Sign in

Hacking the Cloud

@hackingthe.cloud
589 followers 1 following 132 posts

An open source encyclopedia of offensive security techniques that can be used in cloud environments. Created and maintained by @frichetten.com

PostsRepliesMedia
Hacking the Cloud @hackingthe.cloud · 30/07/2026
CodeBuild GitHub runners can become AWS persistence. Backdoor a role trust policy, connect a runner project to an attacker repo, and trigger workflows inside the victim account. hackingthe.cloud/aws/post_exp...
000
Hacking the Cloud @hackingthe.cloud · 28/07/2026
Retiring cloud resources in the wrong order can leave takeover paths behind. This covers DNS and CloudFront records pointing at deleted S3 buckets, plus AWS's newer error behavior. hackingthe.cloud/aws/exploita...
000
Hacking the Cloud @hackingthe.cloud · 22/07/2026
Public AWS exposure is not just S3. This playbook covers quick CLI paths for AMIs, snapshots, SSM docs, roles, and CloudFront-backed buckets. hackingthe.cloud/aws/exploita...
010
Hacking the Cloud @hackingthe.cloud · 16/07/2026
A mounted Docker socket in Cloud Workstations can turn a dev shell into a host breakout. This walks through escape, VM service account token theft, and why scopes still matter. hackingthe.cloud/gcp/exploita...
000
Hacking the Cloud @hackingthe.cloud · 14/07/2026
IAM Roles Anywhere can become AWS persistence. With enough access, an attacker can register a malicious CA as a trust anchor, bind it to a role profile, and mint credentials from outside AWS. hackingthe.cloud/aws/post_exp...
000
Hacking the Cloud @hackingthe.cloud · 08/07/2026
Deleted Azure blobs are not always gone. If soft delete is enabled and an attacker gets a storage connection string, they may be able to list, undelete, and recover files that everyone assumed were removed. hackingthe.cloud/azure/soft-d...
000
Hacking the Cloud @hackingthe.cloud · 02/07/2026
S3 exfil does not always need a local file write. This shows how to stream an object from a victim bucket to an attacker bucket so the victim sees GetObject while PutObject lands in the attacker account. hackingthe.cloud/aws/exploita...
000
Hacking the Cloud @hackingthe.cloud · 30/06/2026
GCP privilege escalation often starts with one dangerous permission. This reference maps Cloud Build, service account, Cloud Run, org policy, and HMAC key paths to public research and scripts. hackingthe.cloud/gcp/exploita...
010
Hacking the Cloud @hackingthe.cloud · 24/06/2026
Found AWS keys and need the principal name? This covers API calls that leak the caller ARN and account ID through access denied errors, giving you options beyond sts:GetCallerIdentity. hackingthe.cloud/aws/enumerat...
000
Hacking the Cloud @hackingthe.cloud · 18/06/2026
GCP service account names tell you more than they first seem to. This quick reference covers default account formats, common key filenames, and the env var pattern you will spot in reviews and recon. hackingthe.cloud/gcp/general-...
000
Hacking the Cloud @hackingthe.cloud · 17/06/2026
One Entra Agent ID blueprint can authenticate every agent identity tied to it. If that blueprint credential leaks, the blast radius can span agents, users, permissions, and even tenants. securitylabs.datadoghq.com/articles/age...
001
Hacking the Cloud @hackingthe.cloud · 16/06/2026
A deny-all session policy can turn verbose AWS `AccessDenied` errors into a public-exposure oracle. If the error says the session policy blocked the request, the resource policy may have allowed it. This post breaks down the signal and the caveats.
buff.ly
Detect Public Resource Exposure via Session Policy Error Messages - Hacking The Cloud
Use session policy denials and verbose IAM error messages to determine if AWS resources have public resource-based policies.
000
Hacking the Cloud @hackingthe.cloud · 10/06/2026
Compromise the AWS Organizations management account and the default `OrganizationAccountAccessRole` can turn member accounts into admin-level pivots. This post walks through where that role appears, how trusted access and delegated admin change the picture, and where Pacu helps. buff.ly/sWrY7ra
buff.ly
AWS Organizations Defaults & Pivoting - Hacking The Cloud
How to abuse AWS Organizations' default behavior and lateral movement capabilities.
000
Hacking the Cloud @hackingthe.cloud · 04/06/2026
A public S3 bucket name can leak more than objects. By abusing `s3:ResourceAccount` wildcard matching, you can brute-force the AWS account ID behind the bucket one digit at a time.
buff.ly
Enumerate AWS Account ID from a Public S3 Bucket - Hacking The Cloud
Knowing only the name of a public S3 bucket, you can ascertain the account ID it resides in.
000
Hacking the Cloud @hackingthe.cloud · 02/06/2026
AWS persistence can hide in a rogue OIDC provider. Backdoor a role trust policy, then later use `AssumeRoleWithWebIdentity` to get fresh role credentials.
buff.ly
IAM Rogue OIDC Identity Provider Persistence - Hacking The Cloud
Obtain persistence by creating a rogue OIDC Identity Provider.
010
Hacking the Cloud @hackingthe.cloud · 27/05/2026
Azure Run Command is a quiet path to VM execution. If an identity can call `Microsoft.Compute/virtualMachines/runCommands/action`, scripts run through the VM agent as SYSTEM on Windows or root on Linux.
buff.ly
Run Command Abuse - Hacking The Cloud
Utilise Azure RunCommands for execution and lateral movement.
001
Hacking the Cloud @hackingthe.cloud · 21/05/2026
CVE-2024-28056 is not only a cross-account story. If an AWS account still has an old vulnerable Amplify role and a same-account Cognito identity pool with classic authflow, role takeover may still be possible.
buff.ly
CVE-2024-28056: Exploit an AWS Amplify Vulnerability in Same-Account Scenarios - Hacking The Cloud
An in-depth explanation of how to still abuse CVE-2024-28056, a vulnerability in AWS Amplify that exposed IAM roles to takeover.
010
Hacking the Cloud @hackingthe.cloud · 19/05/2026
GuardDuty PenTest findings can hinge on an AWS API User-Agent. This post shows how boto3/botocore builds that string, how it can be changed, and why defenders should treat it as a weak signal.
buff.ly
Bypass GuardDuty Pentest Findings via Botocore Config - Hacking The Cloud
Override the default botocore user-agent string in boto3 to prevent GuardDuty PenTest findings from firing.
000
Hacking the Cloud @hackingthe.cloud · 13/05/2026
An EC2 foothold can get weird fast. This post shows how SSM Agent traffic can be spoofed: race the real agent for EC2 Messages, force Success, or open your own SSM Sessions control channel.
buff.ly
Intercept SSM Communications - Hacking The Cloud
With access to an EC2 instance you can intercept, modify, and spoof SSM communications.
000
Hacking the Cloud @hackingthe.cloud · 07/05/2026
Two AWS CLI habits: use `-` to stream S3 objects without temp files, and set `AWS_EXECUTION_ENV` to add context to CloudTrail user-agents. Small tricks that make AWS work less annoying.
buff.ly
AWS CLI Tips and Tricks - Hacking The Cloud
A collection of tips and tricks for using the AWS CLI.
000
Hacking the Cloud @hackingthe.cloud · 05/05/2026
Got an AWS IAM unique ID and need the ARN behind it? For AIDA and AROA identifiers, AWS can do the lookup for you: place the ID in a resource-based policy, save, refresh, and watch it resolve to the principal ARN.
buff.ly
Derive a Principal ARN from an AWS Unique Identifier - Hacking The Cloud
How to convert an unique identifier to a principal ARN.
001
Hacking the Cloud @hackingthe.cloud · 26/03/2026
What if you could maintain AWS access indefinitely without creating users or keys? Role chain juggling exploits how assume-role refreshes credential expiration. Chain calls to the same role or cycle between roles to keep access alive.
buff.ly
Role Chain Juggling - Hacking The Cloud
Keep your access by chaining assume-role calls.
000
Hacking the Cloud @hackingthe.cloud · 24/03/2026
Can attackers undo your containment actions before they take effect? IAM's eventual consistency creates a 4-second window where deleted creds stay valid. Attackers can detect and remove deny-all policies before propagation completes.
buff.ly
IAM Persistence through Eventual Consistency - Hacking The Cloud
Abuse IAM's eventual consistency to maintain persistence against incident response containment.
000
Hacking the Cloud @hackingthe.cloud · 23/03/2026
ICYMI: Our latest article covers Daniel Grzelak's research on how AWS error messages can reveal publicly exposed resources, without needing access! We cover how to use them for enumeration and detection.
buff.ly
Detect Public Resource Exposure via Session Policy Error Messages - Hacking The Cloud
Use session policy denials and verbose IAM error messages to determine if AWS resources have public resource-based policies.
060
Hacking the Cloud @hackingthe.cloud · 18/03/2026
Can attackers hide GCP projects in plain sight? Apps Script projects create hidden sys-* folders invisible in the console. Attackers can mimic this naming convention to stash service accounts or compute instances where no one looks.
buff.ly
Apps Script project impersonation / Google Apps Script persistence - Hacking The Cloud
Google Workspace Apps Script projects create hidden GCP projects (sys-<...>) that can be impersonated by attackers. This technique enables stealthy persistence (service accounts, hidden compute,…
010
Hacking the Cloud @hackingthe.cloud · 16/03/2026
AI agents are becoming identity infrastructure, whether we’re ready or not. While investigating agent controls, the Datadog Security Research Team found that Copilot Studio wasn’t recording certain administrative changes to agents, exposing a potential monitoring blind spot.
buff.ly
Uncovering agent logging gaps in Copilot Studio | Datadog Security Labs
During research, we sometimes encounter scenarios that remind us that it's a good idea to trust but verify. In September 2025, we noticed that certain Microsoft Copilot Studio agent settings did not…
021
Hacking the Cloud @hackingthe.cloud · 12/03/2026
Got shell access to an EC2 instance? You can enumerate the AWS account ID using two methods: get-caller-identity if an instance profile exists, or the metadata service at 169.254.169.254. Both reveal the account ID plus useful context like region and instance type.
buff.ly
Enumerate AWS Account ID from an EC2 Instance - Hacking The Cloud
With access to an ec2 instance, you will be able to identify the AWS account it runs in.
021
Hacking the Cloud @hackingthe.cloud · 04/03/2026
Got a list of potential corporate emails? You can verify which ones are valid Azure AD accounts without authentication using tools like CredMaster or Quiet Riot. Useful for password spraying or even pivoting to AWS root user testing.
buff.ly
Unauthenticated Enumeration of Azure Active Directory Email Addresses - Hacking The Cloud
Discover how to exploit information disclosure configurations in Azure Active Directory to enumerate valid email addresses.
000
Hacking the Cloud @hackingthe.cloud · 26/02/2026
What if an attacker could turn a simple Cognito login into full AWS account access? Misconfigured Identity Pools can grant excessive IAM permissions to anyone who authenticates, even anonymous users. Learn how this exploitation chain works.
buff.ly
Abusing Overpermissioned AWS Cognito Identity Pools - Hacking The Cloud
How to take advantage of misconfigured Amazon Cognito Identity Pools.
000
Hacking the Cloud @hackingthe.cloud · 24/02/2026
EC2 user data scripts often contain hardcoded credentials, despite AWS explicitly warning against it. If you gain access to an instance, check 169.254.169.254/latest/user-... immediately.
buff.ly
Introduction to User Data - Hacking The Cloud
An introduction to EC2 User Data and how to access it.
000
Hacking the Cloud @hackingthe.cloud · 18/02/2026
Got IAM creds but tired of wrestling with CLI flags? You can spawn an AWS Console session using aws-vault. Temporary creds work directly, long-term creds need sts:GetFederationToken first. Heads up: this is noisy in CloudTrail.
buff.ly
Create a Console Session from IAM Credentials - Hacking The Cloud
How to use IAM credentials to create an AWS Console session.
011
Hacking the Cloud @hackingthe.cloud · 16/02/2026
ICYMI: A look at how a familiar container escape pattern shows up in GCP Cloud Workstations. We trace a path from a container to service account. If you’re using Cloud Workstations, this is a useful model to keep in mind.
buff.ly
GCP Cloud Workstations Privilege Escalation - Hacking The Cloud
Break out of a Cloud Workstations container through an exposed Docker socket, then access project credentials from instance metadata.
010
Hacking the Cloud @hackingthe.cloud · 12/02/2026
Got browser cookies but no AWS credentials? CloudShell has an undocumented metadata endpoint on port 1338 that exposes IAM creds. Load the session cookies, hit the endpoint, and you've got temporary credentials for your tools.
buff.ly
Get IAM Credentials from a Console Session - Hacking The Cloud
Convert access to the AWS Console into IAM credentials.
000
Hacking the Cloud @hackingthe.cloud · 10/02/2026
Tens of thousands of EBS snapshots are publicly exposed right now. Unlike most AWS resources, you can list all public snapshots via the API and filter by account ID. Easy recon, zero detection risk.
buff.ly
Loot Public EBS Snapshots - Hacking The Cloud
How to find and take advantage of exposed EBS snapshots.
000
Hacking the Cloud @hackingthe.cloud · 04/02/2026
How do you know what permissions compromised AWS credentials actually have? Brute force them. enumerate-iam tests safe API calls to map your access. Just note: this is loud and will light up CloudTrail.
buff.ly
Brute Force IAM Permissions - Hacking The Cloud
Brute force the IAM permissions of a user or role to see what you have access to.
000
Hacking the Cloud @hackingthe.cloud · 02/02/2026
ICYMI: AI workloads are landing in the same cloud accounts we’ve been breaking into (and defending) for years. It's time for Hacking the Cloud to catch up. We're announcing a call for research! Share your AI and LLM sec research with thousands of readers.
buff.ly
Call for research: AI and LLM security - Hacking The Cloud
Hacking the Cloud is opening the door to AI and LLM security research.
010
Hacking the Cloud @hackingthe.cloud · 29/01/2026
GCP buckets and AWS S3 buckets are nearly identical under the hood. CloudStorageFinder works for both with minimal changes - just swap the endpoint URL. Here's how to hunt for GCP buckets.
buff.ly
Hunting GCP Buckets - Hacking The Cloud
How to find valid and invalid GCP Buckets using tools
021
Hacking the Cloud @hackingthe.cloud · 27/01/2026
AWS Network Firewall checks SNI and Host headers but never verifies the actual destination IP. Attackers can bypass egress filtering by spoofing legitimate domains while routing traffic to malicious IPs.
buff.ly
AWS Network Firewall Egress Filtering Bypass - Hacking The Cloud
Bypass AWS Network Firewall Egress Filtering using SNI spoofing and Host Header manipulation.
010
Hacking the Cloud @hackingthe.cloud · 26/01/2026
In case you missed it, did you know Claude models have a "magic string" to test when a model refuses to respond? If that string enters prompt context, it can be abused to break LLM workflows until context is reset. It's the EICAR test string of the AI age. Details:
buff.ly
Break LLM Workflows with Claude's Refusal Magic String - Hacking The Cloud
How Anthropic's refusal test string can be abused to stop streaming responses and create sticky failures.
100
Hacking the Cloud @hackingthe.cloud · 21/01/2026
Misconfigured GitLab OIDC with AWS IAM roles can lead to unauthorized role assumption. Learn to identify and exploit such vulnerabilities with a step-by-step guide. Stay informed to protect your cloud infrastructure from unauthorized access.
buff.ly
Exploiting Misconfigured GitLab OIDC AWS IAM Roles - Hacking The Cloud
Discover how to identify and exploit misconfigured AWS IAM roles using GitLab OIDC, with a detailed, step-by-step guide.
010
Hacking the Cloud @hackingthe.cloud · 15/01/2026
Discover how to enumerate IAM users and roles in AWS without prior access! Through clever techniques like exploiting resource-based policies, you can explore insights across AWS accounts. Harness tools like Quiet Riot for efficient execution. Dive deeper here:
buff.ly
Unauthenticated Enumeration of IAM Users and Roles - Hacking The Cloud
Discover how to exploit cross-account behaviors to enumerate IAM users and roles in another AWS account without authentication.
010
Hacking the Cloud @hackingthe.cloud · 13/01/2026
Exploring the impact of misconfigured AWS IAM role trust policies. Learn how wildcard Principals in trust policies can open up roles to any AWS account, posing serious security risks. Are your policies airtight? Dive deeper into this cloud security issue with us!
buff.ly
Abusing Misconfigured Role Trust Policies with a Wildcard Principal - Hacking The Cloud
How to take advantage of misconfigured role trust policies that have wildcard principals.
000
Hacking the Cloud @hackingthe.cloud · 07/01/2026
Discover how a default configuration in Terraform Enterprise can expose sensitive credentials via the Metadata Service. By understanding the nuances of remote execution and Docker in Terraform, you can mitigate potential security risks before they affect your cloud infrastructure.
buff.ly
Terraform Enterprise: Attack the Metadata Service - Hacking The Cloud
Leverage a default configuration in Terraform Enterprise to steal credentials from the Metadata Service
010
Reposted by Hacking the Cloud
Nick Frichette @frichetten.com · 05/01/2026
The 2025 Hacking the Cloud: Year in Review is out! We take a look at the growing tide of software supply chain attacks, discuss the most critical cloud vuln discovered to date, and share some stats for the site! hackingthe.cloud/blog/2025_wr...
hackingthe.cloud
2025 Hacking the Cloud: Year in Review - Hacking The Cloud
An end of year summary for Hacking the Cloud in 2025.
052
Hacking the Cloud @hackingthe.cloud · 01/01/2026
Discover how AWS connection tracking affects security group rules. Once connections are established, they persist even if rules change. Learn how this impacts security, illustrated with EC2 instances and penetration testing scenarios.
buff.ly
Connection Tracking - Hacking The Cloud
Abuse security group connection tracking to maintain persistence even when security group rules are changed.
000
Hacking the Cloud @hackingthe.cloud · 30/12/2025
Dive into "CI/CDon't", an AWS/GitLab-themed CTF where you can test your security chops on vulnerable infrastructure. Deploy it using Terraform and explore fun, low-difficulty CI/CD challenges. Remember, it's in your AWS account, so handle with care! Check it out:
buff.ly
CI/CDon't - Hacking The Cloud
An AWS/GitLab CICD themed CTF.
010
Hacking the Cloud @hackingthe.cloud · 24/12/2025
Learn how to bypass AWS GuardDuty's Tor Client detection on EC2 instances without triggering alerts. By leveraging Tor bridges and using obfs4proxy, you can connect discreetly to the Tor network, maintaining privacy while avoiding unauthorized access warnings. More details here:
buff.ly
Bypass GuardDuty Tor Client Findings - Hacking The Cloud
Connect to the Tor network from an EC2 instance without alerting GuardDuty.
000
Reposted by Hacking the Cloud
Nick Frichette @frichetten.com · 18/12/2025
New on @hackingthe.cloud, did you know that attackers can prevent you from kicking them out of your environment in certain situations? Eduard Agavriloae shares his research on how attackers can nullify containment attempts! hackingthe.cloud/aws/post_exp...
hackingthe.cloud
IAM Persistence through Eventual Consistency - Hacking The Cloud
Abuse IAM's eventual consistency to maintain persistence against incident response containment.
061
Hacking the Cloud @hackingthe.cloud · 18/12/2025
Lambda's environment variables hold IAM credentials that attackers can target via file read and SSRF vulnerabilities. They can also extract event data using SSRF exploits. This blog explores practical techniques for exploiting these vulnerabilities in Lambda functions.
buff.ly
Steal IAM Credentials and Event Data from Lambda - Hacking The Cloud
Leverage file read and SSRF vulnerabilities to steam IAM credentials and event data from Lambda.
000
Hacking the Cloud @hackingthe.cloud · 16/12/2025
Public AMIs can reveal AWS secrets! If you have an account ID, you can use the AWS API to find these AMIs and launch instances to look for sensitive data. Manual and automated scanning can help find credentials, but remember: curiosity must come with a conscience.
buff.ly
Discover secrets in public AMIs - Hacking The Cloud
How to find public AMIs and get stored secrets.
000