<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>AWS on bubka hacks stuff</title><link>https://hexpysya.github.io/tags/aws/</link><description>Recent content in AWS on bubka hacks stuff</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Wed, 15 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hexpysya.github.io/tags/aws/index.xml" rel="self" type="application/rss+xml"/><item><title>Splunk-AWSRaid</title><link>https://hexpysya.github.io/blue_team/splunk-awsraid/</link><pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/blue_team/splunk-awsraid/</guid><description>An attacker conducted a brute-force attack to compromise the helpdesk.luke account, performed reconnaissance from various VPN IPs, exfiltrated sensitive data including customer backups and secrets, modified bucket permissions, and established persistence by creating an admin backdoor account.</description></item></channel></rss>