What problem does it solve?
This Skill provides a comprehensive framework for red-team operators to assess and exploit cloud IAM configurations, identifying potential vulnerabilities and misconfigurations in AWS, Azure, and GCP environments.
Core Features & Use Cases
- Cloud IAM Enumeration: Enumerate and analyze IAM roles, policies, and users across AWS, Azure, and GCP.
- Privilege Escalation: Identify and exploit privilege escalation paths within cloud environments.
- Credential Validation: Validate and assess the impact of leaked cloud credentials.
- Use Case: For a red-team engagement targeting a cloud environment, this Skill can be used to identify misconfigured IAM roles that allow for unauthorized access to sensitive resources.
Quick Start
Run the cloud-iam-deep skill to enumerate IAM roles and policies in the AWS account 'my-aws-account'.