# Pentest Cloud Infrastructure

> Cloud security posture management and container security assessment for AWS, Azure, GCP, and Kubernetes.

- Skill: `jd-opensource/pentest-cloud-infrastructure` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add jd-opensource/pentest-cloud-infrastructure`
- Raw SKILL.md: https://api.skillmd.com/api/skills/jd-opensource/pentest-cloud-infrastructure/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: jd-opensource (https://skillmd.com/u/jd-opensource)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/jd-opensource/pentest-cloud-infrastructure

---


# Pentest Cloud Infrastructure

## Purpose
Assess the security configuration of cloud environments and containerized infrastructure to detect misconfigurations, excessive permissions, and vulnerabilities.

## Core Workflow
1. **Cloud Config Audit**: Assess cloud provider configuration (AWS/Azure/GCP) using `prowler` and `scoutsuite`.
2. **IaC Scanning**: Analyze Infrastructure-as-Code (Terraform, CloudFormation) for security flaws using `checkov` and `terrascan`.
3. **Container Security**: Scan container images and runtime environments using `trivy`, `clair`, and `dockle`.
4. **Kubernetes Assessment**: Audit K8s clusters for CIS compliance and vulnerabilities using `kube-bench` and `kube-hunter`.
5. **Runtime Monitoring**: Analyze runtime behavior and rule violations using `falco`.

## References
- `references/tools.md`
- `references/workflows.md`

