Skip to content
Back to skills

Cloud Iam Privesc

ASecurity

Escalate privileges in cloud IAM (AWS/GCP/Azure) from a low-priv set of credentials. Load when you hold cloud creds/keys/a role and want higher privilege or new resources. Signals: leaked AWS keys, an assumed role, a service-account token, "escalate in AWS/GCP/Azure", enumerated permissions.

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
ai-agentsrustgoawsgcpazuresecurity

Works with

  • cli

Security analysis

A100/100

Scanned September 22, 2026

npx -y skills add NoorQureshi/SploitAgent --skill cloud-iam-privesc --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cloud Iam Privesc?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cloud Iam Privesc
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-cloud-iam-privesc/badge)](https://www.skillsdirectory.com/skills/noorqureshi-cloud-iam-privesc)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cloud-iam-privesc
description: >
  Escalate privileges in cloud IAM (AWS/GCP/Azure) from a low-priv set of credentials. Load when
  you hold cloud creds/keys/a role and want higher privilege or new resources. Signals: leaked
  AWS keys, an assumed role, a service-account token, "escalate in AWS/GCP/Azure", enumerated permissions.
domain: cloud
type: technique
stability: learning
modes: [pentest, bugbounty]
severity: critical
owasp: [A01:2021-Broken-Access-Control]
cwe: [CWE-269]
mitre: [T1078.004, T1548]
tools: [awscli, pacu, scoutsuite, enumerate-iam]
schema_version: 1
---

# Cloud IAM privilege escalation

## When it applies
You have some cloud identity (leaked keys, an SSRF-obtained role — `cloud-imds-ssrf`, a
compromised service account) and want to escalate to admin or reach more resources.

## Why it works
IAM is complex and permissions are over-granted. A handful of seemingly-minor permissions form
known escalation paths — creating a policy version, attaching a policy, passing a role, updating a
function's code/role — that promote a low-priv identity to admin.

## Method
1. **Identify & enumerate**: `aws sts get-caller-identity`; enumerate your effective permissions
   (`enumerate-iam`, `pacu`, or read attached policies). GCP: `gcloud ... get-iam-policy`; Azure: `az role assignment list`.
2. **Find an escalation primitive** (AWS examples):
   - `iam:CreatePolicyVersion` / `SetDefaultPolicyVersion` → grant yourself `*`.
   - `iam:AttachUserPolicy` / `PutUserPolicy` → attach AdministratorAccess.
   - `iam:PassRole` + `lambda:CreateFunction`/`ec2:RunInstances`/`glue`/`cloudformation` → run code as a privileged role.
   - `iam:CreateAccessKey` on another user; `sts:AssumeRole` on an over-trusting role.
   GCP: `iam.serviceAccounts.actAs`, `setIamPolicy`, editor→owner via `deploymentmanager`.
3. **Execute the path** (in scope), then confirm elevated access with a read-only admin call.
4. **Automate discovery** with `pacu` (AWS) escalation modules / ScoutSuite for the landscape.

## Gotchas
- Enumerate permissions first — escalation depends entirely on which ones you hold.
- Prove escalation with a minimal, reversible action; don't create lasting admin backdoors on a live account (RoE).
- Temp creds expire — capture `get-caller-identity` before and after as proof.

## Verify success
You gain permissions/resources beyond your starting identity (e.g. an admin-only call now
succeeds, or you assume a higher-priv role), demonstrated with before/after identity.

## References
Rhino Security "AWS IAM privilege escalation" methods; Pacu; GCP/Azure privesc guides; ScoutSuite.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…