Cloud IAM privilege escalation
SkillCloud & infraEscalate privileges in cloud IAM (AWS/GCP/Azure) from a low-priv set of credentials. Load when you hold cloud creds/keys/a role and want higher privilege or new resources. Signals: leaked AWS keys, an assumed role, a service-account token, "escalate in AWS/GCP/Azure", enumerated permissions.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Cloud IAM privilege escalation skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/cloud/cloud-iam-privesc/SKILL.md and read by ahel’s review.
When it applies
You have some cloud identity (leaked keys, an SSRF-obtained role — cloud-imds-ssrf, a
compromised service account) and want to escalate to admin or reach more resources.
Why it works
IAM is complex and permissions are over-granted. A handful of seemingly-minor permissions form known escalation paths — creating a policy version, attaching a policy, passing a role, updating a function's code/role — that promote a low-priv identity to admin.
Method
- Identify & enumerate:
aws sts get-caller-identity; enumerate your effective permissions (enumerate-iam,pacu, or read attached policies). GCP:gcloud ... get-iam-policy; Azure:az role assignment list. - Find an escalation primitive (AWS examples):
iam:CreatePolicyVersion/SetDefaultPolicyVersion→ grant yourself*.iam:AttachUserPolicy/PutUserPolicy→ attach AdministratorAccess.iam:PassRole+lambda:CreateFunction/ec2:RunInstances/glue/cloudformation→ run code as a privileged role.iam:CreateAccessKeyon another user;sts:AssumeRoleon an over-trusting role. GCP:iam.serviceAccounts.actAs,setIamPolicy, editor→owner viadeploymentmanager.
- Execute the path (in scope), then confirm elevated access with a read-only admin call.
- Automate discovery with
pacu(AWS) escalation modules / ScoutSuite for the landscape.
Gotchas
- Enumerate permissions first — escalation depends entirely on which ones you hold.
- Prove escalation with a minimal, reversible action; don't create lasting admin backdoors on a live account (RoE).
- Temp creds expire — capture
get-caller-identitybefore and after as proof.
Verify success
You gain permissions/resources beyond your starting identity (e.g. an admin-only call now succeeds, or you assume a higher-priv role), demonstrated with before/after identity.
References
Rhino Security "AWS IAM privilege escalation" methods; Pacu; GCP/Azure privesc guides; ScoutSuite.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
cloud-iam-privesc- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · microsoft
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infraowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)aws-architecture-diagram
Skill · awslabs
The pick for AWSaws-health-events
Skill · aws
The pick for AWS