From unauth web RCE to IAM crown jewel.
Chained cloud exploitation with marker round-trip proofs, container cleanup, and evidence a CNAPP alone cannot produce.
Proof doctrine
- Jenkins script-console RCE — CSRF-crumb dance; bounded println marker round-trip, zero side effects.
- Docker Engine container escape — marker container mounting host /, uid=0 proof, container removed after.
- Anonymous kubelet audit (10250) — /pods inventory of privileged hostPath pods.
- OS privilege escalation over SSH foothold — sudo NOPASSWD, SUID-vs-GTFOBins, writable cron; root proved by bounded read.
- AWS IAM pivot — IMDSv2 harvest → Secrets Manager → sts:AssumeRole trust-chain → S3 exfiltration, strictly read-then-report.
- SSH lateral movement — russh password userauth + single-command exec sessions.
Proof point: 200-host AWS engagement, 4/4 IAM hops, zero GuardDuty attack detections. Read the engagement.