云凭据窃探
原名:Account Manipulation
通过跨 AWS、Azure 和 GCP 的分析,检测受损的云凭据。
- 分类
- 开发提效
- 版本
- v1.1
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-07
- TRACE 评分
- 0 / 5
内容概览
- When investigating alerts about unusual cloud API activity from unfamiliar locations - When building detection rules for credential theft and abuse across cloud environments - When responding to notifications from cloud providers about exposed credentials - When monitoring for credential stuffing or brute force attacks against cloud identities - When assessing the scope of a credential compromise after initial detection Do not use for preventing credential compromise (use MFA, credential rotation, and secrets management), for detecting application-level credential theft (use application security monitoring), or for endpoint credential harvesting detection (use EDR tools). - AWS GuardDuty enabled across all accounts and regions - Azure Defender for Identity and Entra ID Protection configured - GCP Security Command Center with Event Threat Detection enabled - CloudTrail, Azure Activity L…