{"enrichment":{"faq":[{"a":"Cloud Security addresses AWS IAM privilege escalation as its highest-weighted intent (0.28). The skill covers misconfigurations in IAM policies that enable attackers to escalate privileges, including cross-account privilege escalation paths and techniques for exploiting overly permissive role assumptions. It provides reconnaissance and exploitation references for identifying and leveraging these weaknesses in AWS environments.","q":"What AWS IAM privilege escalation techniques does Cloud Security cover?"},{"a":"Cloud Security treats credential harvesting via SSRF and metadata endpoints as a core focus (0.24 weight). The skill documents how attackers exploit Server-Side Request Forgery to access cloud metadata services\u2014such as AWS IMDS, Azure metadata endpoints, and GCP metadata servers\u2014to steal temporary credentials and service account tokens for lateral movement and privilege escalation.","q":"How does Cloud Security help with IMDS metadata SSRF credential theft?"},{"a":"Cloud Security includes assessment of Kubernetes and container security for breakout paths (0.2 weight). It covers container escape exploits, EKS node credential lateral movement, and Kubernetes RBAC privilege escalation techniques. The skill helps identify misconfigurations that allow attackers to break out of containers and move laterally within Kubernetes clusters.","q":"What container security assessment capabilities does Cloud Security provide?"},{"a":"Yes. Cloud Security covers abuse of CI/CD and Infrastructure-as-Code federation trust policies (0.18 weight), including OIDC federation trust exploitation and Terraform state secrets extraction. It documents how attackers can abuse trust relationships between CI/CD systems and cloud identity providers to gain unauthorized access and escalate privileges.","q":"Does Cloud Security address CI/CD and IaC federation trust abuse?"},{"a":"Cloud Security performs red team assessments across AWS, Azure, and GCP (0.1 weight). It includes Azure Entra device-code phishing attacks, GCP service account impersonation chains and actAs attacks, and Azure managed identity escalation. The skill provides cross-platform reconnaissance and exploitation guidance for comprehensive cloud security testing.","q":"What cloud platforms does Cloud Security red team assessment cover?"},{"a":"Cloud Security is released under the MIT license, allowing broad use, modification, and distribution for both commercial and non-commercial purposes.","q":"What license does Cloud Security use?"}],"shadow_tags":["privilege-escalation","identity-compromise","lateral-movement","cloud-infrastructure","container-security","supply-chain-attack","credential-theft","misconfiguration-hunting","persistence-mechanism","federation-abuse"],"summary_rewrite":"Cloud Security targets identity and access control weaknesses across major cloud platforms. It covers IAM privilege escalation, credential harvesting via metadata SSRF, Entra device-code attacks, GCP service-account impersonation chains, Kubernetes container breakout, and CI/CD federation trust abuse. Includes scripts and references for reconnaissance, exploitation, and lateral movement within cloud environments."},"files":[{"bytes":9221,"path":"skills/cloud-security/SKILL.md","sha256":"6a04310a29c0fe9d4d6b474546e82766f36498742383352e5442dffaab62e444","url":"https://skillfed.io/files/hypnguyen1209/offensive-claude/cloud-security/700105bf/SKILL.md"}],"id":"hypnguyen1209/offensive-claude/cloud-security","links":{"html":"https://skillfed.io/hypnguyen1209/offensive-claude/cloud-security","md":"https://skillfed.io/hypnguyen1209/offensive-claude/cloud-security.md","repo":"https://github.com/hypnguyen1209/offensive-claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":58,"language":"Python","last_updated":"2026-07-03","license":"MIT","name":"cloud-security","publisher":"hypnguyen1209","stars":326},"relations":{"similar":[{"id":"hypnguyen1209/offensive-claude/cicd-supply-chain"},{"id":"hypnguyen1209/offensive-claude/incident-response"},{"id":"hypnguyen1209/offensive-claude/threat-hunting"},{"id":"hypnguyen1209/offensive-claude/privesc-windows"},{"id":"hypnguyen1209/offensive-claude/privesc-linux"},{"id":"hypnguyen1209/offensive-claude/active-directory-attack"},{"id":"hypnguyen1209/offensive-claude/windows-boundaries"},{"id":"hypnguyen1209/offensive-claude/container-k8s-escape"},{"id":"sangrokjung/claude-forge/security-pipeline"},{"id":"Aradotso/mcp-skills/security-detections-mcp"}]},"slug":{"owner":"hypnguyen1209","repo":"offensive-claude","skill":"cloud-security"},"version":"700105bf"}
