AWSDoor

AWSDoor isn't an AWS product, despite the name. It's a post-compromise persistence tool attackers use once they're already inside an AWS environment, abusing native features like IAM, Lambda, and EBS snapshots to keep hidden access.