本文へ移動
cccskills
無料GitHub で公開

cloud-attack

Cloud control-plane exploitation for AWS, Azure/Entra, GCP, and Alibaba Cloud: IAM/RAM privilege escalation, impersonation, cross-account trust, serverless/compute control, and cloud-native persistence. Host OS persistence/C2 after root/SYSTEM belongs to /post. K8s RBAC belongs to /k8s. Operator chooses next modules; new identities default to /cloud-recon first.

インストール方法を見る

含まれるファイル(10)

  • SKILL.md3.8 KB
  • references/alibaba-persistence.md2.0 KB
  • references/alibaba-privesc-paths.md3.0 KB
  • references/aws-persistence.md2.7 KB
  • references/aws-privesc-paths.md3.3 KB
  • references/aws-serverless.md2.1 KB
  • references/azure-persistence.md2.1 KB
  • references/azure-privesc-paths.md1.8 KB
  • references/gcp-persistence.md1.5 KB
  • references/gcp-privesc-paths.md1.9 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

/cloud-attack — 云控制面利用

scope: 已有云身份,打到 更高云身份 / 账户控制 / 能下发 OS 执行的 compute。改策略前保存原文 + rollback。平台原生持久化在这里;主机 SSH/C2 → /post;K8s RBAC → /k8s。

厂商命令在 reference。先看是哪朵云、再看是提权还是持久化,只 Read 那一份。禁止把 AWS+Azure+GCP+阿里八个文件开局全读。

  • AWS:references/aws-privesc-paths.md / references/aws-serverless.md / references/aws-persistence.md
  • Azure:references/azure-privesc-paths.md / references/azure-persistence.md
  • GCP:references/gcp-privesc-paths.md / references/gcp-persistence.md
  • 阿里:references/alibaba-privesc-paths.md / references/alibaba-persistence.md

CVE 仅 versioned 组件 → ../shared/cve-enrichment.md。IAM/SCP 不是 CVE。


开局与收尾

开局第一件事:Read ./notes.md。没有则 python ~/.claude/skills/bin/notes.py init。只按已拿下/凭据继续。 走到哪条链,才 Read 一份 references/<file>.md。禁止开局全读、禁止凭记忆写 payload。 监听 / sudo / 输密码 / Permission denied:立刻停,说明等操作者做什么,等回报。不要假装已成功。 收尾:

  1. 追加 ./notes.md
  2. python ~/.claude/skills/bin/modules.py tail <本模块名> Read 备用:~/.claude/skills/shared/modules.yaml 禁止 ./modules.yaml 和 python ../bin/...
  3. 优先 default_next;never_default 不得当作默认(操作者点名除外)
  4. 名册外的名字不许建议
  5. 停。等操作者选 /模块 或 /clear /edr-bypass 半条链未完:打通后回本模块,不要 /clear。

0. 成功 / 强度

AssumeRole、改 trust、改 Lambda 代码、建联合凭据都是攻击原语,不是只读验证。先 snapshot 再改。

不算: 只列出 AdministratorAccess、只 pmapper 出图。


0.5 EDR

IAM/SCP/Conditional Access/SG = 本模块。
SSM/RunCommand 已经在 OS 执行 被 AV 杀 → /edr-bypass → 回来把云→host 链打完。


1. 决策树

手上是哪朵云 + 当前 principal 能做什么(来自 /cloud-recon)
        ↓
AssumeRole / actAs / 改 trust / 附加策略     → references/*-privesc-paths.md
PassRole + 建计算 / 改 serverless 代码        → serverless / compute 节
能下发 VM/SSM                                 → 执行后候选 /post 或继续云
能拿 EKS/AKS/GKE/ACK kubeconfig               → 停,候选 /k8s
要平台持久化                                  → references/*-persistence.md
身份已经变了                                  → 候选 /cloud-recon 再枚举新身份

不要按 AWS→Azure→GCP→阿里把四本手册跑完。


2. 原语(指针)

提权: CreatePolicyVersion / Attach*Policy / UpdateAssumeRolePolicy / PassRole+create / SA impersonation / RAM UpdateRole。

Serverless/Compute: Lambda UpdateFunctionCode、FC 改代码、EC2+实例配置、元数据 Role。拿到 OS shell 后本链可停,候选 /post。

持久化: AccessKey、Role trust、联邦凭据、Lambda Layer。SA key 是否允许创建看组织策略。

K8s 边界: 只拿到集群凭证就出 /k8s,不要在这打 RBAC。


3. 完成后

写入 ./notes.md。候选只按「开局与收尾」跑 python ~/.claude/skills/bin/modules.py tail(默认不要再 /cloud-attack)。

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

ad-attack

無料

Active Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the account), delegation, NTLM coercion/relay, lateral movement, ACL abuse, ADCS ESC1-ESC17 and CVE paths, dMSA/BadSuccessor, Kerberos reflection, identity confusion, management-plane, domain trust, and domain persistence. Own the current AD chain through crack-and-use to DA, equivalent domain control, or the targeted host SYSTEM. Do not stop after requesting TGS. Host C2 belongs to /post. Operator chooses next modules.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

ad-recon

無料

Active Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, BloodHound, Server 2025/dMSA/Ghost SPN candidates, and trust mapping. Recon only — do not exploit Kerberoast-to-DA, DCSync, or change passwords. Operator may select /ad-attack after cards are ready.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

cicd

無料

CI/CD pipeline and software-supply-chain exploitation: Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, Gitea/Forgejo, self-hosted runners/agents, poisoned pipeline execution, artifact/cache abuse, dependency confusion, third-party Action trust, GitOps/registry poisoning, workload identity/OIDC, and emerging agentic CI/CD. Use this skill when the operator has access to a CI/CD system, source repository, build/deploy configuration, runner/agent, artifact/package/registry path, or software delivery trust chain.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

Cloud control-plane reconnaissance for AWS, Azure/Entra, GCP, and Alibaba Cloud: identity, IAM/RAM, trust, resources, metadata, and managed-Kubernetes cloud-side boundary. Recon only — no policy changes, no privilege escalation. Operator may select /cloud-attack or /k8s.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

creds

無料

Credential operations: secret discovery, classification, extraction, conversion, offline cracking of hashes the operator already has as a credential job, policy-aware spraying, NetNTLM capture, generic SMB relay, and Windows/Linux harvest. Do not hijack an in-progress /ad-attack Kerberoast/AS-REP chain (that module cracks and uses the ticket itself). Do not DCSync, read LAPS LDAP, or escalate cloud IAM. Usable credentials are recorded; the operator chooses the next module.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

Endpoint defense evasion after an operator-selected chain already has a valid execution path but AV/EDR/AMSI/WDAC/PPL/memory/kernel telemetry blocks the intended action. Originating modules include /web-attack /ad-attack /cloud-attack /k8s /cicd /service-attack /phishing /privesc-win /privesc-linux /creds /post /shell. Success is the blocked action becoming executable, then resume the originating module — not obtaining a shell here.

日本語の概要は準備中です。原文の説明を表示しています。

pale-knight/redteam-skill492026年8月23日 更新

pale-knight のスキルをすべて見る

このスキルの問題を報告する