Cloud IAM privilege escalation
SkillCloud & infraEscalate privileges in cloud IAM (AWS/GCP/Azure) from a low-priv set of credentials. Load when you hold cloud creds/keys/a role and want higher privilege or new resources. Signals: leaked AWS keys, an assumed role, a service-account token, "escalate in AWS/GCP/Azure", enumerated permissions.
Use Cloud IAM privilege escalation in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Cloud IAM privilege escalation and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Cloud IAM privilege escalation skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/cloud/cloud-iam-privesc/SKILL.md and read by Ahel’s review.
When it applies
You have some cloud identity (leaked keys, an SSRF-obtained role — cloud-imds-ssrf, a
compromised service account) and want to escalate to admin or reach more resources.
Why it works
IAM is complex and permissions are over-granted. A handful of seemingly-minor permissions form known escalation paths — creating a policy version, attaching a policy, passing a role, updating a function's code/role — that promote a low-priv identity to admin.
Method
- Identify & enumerate:
aws sts get-caller-identity; enumerate your effective permissions (enumerate-iam,pacu, or read attached policies). GCP:gcloud ... get-iam-policy; Azure:az role assignment list. - Find an escalation primitive (AWS examples):
iam:CreatePolicyVersion/SetDefaultPolicyVersion→ grant yourself*.iam:AttachUserPolicy/PutUserPolicy→ attach AdministratorAccess.iam:PassRole+lambda:CreateFunction/ec2:RunInstances/glue/cloudformation→ run code as a privileged role.iam:CreateAccessKeyon another user;sts:AssumeRoleon an over-trusting role. GCP:iam.serviceAccounts.actAs,setIamPolicy, editor→owner viadeploymentmanager.
- Execute the path (in scope), then confirm elevated access with a read-only admin call.
- Automate discovery with
pacu(AWS) escalation modules / ScoutSuite for the landscape.
Gotchas
- Enumerate permissions first — escalation depends entirely on which ones you hold.
- Prove escalation with a minimal, reversible action; don't create lasting admin backdoors on a live account (RoE).
- Temp creds expire — capture
get-caller-identitybefore and after as proof.
Verify success
You gain permissions/resources beyond your starting identity (e.g. an admin-only call now succeeds, or you assume a higher-priv role), demonstrated with before/after identity.
References
Rhino Security "AWS IAM privilege escalation" methods; Pacu; GCP/Azure privesc guides; ScoutSuite.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
cloud-iam-privesc- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · nvidia
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infraaws-architecture-diagram
Skill · awslabs
The pick for AWSaws-health-events
Skill · aws
The pick for AWSazure-quotas
Skill · microsoft
The pick for Azureazure-cosmos-db
Skill · microsoftdocs
The pick for Azure