cloud-security
Installation
SKILL.md
Cloud Security & Attack
When to Activate
- Cloud penetration test / red team against AWS, Azure (Entra ID), or GCP
- IAM / identity privilege escalation and cross-account or cross-tenant pivoting
- Compromised web app or SSRF reachable from cloud compute — harvest metadata credentials
- Kubernetes / container assessment, node breakout, cluster takeover
- CI/CD and IaC review: Terraform state, OIDC federation trust policies, pipeline secrets
- Post-exploitation: secret extraction, lateral movement, persistence in cloud control plane