What problem does it solve?
cloud-iam-deep eliminates guesswork after a cloud credential is exposed by quickly validating what the credential can access and mapping likely IAM privilege-escalation paths across AWS, Azure, and GCP.
Core Features & Use Cases
- Credential validation in minutes: Verifies identity and enumerates what IAM permissions the exposed AWS key, Azure credential/managed identity context, or GCP service account can actually exercise.
- External-only cloud attack chain analysis: Focuses on paths that start from externally reachable leakage (e.g., leaked key/JSON, SSRF reaching metadata/IMDS, exposed K8s tokens) and then reasons about post-credential discovery privilege analysis.
- Privilege escalation pattern guidance: Provides structured escalation techniques (e.g., AWS STS chaining and IMDSv1/v2 SSRF considerations, Azure Managed Identity abuse, GCP service-account JSON abuse, Kubernetes SA token abuse) while emphasizing guardrails and audit awareness.
Quick Start
Use the cloud-iam-deep skill to validate the exposed AWS access key and summarize what actions it permits plus the highest-priority escalation patterns it enables.