AWS
Download the module and modify ROOT_AWSstub.ps1 - out of the box it lists just the current server. You will probably want to add more from one of the inventories. Contribute more on Github.
The AWS module provides a user without access to the AWS management console with an ability to perform some basic read-only activities:
- to check status (stopped/started) of EC2 instances and their configuration
- to check status of RDS instances
- to get logs from RDS and EC2 and to read console messages
- to browse S3 buckets and files - without the ability to read files (just to check, for example, that a file exists)
- to get CPU charts
The following screenshot gives you an overview of what you can access:
data:image/s3,"s3://crabby-images/ad2ed/ad2ed7268403837890ceefa0d927d90aeb70087b" alt="aws1"
You can get detailed properties of EC2 and RDS:
data:image/s3,"s3://crabby-images/b2008/b20089e730b8ceee5242cd95556218b038bc1ccd" alt="aws2"
You can read the console logs of EC2 instances:
data:image/s3,"s3://crabby-images/eafe2/eafe213f5ebf1ce1e50b7b51b75726f907ce9441" alt="aws3"
For the running RDS and EC2 instances you can check CPU statistics:
data:image/s3,"s3://crabby-images/bf4ac/bf4ac3b0fb8d858c2cd9f9ee8fa4046280974948" alt="aws4"
For RDS, you can check the logs available on the AWS side (as you can't access them directly):
data:image/s3,"s3://crabby-images/63bfb/63bfbc79ceed5fb978a346daef7e0868ba5354bb" alt="aws5"
And finally, you can browse S2 buckets and files inside - without accessing the files, so no sensitive information can leak, but users can check the existence of a file or a backup:
data:image/s3,"s3://crabby-images/5eccd/5eccd5b157a4df559e0c475fceaf5644eee7cad9" alt="aws6"