cloud-security-technique

Installation
SKILL.md

Cloud Security Technique

Goal: from cloud credential, account ID, or workload shell to maximum demonstrated impact within the authorized cloud scope.

When this technique applies

  • Valid cloud provider credentials (AWS IAM keys, Azure service principal, GCP service account key).
  • Shell access inside a cloud workload (EC2, VM, container, Lambda, Cloud Function).
  • Cloud account ID or organization name for passive enumeration.
  • Need to assess cloud-specific attack paths: IAM privilege escalation, storage exposure, metadata service abuse, container escape, cross-account pivot.

Boundary

  • Input from recon-technique: cloud asset discovery (bucket names, subdomain patterns, provider prefix lists).
  • Input from post-exploit-technique: shell on cloud workload, harvested cloud credentials.
  • Web application exploitation in cloud: use web-exploit-technique (SSRF to metadata, API auth bypass).
  • Deep container escape chains: this skill covers the common primitives; for kernel-level escape development use offensive-coding/linux-internals-dev/.
  • Cracking cloud credentials: use cracking-technique.
Installs
5
GitHub Stars
22
First Seen
Jun 19, 2026
cloud-security-technique — aeondave/malskill