cloud-containers

v2026.09.24

Cloud and container security testing - AWS, Azure, GCP, Docker, and Kubernetes misconfigurations and exploitation.

GitHub
安装命令
npx skhub add transilienceai/cloud-containers
Markdown
SKILL.md

Cloud & Containers

Test cloud infrastructure and container environments for security misconfigurations and exploitation paths.

Techniques

PlatformKey Vectors
AWSS3 bucket exposure, IAM misconfig, metadata service, Lambda abuse
AzureBlob storage, RBAC flaws, managed identity, App Service misconfig
GCPCloud Storage, service account keys, metadata server, IAM
DockerContainer escape, privileged mode, socket exposure, image vulnerabilities
KubernetesRBAC bypass, secret exposure, pod escape, API server access

Workflow

  1. Enumerate cloud resources and services
  2. Test IAM/RBAC configurations
  3. Check storage and secrets exposure
  4. Test container isolation and escape paths
  5. Document findings with cloud-specific evidence

Two lanes — attack vs assess

This skill covers both, and they are different jobs producing different artifacts. Do not mix them in one deliverable.

LaneYou haveYou produceStart at
Offensivea cloud target to attackexploited findings with a PoCreference/INDEX.md
Postureread-only credentials and a "review the configuration" askone evidenced verdict per control in a pinned cataloguereference/posture/INDEX.md

Reference

  • reference/INDEX.md - Router for platform-specific attack scenarios (AWS, Azure, GCP, Docker, K8s)
  • reference/posture/INDEX.md - Credentialed read-only configuration review (CSPM): run order, verdict vocabulary, the four false-pass traps, pinned catalogues, and the licensing rule for benchmark-derived content
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

MIT

源路径

skills/cloud-containers

默认分支

main

最新提交

95fdc12

Tree SHA

854bd03