e.g., via Secrets Manager or CloudFormation), subscribe to it to intercept messages (which sometimes contain provisioning or “onboarding” notifications).
Subscribe to a topic