ABCDEFGHIJKLMNOPQRSTUVWXYZAAAB
1
FEATURE
2
APPROACH/TOOLCan AWS Web Console be Accessed from Tool?Can AWS CLI Commands be Executed from Tool?Does Tool Support Windows Remote Desktop?What Credentials are Required to the Tool?What Networking is Required to Access the Tool?Does Tool Provide an "AirGap" between Staff System and Target?What Type of AWS Credentials are Supported by Tool?What are Network Requirements for Tool to Access Target?Does Tool Supports Multiple Simulaneous Users?Does Tool Log Commands for Audit Purposes?How is Tool Patched?What Cost Efficiencies are Possble?Access to "Local" Persistent Files on Tool?Access to Shared Files from ToolTool can be Domain-joined?Cornell Two-Step Login Supported to Access Tool?
3
linux staff laptop/workstation (direct to target)yyyCornell SSOphysical possessionn- static access keys
- temporary access keys via SSO
(optional) Cornell VPNnnautomaticnot applicabley- SFS
- S3
- git
yy
4
Windows staff/laptop workstation (direct to target)yyyCornell SSOphysical possessionn- static access keys
- temporary access keys via SSO
(optional) Cornell VPNnnautomaticnot applicabley- SFS
- S3
- git
yy
5
VM in MSOP (Windows or linux)Windows: y
linux: n
yWindows: y
linux: n
SFam permissions- MSOP Hopper
- Cornell VPN
y- static access keys
- temporary access keys via SSO
variesynautomaticnot applicabley- SFS
- S3
- git
Windows: y
linux: n
Windows: y
linux: n
6
VM in MSITC (Windows or linux)Windows: y
linux: n
yWindows: y
linux: n
SFam permissions- MSOP Hopper
- Cornell VPN
y- static access keys (discouraged)
- temporary access keys via SSO
- IAM instance profile
variesynautomaticMSITC power scheduley- S3
- git
Windows: y
linux: n
Windows: y
linux: n
7
Pet linux EC2 instancenyn- keypair (usually)
- local username/password (uncommon)
variesy- static access keys (discouraged)
- temporary access keys via SSO
- IAM instance profile
variesyn- requires configuration/actionpower scheduling availabley- S3
- EFS
- git
ny
8
Pet Windows EC2 instanceyyy- keypair + local username/password
- local username/password (uncommon)
variesy- static access keys (discouraged)
- temporary access keys via SSO
- IAM instance profile
variesyn- requires configuration/actionpower scheduling availabley- S3
- git
yy
9
Ephemeral linux EC2 instancenyn- keypair (usually)
- local username/password (uncommon)
variesy- static access keys (discouraged)
- temporary access keys via SSO
- IAM instance profile
variesyn- requires configuration/action- create+destroy as needed
- power scheduling available
n- S3
- EFS
- git
ny
10
Ephemeral Windows EC2 instanceyyy- keypair + local username/password
- local username/password (uncommon)
variesy- static access keys (discouraged)
- temporary access keys via SSO
- IAM instance profile
variesyn- requires configuration/action- create+destroy as needed
- power scheduling available
n- S3
- EFS
- git
yy
11
AWS Workspaceyyy- Cornell SSO (Two-step Login not supported)public internety- static access keys
- temporary access keys via SSO
variesy (using separate instances)nautomaticautomatic sleepy- S3
- git
- EFS (linux only)
- Google Drive
- Box
y???
12
AWS Appstreamyyy?- Cornell SSO + AWS IAMpublic internety- static access keys
- temporary access keys via SSO
variesy (using separate instances)nautomatic?automatic provision and terminationy- S3
- git
- Google Drive
- Box
yy
13
Cloud 9 on your EC2 instance (linux)not applicableyn- Cornell SSO + AWS IAMpublic internety- static access keys (discouraged)
- temporary access keys via SSO
- IAM instance profile
variesnn- requires configuration/actionpower scheduling availabley- S3
- EFS
- git
nn
14
Cloud 9 on AWS-managed EC2 instance (linux)not applicableyn- Cornell SSO + AWS IAMpublic internety- static access keys (discouraged)
- temporary access keys via SSO
- IAM instance profile
variesnn- requires configuration/actionautomatic sleepy- S3
- EFS
- git
nn
15
AWS SSM Session Manager - Webnot applicableyn- Cornell SSO + AWS IAMpublic internety- static access keys (discouraged)
- temporary access keys via SSO
- IAM instance profile
none requiredy?ynot applicablenot applicablen- S3
- EFS
- git
ny
16
AWS SSM Run Command - Webnsort of; limitedn- Cornell SSO + AWS IAMpublic internety- IAM instance profilenone requiredyynot applicablenot applicablen- S3
- EFS?
- git
ny
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100