From unauth web RCE to IAM crown jewel.
Chained cloud exploitation with marker round-trip proofs, container cleanup, and evidence a CNAPP alone cannot produce.
Proof doctrine
- Jenkins script-console RCE — CSRF-crumb dance; bounded println marker round-trip, zero side effects.
- Docker Engine container escape — marker container mounting host /, uid=0 proof, container removed after.
- Anonymous kubelet audit (10250) — /pods inventory of privileged hostPath pods.
- OS privilege escalation over SSH foothold — sudo NOPASSWD, SUID-vs-GTFOBins, writable cron; root proved by bounded read.
- AWS IAM pivot — IMDSv2 harvest → Secrets Manager → sts:AssumeRole trust-chain → S3 exfiltration, strictly read-then-report.
- SSH lateral movement — russh password userauth + single-command exec sessions.
Proof point: 200-host AWS engagement, 4/4 IAM hops, zero GuardDuty attack detections. Read the engagement.
Related cloud and container reading
- Agentic pentesting explained — how an IMDSv2 credential becomes a full IAM pivot chain.
- The SwarmHack engine — the six-phase kill chain behind every capability here.
- SSE and ZTNA validation — prove whether the edge blocks egress from a compromised workload.
- Authorization envelope and safety gates — how destructive cloud actions stay default-deny.
- Tutorial: cloud security posture — wire cloud accounts in before the agentic passes.