Skip to main content

cloud-defense

Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) —

Quellinformationen

Repository
Kur1sulab/whitebox
Letzte Quellaktivität
12. August 2026 um 15:17
Erkannte Sprache von SKILL.md
Englisch
Sterne
1
Forks
0

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

Datei-Explorer
4 Dateien

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
cloud-defense
description
Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) —
# Cloud Defense The blue-team counterpart to [`cloud-containers`](https://github.com/xiaoyang-xyc/blackbox/blob/main/pt-cloud-containers/SKILL.md). For each attacker move — lateral movement, privilege escalation, data exfiltration, defense evasion — this skill gives the log event to alert on and the single control that removes the technique. Use it to turn an offensive cloud finding into a concrete detection and remediation. ## When to use - Writing the remediation / hardening section of a cloud pentest report. - Cloud detection engineering: deciding which control-plane events to alert on. - Reviewing an AWS / Azure / GCP account's posture against the post-compromise chain. ## Workflow 1. Confirm the logging prerequisites are in place (org-wide trail, data events, threat detection on) — without them the signals below are invisible. 2. Map each attacker stage to its detection signal — see [reference/detection-signals.md](reference/detection-signals.md). 3. Apply the preventive control that breaks each stage — see [reference/hardening-controls.md](reference/hardening-controls.md). 4. Re-run the matching offensive technique from [`cloud-containers`](https://github.com/xiaoyang-xyc/blackbox/blob/main/pt-cloud-containers/SKILL.md) to confirm the control holds or the alert fires. ## References - [reference/INDEX.md](reference/INDEX.md) — router - [reference/detection-signals.md](reference/detection-signals.md) — per-stage log signals + logging prerequisites - [reference/hardening-controls.md](reference/hardening-controls.md) — the control that breaks each stage
Auf GitHub ansehen