cloud-iam-deep

Identifies and exploits cloud IAM credential exposures across AWS, Azure, and GCP.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/chatbotkit/rook --skill cloud-iam-deep-chatbotkit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cloud-iam-deep
Source: https://github.com/chatbotkit/rook/tree/main/skills/cloud-iam-deep
Command: npx skills add https://github.com/chatbotkit/rook --skill cloud-iam-deep-chatbotkit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Cloud IAM misconfigurations and exposure patterns across AWS, Azure, and GCP enable unauthorized credential use and privilege escalation. This skill provides a structured, multi-cloud red-team workflow from discovery to post-credential exploitation, helping security teams understand and simulate attacker paths.

Core Features & Use Cases

  • Enumerates cloud IAM credentials and misconfigurations across AWS, Azure, and GCP.
  • Demonstrates cross-cloud privilege-escalation patterns (STS/AssumeRole chaining, identity pools, service accounts).
  • Guides post-compromise actions and evidence collection for blue-team validation.

Quick Start

Provide a practical, end-to-end cloud IAM abuse workflow using mock data to illustrate enumeration and escalation.

Frequently Asked Questions about cloud-iam-deep

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enumerate cloud IAM misconfigurations across AWS, Azure, and GCP?

Cloud IAM enumeration involves identifying exposed credentials and analyzing identity permissions across AWS, Azure, and GCP. This skill structures red-team workflows to discover unauthorized credential use and map privilege escalation paths.

What is STS AssumeRole chaining for cross-account privilege escalation?

STS AssumeRole chaining is a privilege escalation technique using compromised credentials to sequentially assume roles across multiple AWS accounts. This skill demonstrates exploiting cross-service trust relationships to achieve admin access.

Can I use this skill for red-team engagements involving cross-cloud access exploitation?

Yes, this skill applies to red-team engagements involving cross-cloud access exploitation in cloud-native environments. It provides structured workflows for credential discovery, enumeration, and privilege escalation across AWS, Azure, and GCP.

How do I validate post-exploitation actions after a cloud IAM compromise?

Validating post-exploitation actions requires evidence collection and blue-team validation workflows after achieving privilege escalation. This skill guides post-compromise actions to verify unauthorized access and document the attack chain.

What is the best way to simulate attacker paths using exposed cloud IAM credentials?

Simulating attacker paths requires a structured multi-cloud workflow from credential discovery to post-exploitation validation. This skill helps security teams understand and demonstrate cross-cloud privilege escalation patterns using mock data.