hunting-iam-privilege-escalation-paths

Solid

Hunt privilege-escalation paths in cloud identity and access management: a low-privileged principal that chains role assumptions, policy rewrites, role-passing, and over-broad trust relationships to reach an administrative or data-access principal. Covers the identity-to-permission-to-resource graph, the known escalation primitives (passing a more privileged role to a service, rewriting a policy to a permissive version, assuming a role whose trust condition is too loose), and the boundary controls that should stop the chain. Use when reviewing cloud IAM, role and policy configuration, or an identity graph. A reachable path from an untrusted principal to admin is the finding.

AI & Automation 4 stars 1 forks Updated yesterday MIT

Install

View on GitHub

Quality Score: 80/100

Stars 20%
23
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Hunting IAM privilege-escalation paths: a reachable chain to admin is the bug Cloud access is a graph. Principals hold policies, policies grant permissions, and some of those permissions let a principal change the graph itself: pass a role, rewrite a policy, assume another identity. Privilege escalation is a path through that graph from where an attacker starts to a principal that can read the data or run the workloads that matter. No single permission looks alarming. The bug is the reachable chain, and you only see it when you follow the edges. ## When to use - You are reviewing cloud IAM: roles, policies, groups, and trust relationships. - A principal is meant to be low-privileged and you want to prove it cannot reach admin. - You have the policy documents and want to know what they compose into, not just what each says. ## Scope check Audit identity configuration in accounts you own or are authorized to test, with credentials provisioned for the review. If you can't name the authorization, stop. ## The loop 1. **Build the identity graph.** Inventory every principal, the policies attached to it, the permissions those policies grant, and the resources they touch. Represent it as edges: principal grants permission on resource. The whole method is reachability over this graph, so the graph is the first artifact. 2. **Enumerate the escalation primitives.** Mark every permission that lets a principal change the graph rather than just use it: passing a more ...

Details

Author
UnboundCompute
Repository
UnboundCompute/security-agent-skills
Created
5 days ago
Last Updated
yesterday
Language
N/A
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

iam-privesc

Cloud IAM privilege escalation methodology for AWS, Azure, and GCP. Covers misconfigured roles, policy enumeration, assume-role chaining, and escalation to admin/root equivalent access.

1 Updated yesterday
sunilgentyala
AI & Automation Solid

hunting-setuid-and-capability-escalation

Hunt local privilege escalation through setuid and setgid binaries and per-file capabilities: programs that run as a more privileged identity, or files granted a capability such as changing user id, overriding file permissions, raw disk or memory access, or loading kernel modules, that expose an exec, file-read, file-write, or library-load primitive an unprivileged caller can reach. Covers known dangerous tools left with the bit set, custom or bundled setuid programs that shell out or trust a writable path, and over-broad capabilities that are privilege in all but name. Use when auditing a host, image, or package for local privilege escalation. The elevated identity is the source, the primitive it exposes is the sink, and the missing confinement is the bug.

4 Updated yesterday
UnboundCompute
AI & Automation Solid

hunting-scheduled-job-and-search-path-hijacks

Hunt local privilege escalation through scheduled jobs and the paths privileged processes trust: periodic and timer jobs whose script, or a file or directory they read, is writable by a lower-privileged user; commands invoked by an unqualified name resolved through a writable search-path entry; and argument injection where a command expands a shell wildcard over a directory an attacker can write to, so a file named like an option (a leading-dash filename) becomes a command-line flag. Covers writable job scripts, writable directories on an effective path, relative command execution, and the filename-as-flag wildcard trick. Use when auditing a host or image for local escalation through automation. The writable input is the source, execution as the job's identity is the sink.

4 Updated yesterday
UnboundCompute