Offensive storage exposure testing across AWS S3, Azure Blob/ADLS, and GCP Cloud Storage - resolves s3 public access state (Block Public Access, ACLs, signed URLs) before declaring exposure - covers — existence, listing, read, write, overwrite, delete,…
GCP IAM privilege escalation - gcp service account impersonation primitives (actAs, getAccessToken, signBlob, signJwt), serviceAccountKeys, setIamPolicy at project/folder/org levels, custom role manipulation, — service account actAs, getAccessToken, signBlob…
Build a working model of the application as a system - roles, resources, workflows, state transitions, trust and tenant boundaries - from black-box behavior, and turn that model into prioritized hypotheses. The foundation skill that converts a recon endpoint…
Distinguish real unauthorized data exposure from harmless metadata - response field differentials by role and tenant, over-fetching, alternate serializers and exports, error responses, notifications, audit logs, cached content - requiring meaningful…
Black-box testing of the full authentication and session lifecycle - registration, login, MFA, password reset, recovery, email change, logout, refresh, device trust - and session token handling including fixation, invalidation, replay, and cross-context…
Application-level authorization methodology - horizontal, vertical, and tenant boundary testing, ownership transitions, method and route differentials. Replay legitimate privileged requests with lower privilege using authz_matrix first to produce differential…
Discover the application intended business rules and violate their assumptions - money and value manipulation, limit bypass, identity and relationship abuse, state misuse - proving persisted out-of-policy outcomes rather than status-code blips.
Model and attack the full file processing pipeline - upload, validation, storage, transformation, scanning, preview, import, processing, serving - hunting parser confusion, archive extraction abuse, traversal, decompression issues, access-control gaps between…