What problem does it solve?
Cloud security assessments often miss critical attack paths like IAM privilege escalation chains, SSRF-to-metadata credential theft, and cross-account lateral movement, leaving organizations with incomplete pictures of their actual cloud risk.
Core Features & Use Cases
- Structured Cloud Pentest Workflow: Seven-step methodology covering scoping under the shared responsibility model, reconnaissance, IAM privilege escalation, SSRF-to-IMDS exploitation, lateral movement, persistence testing, and reporting.
- Tool-Specific Guidance: Concrete commands for Pacu, ScoutSuite, Prowler, and CloudFox across AWS, Azure, and GCP, including IMDSv1/v2 testing and cross-account role assumption checks.
- MITRE ATT&CK Cloud Reporting: Findings template that maps each issue to ATT&CK tactics with severity, proof of concept, and remediation guidance.
- Use Case: A security consultant with read-only developer credentials in a client's AWS account uses this workflow to enumerate permissions with Pacu, discover an iam:CreatePolicyVersion escalation path, and document the full chain to administrative access in an ATT&CK-mapped report.
Quick Start
Ask the AI to plan and execute an authorized penetration test of your AWS account, starting from low-privilege credentials and reporting findings mapped to the MITRE ATT&CK Cloud matrix.