本文へ移動
cccskills
無料GitHub で公開

cloud-pentest

Post-access cloud exploitation for AWS, GCP, and Azure — what to do AFTER you obtain credentials or reach a metadata endpoint. Covers IAM enumeration and privilege escalation (iam:PassRole, CreatePolicyVersion, AssumeRole chains, GCP service-account impersonation, Azure managed-identity abuse), IMDSv1/v2 metadata credential theft, STS token abuse, S3/GCS/Blob bucket takeover and object exfil, Lambda/Cloud Functions env-var secrets, cross-account and cross-service pivoting, and turning leaked keys into demonstrated impact (read PII, assume admin, exfil data). Assumes authorized scope only. Use when you have AWS/GCP/Azure keys, an SSRF hitting 169.254.169.254 / metadata.google.internal, a leaked service-account JSON, or a token, and need to escalate and prove impact. For finding buckets/origins first, use cloud-recon; for the SSRF entry point, see web2-vuln-classes. 中文触发词:云渗透、AWS提权、IAM枚举、元数据凭证、云安全审计

インストール方法を見る

含まれるファイル(1)

  • SKILL.md7.1 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

CLOUD PENTEST — Post-Access Exploitation

Recon finds the door; this is what you do inside. A leaked AKIA... key or a metadata token is not a finding on its own — the finding is what that identity can DO. Enumerate the identity, find the privesc path, prove real impact. Never touch data you're not authorized to.


AUTHORIZATION FIRST

[ ] Target cloud account/subscription is explicitly in scope
[ ] You have written authorization (program scope, engagement doc)
[ ] Read-only enumeration before ANY state change
[ ] No exfil of real customer data — prove access with a benign canary/own-account object
[ ] Discovered accounts/roles you can pivot to are NOT auto-authorized — confirm scope

Stop here if any box is unchecked.


0. IDENTIFY THE IDENTITY (do this first, always)

You haveFirst callTells you
AWS keysaws sts get-caller-identityaccount id, principal ARN, user vs role
AWS metadatacurl .../iam/security-credentials/<role>temp creds + role name
GCP SA JSON / tokengcloud auth ... / curl metadata ...tokenproject, service account, scopes
Azure token / MIIMDS .../identity/oauth2/tokentenant, object id, resource access

Never assume privilege. Enumerate what this identity actually has before planning.


1. AWS — ENUMERATE THEN ESCALATE

Enumerate (read-only):

aws sts get-caller-identity
aws iam get-account-authorization-details 2>/dev/null   # full policy dump if allowed
aws iam list-attached-user-policies --user-name <u>
aws iam list-role-policies / list-attached-role-policies
# No IAM read? Brute the effective perms with enumerate-iam / then map with a policy tool

Classic privesc paths (need the matching permission):

Permission heldEscalation
iam:CreatePolicyVersionWrite a new default *:* version onto an attached policy
iam:PassRole + ec2:RunInstances / lambda:CreateFunctionLaunch compute AS an admin role
iam:AttachUserPolicy / PutUserPolicyAttach AdministratorAccess to yourself
sts:AssumeRole (over-broad trust)Assume a more privileged role
iam:CreateAccessKey on another userMint keys for a privileged user
lambda:UpdateFunctionCode on privileged fnRun code with the function's role
iam:UpdateAssumeRolePolicyRewrite trust policy to let you assume it

Impact proof (benign): list a bucket you were told is in scope, sts assume-role into the admin role and get-caller-identity to show the new ARN, or read a canary object. Don't touch real PII.


2. METADATA (IMDS) — SSRF LANDS HERE

IMDSv1 (no token): GET http://169.254.169.254/latest/meta-data/iam/security-credentials/<role>
IMDSv2 (token):    PUT .../latest/api/token  (X-aws-ec2-metadata-token-ttl-seconds: 21600)
                   then GET with  X-aws-ec2-metadata-token: <token>
GCP:  GET http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token
      header: Metadata-Flavor: Google
Azure: GET http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/
      header: Metadata: true

Got temp creds → jump to section 1 (AWS) / 3 (GCP) / 4 (Azure) and enumerate what THAT role can do. SSRF alone is Medium; SSRF → metadata creds → data/admin is Critical.


3. GCP — IMPERSONATION IS THE PIVOT

gcloud auth activate-service-account --key-file=sa.json   # or use the token
gcloud projects get-iam-policy <project>
gcloud iam service-accounts list
PermissionEscalation
iam.serviceAccounts.getAccessToken / actAsImpersonate a higher-priv SA (--impersonate-service-account)
iam.serviceAccountKeys.createMint a key for a privileged SA
iam.roles.update on a custom role you holdAdd permissions to yourself
cloudfunctions.functions.update / deployRun code as the function's SA
storage.objects.get on a sensitive bucketRead secrets/state

Owner/Editor at project level = effectively admin. Check for the default Compute SA having Editor — extremely common.


4. AZURE — MANAGED IDENTITY & RBAC

az account show
az role assignment list --assignee <objectId> --all
az resource list
PathEscalation
Managed identity with ContributorDeploy/modify resources, run commands on VMs (az vm run-command)
Microsoft.Authorization/*/writeAssign yourself Owner
Key Vault access policy / RBACRead secrets, certs, keys
Automation Account / RunbookExecute as the automation identity
Storage account key readFull blob access

5. STORAGE — S3 / GCS / BLOB

[ ] List: aws s3 ls s3://<bucket> --no-sign-request  (public?)
[ ] Read/Write ACL: get-bucket-acl / put-object test (own canary file only)
[ ] Bucket policy allows *? cross-account?
[ ] Versioning / logging exposes old secrets?
[ ] Website / static hosting → subdomain takeover angle (see web2-vuln-classes)

Writable public bucket serving a live site = Critical (content injection / takeover). Readable bucket with secrets/PII = High/Critical.


6. SECRETS HARVEST (post-access)

[ ] Lambda/Cloud Function/App env vars (often hold API keys, DB creds)
[ ] SSM Parameter Store / Secrets Manager (if perms allow)
[ ] EC2 user-data / instance tags
[ ] Terraform state in the bucket you just read
[ ] CI/CD variables reachable from the identity

Each secret → re-run "identify the identity" for the NEW credential. Chain until you hit admin or crown-jewel data, then stop and write it up.


7. REPORT LINE (per finding)

Entry: <leaked key | SSRF→metadata | public bucket | SA JSON>
Identity: <ARN / SA / object id> — <what it could do>
Escalation: <exact permission → action that raised privilege>
Impact proven: <assumed admin ARN | read canary | listed in-scope resource>
Blast radius: <accounts/services/data reachable>
Fix: <least-privilege policy | IMDSv2 enforce | block-public-access | rotate>

Impact must be demonstrated with a concrete call, using benign/own-account objects. "The key might allow…" is not a finding — show get-caller-identity after the escalation.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Black-box security audit of a DEPLOYED AI agent (not the MCP server behind it) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR, excessive agency / unconfirmed destructive actions, and privilege compromise where the agent holds broader perms than the user. Use when the target is a live assistant/agent product with tool access (bookings, email, payments, file/RAG, browsing) rather than a raw LLM chat box or an MCP server you can read.

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3162026年10月10日 更新

argus

無料

Argus — the all-seeing scanner suite. Six automated scanners for high-value web + LLM bug classes — CORS misconfiguration (origin reflection / null / credentialed read), CRLF & host-header injection, NoSQL injection (operator auth-bypass / $where blind), JWT attacks (alg:none / RS256→HS256 confusion / secret crack), out-of-band confirmation of blind SSRF/XXE/SQLi/RCE/Log4Shell via interactsh, and an LLM red-team corpus (prompt-injection / jailbreak / system-prompt leak / exfil / indirect injection). Use when a target exposes a JSON API, a login endpoint, JWT auth, a parameter that might reach the server, a chatbot/agent, or any endpoint suspected of a blind/out-of-band bug.

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3162026年10月10日 更新

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other skills based on current hunting phase. Also use when asking "what should I do next" or "where am I in the process."

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3162026年10月10日 更新

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth), bypass tables (SSRF IP bypass, open redirect bypass, file upload bypass), language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, 4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, always-rejected list, conditional chain table, submission checklist). Use for ANY bug bounty task — starting a new target, doing recon, hunting specific vulns, auditing source code, testing AI features, validating findings, or writing reports. 中文触发词:漏洞赏金、安全测试、渗透测试、漏洞挖掘、信息收集、子域名枚举、XSS测试、SQL注入、SSRF、安全审计、漏洞报告

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3162026年10月10日 更新

Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (ASI01-ASI10), A-to-B bug chaining, bypass tables, language-specific grep patterns, and reporting (7-Question Gate, 4 validation gates, CVSS 3.1, PoC generation, submission checklist). Use for ANY bug bounty task — recon, hunting specific vulns, auditing source code, testing AI features, validating findings, or writing reports.

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3162026年10月10日 更新

CI/CD pipeline security hunting — GitHub Actions workflow injection, secret exfiltration, self-hosted runner poisoning, dependency confusion, OIDC token theft, and supply chain attacks. Covers sisakulint scanning, manual workflow analysis, and chaining CI/CD bugs into critical findings. Use when a target has public repos, GitHub Actions, CircleCI, Jenkins, or GitLab CI.

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3162026年10月10日 更新

awarexone のスキルをすべて見る

このスキルの問題を報告する