
Pacu
Pacu is a free open-source AWS exploitation framework used to test Amazon Web Services accounts for cloud penetration testers working with authorization.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxmacOS
- License
- Open source
- Reviewed
- Last reviewed 6 October 2026
What it is
A modular toolkit for offensive testing of Amazon Web Services, with a console and plug-in modules covering recon, permission checks, and post-access actions.
What it helps with
- Enumerating permissions and surfacing privilege escalation paths in an account
- Running focused modules across AWS services from one session
- Logging actions to help document an engagement
Who it's for
Cloud penetration testers assessing Amazon Web Services accounts they own or are authorized to test.
Worth knowing
Each engagement is stored as a named session with its own keys and gathered data, which keeps separate tests from mixing together. It is supported on Linux and macOS and is maintained by Rhino Security Labs.
How many modules are there?
More than thirty five, and new ones can be added.
Where does it keep collected data?
In a local SQLite database, which also cuts repeated API calls.
Can I run it in a container?
Yes. A Docker image is published for it.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.