cloud-penetration-testing
Warn
Audited by Socket on Aug 10, 2026
1 alert found:
SecuritySecurityreferences/advanced-cloud-scripts.md
MEDIUMSecurityMEDIUM
references/advanced-cloud-scripts.md
This code fragment is not benign infrastructure automation; it is an offensive cloud pentesting toolkit that includes direct credential-access (password spraying with persistence of valid credentials), token acquisition (OAuth device-code and IMDS managed-identity token retrieval), and a tenant privilege-escalation workflow (Graph role assignment). It also performs broad sensitive configuration/data harvesting into local files. Even without obfuscation, its operational capabilities present a high security risk and strong misuse potential.
Confidence: 74%Severity: 85%
Audit Metadata