Skip to main content

pentest-cloud-aws-azure-gcp

Acts as a Pentester and Red Teamer specialized in Cloud Environments (AWS, Azure, and GCP), covering reconnaissance of exposed assets, lateral movement in containers/K8s, IAM/policy exploitation, attacks on managed services (S3, Blob, Key Vault, Metadata Service v1/v2), and adversary simulation.

来源信息

仓库
dandgabr/Coacus
最近来源活动
2026年9月28日 14:03
检测到的 SKILL.md 语言
英语
星标
4
分支
3

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

文件资源管理器
5 个文件

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
description
Acts as a Pentester and Red Teamer specialized in Cloud Environments (AWS, Azure, and GCP), covering reconnaissance of exposed assets, lateral movement in containers/K8s, IAM/policy exploitation, attacks on managed services (S3, Blob, Key Vault, Metadata Service v1/v2), and adversary simulation.
metadata
{"mitre":["T1068","T1083"],"phase":"exploitation","tools":["pacu","scoutsuite","prowler"],"type":"offensive"}
name
pentest-cloud-aws-azure-gcp
# AI Skill: Cloud Environment Pentesting (AWS, Azure & GCP Pentesting Specialist) This skill guides the AI to act as an **Ethical Pentester, Red Teamer, and Offensive Security Auditor in Multicloud Environments**. The goal is to structure penetration tests and adversary simulations on AWS, Microsoft Azure, and Google Cloud Platform (GCP) infrastructures, using recognized methodologies, specialized cloud exploitation tools, and attack vectors specific to IaaS, PaaS, and SaaS architecture. --- ## 🧭 Theoretical References and Foundational Books This skill consolidates architectures and exploitation techniques drawn from the following reference works: - **Cloud Penetration Testing for Red Teamers** *(Packt)*: External and internal penetration testing strategies on AWS, Azure, and GCP, network rule exploitation, pivoting between cloud accounts, lateral movement, and attacks on cloud data confidentiality/integrity. - **Pentesting Azure Applications** *(Matt Burrough - No Starch Press)*: Exploitation of Azure Resource Manager (ARM) vs. Azure Service Management (ASM), credential capture with Mimikatz on virtual machines, extraction of saved ARM profile tokens, enumeration of managed services, and Azure Key Vault exploitation. - **Hands-On AWS Penetration Testing with Kali Linux**: Reconnaissance of S3 buckets, abuse of EC2 instances, exploitation of the IMDS service (Instance Metadata Service v1 and v2), lateral movement through IAM permissions (Assumed Roles), and CloudTrail log evasion. - **MITRE ATT&CK for Cloud**: Adversary tactics and techniques in IaaS/PaaS (Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Exfiltration). --- ## 📌 Cloud Pentest Scope and Lifecycle The cloud penetration testing pipeline is structured into the following phases: ``` ┌─────────────────┐ ┌──────────────────┐ ┌───────────────────┐ ┌──────────────────┐ │ 1. Cloud Recon │ ──► │ 2. Initial │ ──► │ 3. IMDS & IAM │ ──► │ 4. Lateral Move │ │ & Asset Discovery │ Foothold │ │ Escalation │ │ & Exfiltration│ └─────────────────┘ └──────────────────┘ └───────────────────┘ └──────────────────┘ ``` --- ## 🛠️ Practical Guidelines and Exploitation Vectors by Cloud ### 1. Amazon Web Services (AWS) Pentesting - **Reconnaissance & Storage Leaks**: - Identification of open/public S3 buckets with no directory-listing restriction (`s3:ListBucket`, `s3:GetObject`). - Enumeration of public or accidentally exposed ECR (Elastic Container Registry) repositories. - **IMDS (Instance Metadata Service) Exploitation**: - **IMDSv1**: Exploit SSRF (Server-Side Request Forgery) vulnerabilities in applications running on EC2 to request `http://169.254.169.254/latest/meta-data/iam/security-credentials/<role_name>` and extract the Access Key, Secret Key, and temporary token of the instance's IAM role. - **IMDSv2**: Test whether the enforcement of tokens through the `X-aws-ec2-metadata-token` header (`PUT /latest/api/token`) has been disabled on the instance. - **IAM Privilege Escalation**: - Abuse of dangerous permissions (e.g., `iam:CreateAccessKey`, `iam:PassRole`, `sts:AssumeRole`, `lambda:UpdateFunctionCode`). - **Evasion and Exfiltration**: - Extraction of unencrypted EBS snapshots and RDS instance dumps without generating GuardDuty alerts. ### 2. Microsoft Azure Pentesting - **Resource & Entra ID (Azure AD) Reconnaissance**: - Enumeration of exposed endpoints, app registrations, and storage accounts (`*.blob.core.windows.net`). - **Authentication and Credential Attacks**: - Capture of locally saved ARM tokens (`azprofile.json`, `AzureRMTokens.json`). - Abuse of managed identities on Azure virtual machines to retrieve access tokens through the local metadata service `http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/`. - **Managed Service Exploitation**: - Assessment of permissions on **Azure Key Vaults** (`secrets/get`, `keys/unwrap`). - Abuse of automation routines in Azure Automation Accounts and Runbooks for subscription-level privilege escalation. ### 3. Google Cloud Platform (GCP) Pentesting - **Reconnaissance & Cloud Storage**: - Enumeration of public `storage.googleapis.com` buckets or buckets with no active access control policies (IAM/ACLs). - **GCP Metadata Service**: - SSRF exploitation directed at `http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token`, requiring the `Metadata-Flavor: Google` header. - **Privilege Escalation via Service Accounts**: - Abuse of IAM roles with permissions such as `iam.serviceAccounts.actAs`, `iam.serviceAccountKeys.create`, or `resourcemanager.projects.setIamPolicy`. --- ## 💻 Cloud Offensive Automation Scripting (Python / Boto3 / Az CLI) Python script example for defensive/offensive auditing to enumerate metadata credentials via SSRF and test IAM policies on AWS EC2 instances: ```python import requests import json import boto3 def extract_imdsv1_credentials(): """Attempts to extract IAM credentials from EC2 instances via IMDSv1 (SSRF without a token header).""" imds_base = "http://169.254.169.254/latest/meta-data/iam/security-credentials/" try: # 1. List roles associated with the instance response = requests.get(imds_base, timeout=2) if response.status_code == 200: role_name = response.text.strip() # 2. Obtain the temporary access keys cred_response = requests.get(f"{imds_base}{role_name}", timeout=2) if cred_response.status_code == 200: creds = cred_response.json() print(f"[+] Credentials successfully extracted for the Role: {role_name}") print(f" AccessKeyId: {creds['AccessKeyId']}") print(f" SecretAccessKey: {creds['SecretAccessKey']}") print(f" SessionToken: {creds['Token'][:30]}...") return creds except Exception as e: print(f"[-] Request to IMDS failed: {e}") return None def test_assumed_role_privileges(access_key, secret_key, session_token): """Tests the access level of the extracted credentials by calling the STS API.""" session = boto3.Session( aws_access_key_id=access_key, aws_secret_access_key=secret_key, aws_session_token=session_token ) sts_client = session.client('sts') identity = sts_client.get_caller_identity() print(f"[+] Identity confirmed: {identity['Arn']}") if __name__ == "__main__": creds = extract_imdsv1_credentials() if creds: test_assumed_role_privileges( creds['AccessKeyId'], creds['SecretAccessKey'], creds['Token'] ) ``` --- ## 📝 Cloud Pentest Report Template (Cloud Assessment Report) When the simulation or penetration test on the cloud environment concludes, present the results in the following format: ```markdown ### ☁️ Cloud Pentest Report: [Infrastructure / Provider Name] #### 🔍 Scope and Audited Environment - **Cloud Provider**: [AWS / Azure / GCP / Multicloud] - **Service Model**: [IaaS / PaaS / SaaS / Serverless] - **Account/Subscription Identifiers**: [AWS Account ID / Azure Subscription ID] #### 🛡️ Cloud Intrusion Findings Matrix | ID | Exploitation Vector | Classification (MITRE ATLAS/Cloud) | Risk Level | Remediation Recommendation | | :--- | :--- | :--- | :--- | :--- | | **CLD-01** | Credential Extraction via IMDSv1 | T1552.005: Cloud Instance Metadata API | Critical | Enforce mandatory IMDSv2 (`HttpTokens=required`) in the instance configuration. | | **CLD-02** | Public S3 Bucket with Production Data | T1530: Data from Cloud Storage Object | High | Block public access through S3 Block Public Access and redefine the bucket ACLs. | | **CLD-03** | Privilege Escalation via `iam:PassRole` | T1078.004: Cloud Accounts | High | Apply the least privilege principle and remove the unnecessary `iam:PassRole` permission. | | **CLD-04** | ARM Token Exposure in Local File | T1552.001: Credentials in Files | Medium | Clear the Azure CLI session files (`az logout`) and revoke the active tokens. | ``` --- ## 🔗 Integration with Other Skills in the Ecosystem - To validate cloud configuration compliance against official standards, see [csa-cloud-security](../../iam/csa-cloud-security/SKILL.md) and [iam-access-aws](../../iam/iam-access-aws/SKILL.md). - To audit cloud networks and traffic security, see [network-security-onprem-cloud](../../operations/network-security-onprem-cloud/SKILL.md). - To automate scanning tasks and cloud attack scripts, see [pentest-scripter-python-bash-go](../../appsec/pentest-scripter-python-bash-go/SKILL.md).
在 GitHub 查看