Red Team — Cloud Attacks

Guide cloud red teaming with AWS, Azure, and GCP attack techniques.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/defconxt/CIPHER --skill red-team-cloud-attacks
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Red Team — Cloud Attacks
Source: https://github.com/defconxt/CIPHER/tree/main/skills/red-team/cloud
Command: npx skills add https://github.com/defconxt/CIPHER --skill red-team-cloud-attacks

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill empowers security professionals to understand and execute advanced cloud-based attack methodologies, crucial for robust penetration testing and defense strategy development.

Core Features & Use Cases

  • Cloud Attack Vectors: Covers initial access, privilege escalation, and persistence across AWS, Azure, and GCP.
  • Service Exploitation: Details techniques for abusing services like S3, Lambda, Azure AD, and GCS.
  • Use Case: A red team operator needs to simulate a sophisticated cloud breach. This Skill provides the exact commands and conceptual understanding to exploit cloud misconfigurations, escalate privileges, and maintain access, mimicking real-world threats.

Quick Start

Use the Red Team Cloud skill to enumerate AWS IAM permissions for a given user.

Frequently Asked Questions about Red Team — Cloud Attacks

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform privilege escalation in AWS during a cloud penetration test?

AWS privilege escalation during cloud penetration testing involves enumerating IAM permissions and abusing misconfigured service roles. This Skill provides specific commands and exploitation chains to identify and execute these attacks across AWS environments.

What are common attack vectors for initial access in Azure and GCP?

Initial access vectors in Azure and GCP often exploit misconfigured services like Azure AD or GCS. This Skill details techniques for abusing these cloud services to gain a foothold and establish persistence during red team operations.

Does this cover specific commands for exploiting cloud services like S3 and Lambda?

Yes, it covers specific exploitation commands for abusing services like S3 and Lambda. The Skill details techniques for service abuse, privilege escalation, and persistence across AWS, Azure, and GCP environments.

How do I enumerate AWS IAM permissions to simulate a cloud breach?

To enumerate AWS IAM permissions for breach simulation, you use the Skill to identify misconfigurations and escalate privileges. It provides the exact commands and conceptual understanding needed to mimic real-world cloud threats.

Can I use this for red teaming across multiple cloud providers or just AWS?

You can use this for red teaming across AWS, Azure, and GCP. It provides comprehensive guidance on attack vectors, service exploitation, and persistence techniques tailored for all three major cloud platforms.

What is the best way to maintain persistence in a compromised cloud environment?

Maintaining persistence in a compromised cloud environment involves abusing native services and escalated privileges to retain access. This Skill details specific techniques and exploitation chains for establishing persistence across AWS, Azure, and GCP.