Cloud red team

Cloud red team

Cloud is IAM-shaped. Most “cloud bugs” are really identity, policy, trust, or supply-chain bugs that happen to live in a cloud control plane. This path puts identity first, then layers per-provider attack surface and Kubernetes on top.

Prereqs

Stage 1 — universal IAM mental model

Stage 2 — per-provider attack surface

AWS

Azure / Entra ID

GCP

Stage 3 — Kubernetes and multi-cloud pivoting

References