Cloud Iam Deep (Grade A) logo

Cloud Iam Deep (Grade A)Ασφαλής δοκιμή ασφάλειας για την εκμάθηση των ικανοτήτων του Claude AI. Κορυφαίος βαθμός (Grade A). Ασφαλειες Cloud IAM της αλυσίδας επίθεσης red-team σε AWS, Azure, GCP — οπτικεσ στο εξωτερικά διαδρομές εκτροπής και μετα-ανακάλυψη προνόμου σε προσωπικές κλειδωθέντα.

(0)
Daniel NikulshynΑξιολογήθηκε από Daniel Nikulshyn·Ενημερώθηκε Ιούλιος 2026

Επισκόπηση

Το Cloud IAM Deep είναι ένα ταλέντο για το Claude AI που επικεντρώνεται σε εξωτερικές διαδρομές εκμετάλλευσης και ανάλυση προνόμιων μετά την ανακάλυψη πιστοποιητικών σε AWS, Azure και GCP. Καλύπτει διατύπωση IAM, κέντρωση STS/AssumeRole, καταπάτηση Azure Managed Identity, κακοποίηση JSON GCP service account, επιθέσεις IMDSv1/v2, ανάλυση προνόμιων tokenu του service του K8s ServiceAccount, ρόλων-πρωθυπουργών με συγχέεται-δεύτερο, κωδικό-επεξεργασία-ασυμβατό cross-account προκαταρκτικών-περιθώριου Assume-Role, προτυποποίηση προνομιούχων IAM, επιπλέον προνόμια AWS Cognito Identity Pool attack-κορμού-αδέσμευν-παιχνιδίου. Το ταλέντο αυτό χρησιμοποιείται όταν ένα πιστοποιητικόnu.cloud surfaces, όπως μια κλειδί, μυστική, τύχου-νταμαρής, ή αρχείο JSON, και βοηθίζει να προσδιοριστεί ποια ομιλίας-έχει και πώς να αποκτήσετε προνόμια.

Βασικές λειτουργίες

  • Συναρίθμηση IAM για AWS, Azure και GCP
  • STS/AssumeRole κατάληξη και καχυποψία Azure Manage Identity
  • Εξαγωγή JSON των εξυπηρετητών GCP και επιθέσεις IMDSv1/v2
  • Αναάλυση προνομίων ServiceAccount και role-trust-policy K8s και εσφαλμένη deputy
  • Κουφαλές ανταλλαγή εγγραφών IAM και ενισχύοντας προνόμια πρόσβασης
  • Αποστολή AWS Cognito Identity Pool από προηγούμενο-ρολάκι attack chain
  • Παρ'ότι το προηγούμενο-ρολλάκι

Τιμές

Μοντέλο
Free
Κατηγορία
Δεξιότητες
Βαθμολογία
Καμία κριτική ακόμα

Περιπτώσεις χρήσης

Φύση Κυρίων Χωρίς Νεφέλες

Χρησιμοποιήστε όταν ανακύπτει κredential σε 클ούν, όπως ένα κλειδί, μυστικό, token ή αρχείο JSON, και χρειάζεστε να καθορίσετε τι παρέχει και πως θα επικαιροποιήσετε προνόμια.

Μετατοπισμός Μετά από RCE

Χρησιμοποιήστε μετά από επιτυχημένη αποτύπωση εκτέλεσης κώδικα εξόريου (RCE) σε μια κλουν-χاست instance για απόκτηση ελέγχου στο πλάνη της κλού.

Υπέρ και κατά

Υπέρ

  • Συμπεριλαμβαντική κάλυψη της εκτελεστικής διερεύνησης και επιβράβευσης των προνομίων ανά πλοίο κλάσεων AWS, Azure και GCP
  • Περιγραφή στο εξωτερική διαδρομές εκτροπής και μετα-ανακάλυψη προνομίων
  • Συμπεριλαμβάνει εργαλεία και τεχνικές για την ταυτοποίηση και καχυποψία των εγγράφων κληρονομιάς
  • Παρ'ότι το προηγούμενο-ρολλάκι

Κατά

  • Μια όρια στην εξωτερική διαδρομές εκτροπής και ίσως δεν καλύπτει εσωτερικές απειλές
  • Απαιτεί προηγούμενη γνώση ασφάλειας πλοιώματος κλάσεων και IAM
  • Μπορεί να μην είναι ευνοϊκό για περιβάλλοντα προβλήματα ή μη σχεδιασμένες ασφάλειας για την εκπόνηση των διαδικασιών

Κριτικές

Σύνδεση για κριτική.

Καμία κριτική. Γίνε ο πρώτος!

Ερωτήσεις

Why this exists?

Most bug‑hunting Claude setups are either too generic (one big "security" prompt) or too fragmented (you bookmark 30 disclosed reports and re‑read them every engagement). Neither scales past the second target. This bundle was built and validated through authorized engagements that exposed different capability gaps: Bug‑bounty engagement — surfaced four gaps a starter 3‑skill stack could not close: 1. No hypothesis discipline — drafts written before validation → wasted hours, hurt validity ratio 2. No per‑program reporting tactics — VRT defaults auto‑downgraded P3‑worthy findings to P4 3. No engagement coordination — findings, evidence, and submission IDs scattered across folders 4. No evidence hygiene — screenshots leaked cookies and victim PII External red‑team engagement — exposed five additional gaps that bug‑bounty defaults made worse: 1. Conservative defaults retracted real findings — WAPT mindset stopped tests early on defended targets where red‑team continuation would have surfaced bypass chains → redteam‑mindset 2. No mid‑engagement situational awareness — client SOC patched confirmed SQLi within 30 min; external attacker locked 14 accounts during a live test session — both invisible without explicit detection methodology → mid‑engagement‑ir‑detection 3. No enterprise‑platform attack chains — M365 + Entra ID, on‑prem SharePoint, Cisco SSL VPN, vCenter, and 7 Android APKs all needed current 2024‑2026 CVE knowledge and platform‑specific tradecraft → m365‑entra‑attack, .

Asked by Zelda Brandt · Sep 4, 2025

Why your model switched mid‑session?

Separate from refusals, and easy to miss. On Opus 5, a narrow set of higher‑risk cyber requests — Anthropic names exploit generation, binary‑based vulnerability scanning and penetration testing — fall back to Opus 4.8 rather than being refused. You get a notice and the response is labelled with the model that answered, but in a long agentic run that is easy to scroll past, so it can look like Opus 5 quietly got worse. See why Claude switched models. What to do depends on what you are actually doing: | Situation | What helps | |---|---| | Auditing your own code — reviewing a repo you own for defects | Say so. "Defensive review of my own repo", "check this against the OWASP Top 10", "secure refactor to remediate" describe the work accurately and read as remediation. | | Authorized offensive work — live engagement, PoC for a bounty submission | This is what the bundle is for, and the supported route is CVP. Do not reword an offensive engagement to look defensive to get past a classifier — enroll instead. | | You just want the switching off | Settings → Capabilities disables automatic model switching. | /hunt states the engagement frame (authorized, scope‑bounded, remediable finding) on its first turn for exactly this reason — engagement context belongs in the session explicitly, not implied.

Asked by Anders Lindgren · Aug 28, 2025

How it works?

A 6‑phase, non‑linear workflow — recon → map & rank → hunt → validate → report — with scope enforced in code and a 7‑Question Gate before anything is submitted. Two ways to drive it: Plain English — describe what you're testing and the relevant skill loads automatically. /hunt scaffold + cbh CLI — engagement‑folder structure, state, and orchestration. Includes a usage guide, worked example, 6‑phase architecture diagram, and the cbh CLI.

Asked by Frank Müller · Aug 16, 2025

What's inside?

82 skills, auto‑loaded by topic — no invocation by name. Coverage across the external attack surface: | Category | # | Examples | |---|---|---| | Web application hunting | 13 | XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open‑redirect | | Authentication & identity | 7 | auth‑bypass, session, OAuth, SAML, MFA‑bypass, ATO | | API & infrastructure | 15 | GraphQL, gRPC, WebSocket, API‑misconfig, host‑header, RCE | | Advanced & concurrency | 6 | race‑condition, HTTP smuggling, deserialization, cache‑poison | | Framework‑specific | 4 | Next.js, Node.js, Laravel, Spring Boot | | Enterprise identity & cloud ★ | 3 | M365/Entra, Okta, cloud‑IAM‑deep | | Infrastructure & appliance ★ | 4 | VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM | | Red‑team tradecraft ★ | 4 | redteam‑mindset, APK pipeline, supply‑chain recon, mid‑engagement IR | | Recon & OSINT | 4 | web2‑recon, offensive‑osint, subdomain | | Workflow, reporting & specialized | 11 | methodology, triage‑validation, evidence‑hygiene, VRT‑aware reporting | Full searchable catalog → docs/skills.md. Also ships 15 slash commands (/hunt, /recon, /report, …) and a deterministic engagement engine (engine/) that maps a target's attack surface and routes each finding to the skill that handles it.

Asked by Carmela Esposito · Aug 12, 2025

What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads. No invocation by name.

Asked by George Papadakis · Aug 10, 2025

Κάνε μια ερώτηση

Εναλλακτικές για Δεξιότητες

Manage Headers (Grade A) logo
Manage Headers (Grade A)Δεξιότητες

Δεδομένης ασφάλειας ανάπτυξης για τον Claude AI. Βαθμός Α. Ελέγχει και ρυθμίζει τις κεφαλίδες ασφαλείας που στέλνει ένας ιστότοπος Power Pages στους browsers — Content Security Policy, προστασία frame και clickjacking.

(0)
Free
Using Git Worktrees (Grade A) logo
Using Git Worktrees (Grade A)Δεξιότητες

Δεδομένα AI με δοκιμή ασφαλείας για το Claude AI. Grade A. Χρησιμοποιήστε όταν ξεκινάτε εργασίες χαρακτηριστικών που χρειάζονται απομόνωση από το τρέχον workspace ή πριν εκτελέσετε σχέδια υλοποίησης – δημιουργεί απομονωμένο git worktree

(0)
Free
Ga4 Bigquery Schema (Grade A) logo
Ga4 Bigquery Schema (Grade A)Δεξιότητες

Δεξιότητα data‑ai ελεγμένη ασφάλεια για Claude AI. Βαθμός A. Αναφορά Σχήματος Εξαγωγής GA4 στο BigQuery — πλήρης αναφορά πεδίων, ένθετες δομές, μοτίβα ερωτημάτων και συμβουλές απόδοσης

(0)
Free
Meta Capi (Grade A) logo
Meta Capi (Grade A)Δεξιότητες

Ασφαλής data‑ai λειτουργία για το Claude AI. Βαθμός Α. Αναφορά εγκατάστασης Meta Conversions API (CAPI) – αρχιτεκτονική, τύποι γεγονότων, κρυπτογράφηση πληροφοριών πελατών, αποφυγή διπλοτύπων, παραδείγματα υλοποίησης, AEM

(0)
Free
Callees (Grade A) logo
Callees (Grade A)Δεξιότητες

Ασφαλειά-ελεγμένου développement skill για τον Claude AI. Α' κατηγορίας. Λίστα όσα μια funkcio/metodo καλεί (call graph direct)

(0)
Free
Test Module Name (Grade A) logo
Test Module Name (Grade A)Δεξιότητες

Προστασία-ελεγχόμενη δεξιότητα data-ai για το Claude AI. Βαθμός A. Ονομάστε τα μοντέλα δοκιμών Haskell με βάση το μοντέλο υπό δοκιμή, προσθέτοντας το κατάληξη Spec στο ίδιο namespace. Χρησιμοποιήστε όταν γράφετε ή αναθεωρείτε ένα μοντέλο δοκιμών Haskell.

(0)
Free
Board Of Directors (Grade A) logo
Board Of Directors (Grade A)Δεξιότητες

Σημαντικά ελεγχμένο δεδομένο-αι skill για Claude AI. Α级. Δοκιμάστε μια 5-μελή.expert τούρνα για σημαντικές αποφάσεις.

(0)
Free
Advpl Mvc Avancado (Grade A) logo
Advpl Mvc Avancado (Grade A)Δεξιότητες

Δυναμική εξέλιξη επανδρωμένης δεξιοτήτας για τον Claude AI. Grade A. Ανιχνευμένη ασφάλεια ανάπτυξης via PE (Πόντοι Ένταξης) — προσθήκη ατομικών τμημάτων στην οθόνη MVC προεπιλογής (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)

(0)
Free