Offensive Cloud

Cloud security attack methodology for AWS, Azure, and GCP: credential harvesting (IMDS, ~/.aws, env vars, CI secrets, instance roles), enumeration (pacu, ScoutSuite, Prowler, ROADtools, gcp_enum), privilege escalation (IAM PassRole, AssumeRole chains, Lambda/Functions flips, Azure Owner-on-self, GCP serviceAccountTokenCreator), persistence (IAM keys, AAD app registration, GCP svc account keys, EventBridge/Logic Apps backdoors), data exfiltration (S3/Blob/GCS, snapshot share, RDS/CosmosDB/Cloud SQL), lateral movement (cross-account assume, Azure AD multi-tenant, GCP project hierarchy), serverless (Lambda env vars, layer hijack, Step Functions), Kubernetes-on-cloud (EKS/AKS/GKE paths to node and metadata), and CSPM evasion (CloudTrail blind spots, GuardDuty mute, Sentinel rule shaping). Use when scope is cloud accounts, when you hold cloud credentials, or when assessing cloud posture. Authorized security research, training, or assessment only.

26zl f644ea3 12.3 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/offensive-cloud commit f644ea38ad

Frequently asked questions

npx skillmds@latest add 26zl/offensive-cloud