Skip to main content

cloud-overview

Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting.

跳到安装

来源信息

仓库
BitterSecurity/Decepticon
最近来源活动
2026年6月29日 01:38
检测到的 SKILL.md 语言
英语
星标
5,611
分支
1,061

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

文件资源管理器
20 个文件

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
cloud-overview
description
Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting.
metadata
{"subdomain":"cloud","when_to_use":"cloud aws gcp azure iam s3 kubernetes k8s terraform metadata imds privesc lane overview routing","mitre_attack":["T1078.004","T1530","T1552.005","T1552.007","T1610","T1611"]}
# Cloud Hunter Skill Catalog ## Playbooks | Skill | Use for | |---|---| | `/skills/standard/cloud/aws-iam-enum/SKILL.md` | IAM enumeration + privesc | | `/skills/standard/cloud/s3-takeover/SKILL.md` | Dangling bucket / subdomain takeover | | `/skills/standard/cloud/k8s-pivot/SKILL.md` | Pod escape, RBAC abuse, hostPath | | `/skills/standard/cloud/terraform-state-leak/SKILL.md` | Exposed state file exploitation | | `/skills/standard/cloud/imds-pivot/SKILL.md` | SSRF → metadata → IAM role | ## Workflow (authenticated engagement) 1. `bash("aws sts get-caller-identity")` 2. `bash("aws iam list-attached-user-policies --user-name <me>")` 3. For each attached policy: fetch JSON and `iam_policy_audit` 4. Feed Terraform state via `bash("aws s3 cp s3://bucket/terraform.tfstate -")` → `tfstate_audit` 5. `bash("kubectl get pods -A -o json")` → `k8s_audit` 6. Every privesc primitive → kg_add_node + chain edges ## Workflow (post-SSRF) 1. `metadata_endpoints("aws")` for the target cloud 2. Pivot URL one at a time via the SSRF vector 3. Confirmed creds → `credential` node + `leaks` edge from the SSRF vuln 4. `plan_attack_chains(promote=True)` to see the full path
在 GitHub 查看