Threat reportThreat IntelligenceTL-2026-3064
CloudPEASS: Open-Source Cloud Privilege Escalation Enumeration Suite (AzurePEAS, GCPPEAS, AWSPEAS, K8sPEAS)
CloudPEASS: Open-Source Cloud Privilege Escalation (TL-2026-3064), also tracked as Cloud Privilege Escalation Awesome Script Suite, is a low-severity tracked intrusion set, first published 2026-10-09. It has no confirmed attribution, affects Microsoft Azure / Entra ID / Microsoft 365, maps to 10 MITRE ATT&CK techniques (T1069.003, T1078.004, T1087.004), and is covered by 9 detection rules and 9 indicators of compromise.
- Severity
- LOWAssessed severity
- CVEs
- 0None referenced
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 9Indicators of compromise
Key facts for TL-2026-3064
- Threat ID
- TL-2026-3064
- Also known as
- Cloud Privilege Escalation Awesome Script Suite, CloudPEASS
- Severity
- LOW
- Status
- MONITORING
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, cloud services, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 9
Malware and tooling in CloudPEASS: Open-Source Cloud Privilege Escalation
Malware and tooling: Python, CloudPEASS
How CloudPEASS: Open-Source Cloud Privilege Escalation works
CloudPEASS (Cloud Privilege Escalation Awesome Script Suite) is a public, dual-use red-team toolkit that enumerates the permissions held by a compromised cloud principal in Azure, GCP, AWS and Kubernetes and flags privilege escalation paths and sensitive-data access. It is documented as read-only, but its API activity is still recorded in cloud audit logs and can be detected.
CloudPEASS is an open-source suite hosted at github.com/peass-ng/CloudPEASS (repository description: red team scripts to find the permissions assigned to a compromised principal in AWS, GCP, Azure and Kubernetes). It is part of the PEASS-ng family and, per secondary sources, was created by Carlos Polop, who also maintains HackTricks Cloud. The suite has four Python modules: AzurePEAS.py (Azure Resource Manager and Entra ID), GCPPEAS.py (Google Cloud), AWSPEAS.py (AWS) and K8sPEAS.py (Kubernetes). Permission severity (Critical/High/Medium/Low) is derived from HackTricks Cloud categorizations, which the README says are synchronized weekly. This is a tooling and detection-coverage item, not a vulnerability: there is no CVE, exploitation, actor attribution or release date in the sources.
AzurePEAS authenticates through Azure CLI reuse (--use-az-cli), ARM/Graph tokens (arguments or AZURE_ARM_TOKEN / AZURE_GRAPH_TOKEN), device code with MFA, username/password or service-principal credentials, or a FOCI refresh token (--foci-refresh-token). It reads token claims (scp, roles, wids), queries effective ARM permissions across subscriptions and resource groups, reconstructs IAM assignments including PIM-eligible roles, reports read-only resource discovery, and can fall back to read-only Azure CLI commands. With a FOCI refresh token it also performs read-only checks of SharePoint, OneDrive, Outlook, Teams, OneNote, contacts and tasks to indicate which data is accessible; it is not intended to download the tenant.
GCPPEAS accepts a token (--token or CLOUDSDK_AUTH_ACCESS_TOKEN), a service-account key file (--sa-credentials-path or GOOGLE_APPLICATION_CREDENTIALS) or Application Default Credentials / workload metadata. It uses local clues and metadata-server data, Resource Manager and Cloud Asset Inventory discovery, batched queryTestablePermissions and testIamPermissions checks, and getIamPolicy reads. Its transport rejects non-read-only endpoints.
AWSPEAS uses a named profile, explicit access keys or the standard boto3 credential chain. It reads inline, attached and group IAM policies, runs read-only SimulatePrincipalPolicy, and performs live read-only probes (List, Get, Describe, BatchGet, Head, Lookup, Search). Managed-policy inference is labeled as inferred. It decodes the account ID locally from modern AKIA/ASIA key IDs and checks ARNs for canary patterns so it can stop before the first STS call; with --no-ask, suspected canary credentials stop the run.
K8sPEAS authenticates through kubeconfig, bearer token (K8S_TOKEN), client certificate and key, or in-Pod service-account credentials. It uses only GET requests and non-persisted self-review APIs: SelfSubjectReview, SelfSubjectRulesReview and SelfSubjectAccessReview. It also reads RBAC roles, bindings and Pod Security Admission labels, with an optional exhaustive resource/verb/subresource/namespace matrix. It does not exec, attach, port-forward or mint tokens.
Defensive relevance: the README states that read-only does not mean invisible, and read calls can appear in CloudTrail and other audit logs. Defenders should expect a burst of IAM, permission-test and discovery calls from a single principal (high-volume AccessDenied/403 responses, SimulatePrincipalPolicy, testIamPermissions, SelfSubjectRulesReview) following credential theft. Because the tool needs a valid credential, the primary controls are credential protection, least privilege, canary credentials and audit-log alerting.
MITRE ATT&CK techniques used in TL-2026-3064
Discovery
T1069.003 Cloud Groups; T1087.004 Cloud Account; T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery; T1613 Container and Resource Discovery; T1619 Cloud Storage Object Discovery
Initial Access
Credential Access
T1528 Steal Application Access Token; T1552.005 Cloud Instance Metadata API
lateral-movement
Affected products and versions in CloudPEASS: Open-Source Cloud Privilege Escalation
Remediation for CloudPEASS: Open-Source Cloud Privilege Escalation
Immediate actions
- Alert on bursts of IAM/permission-discovery API calls from a single principal (CloudTrail SimulatePrincipalPolicy and IAM List/Get calls, GCP testIamPermissions/queryTestablePermissions, Kubernetes SelfSubjectRulesReview/SelfSubjectAccessReview)
- Deploy AWS canary credentials and alert on any use; AWSPEAS is documented to check for canary patterns but other tooling will not
- Review Entra ID sign-ins for device code flow and FOCI refresh-token use from unexpected clients
Workarounds
- Limit use of long-lived access keys, service-account key files and static tokens; prefer short-lived federated credentials
- Block or conditionally restrict device code flow where not required
Longer-term hardening
- Enforce least privilege and remove standing high-risk permissions; use PIM just-in-time access in Azure
- Restrict who can call IAM simulation and policy-read APIs, and keep SCPs, permission boundaries and RBAC tight
- Retain and centralize cloud audit logs (CloudTrail, Azure Activity/Entra logs, GCP Cloud Audit Logs, Kubernetes audit logs) for threat hunting
- Run the tool defensively against your own principals to find over-permissioned identities
Timeline of CloudPEASS: Open-Source Cloud Privilege Escalation
- Earliest commit visible in the repository history (window begins here): 'Expand tested Azure permission attack coverage'.
- Commit 'Classify newer GCP service attack paths in the risk rules' extends GCPPEAS risk classification.
- Commit integrates tested Azure permission attack paths and GCP risk classifications into the tools.
- Commits 'Consume shared HackTricks permission data and sync weekly', 'Retry and bound canonical permission source fetches' and 'Align permission severities with latest HackTricks techniques' add the weekly HackTricks Cloud sync.
- Commits expand AWSPEAS live read-only probing: 'Probe vetted AWS read operations beyond common prefixes' and 'Discover real AWS resource IDs during read-only probes'.
- Most recent commit observed references K8sPEAS functionality.
- Threat opened as a low-severity tooling and detection-coverage item under MONITORING; no CVE, KEV listing, exploitation or actor attribution in sources.
- README documents AWSPEAS canary-account detection: it decodes the account ID from AKIA/ASIA key IDs and stops before the first STS call when canary patterns match.
- README states that read-only scans can still appear in CloudTrail and other audit logs, making the tool detectable through audit-log analytics.
- GitHub repository peass-ng/CloudPEASS observed at about 696 stars, 85 forks and 415 commits on the main branch; no tagged release versions visible.
- CloudPEASS README retrieved and analyzed; it documents four modules (AzurePEAS, GCPPEAS, AWSPEAS, K8sPEAS) and states that operations are read-only. The source gives no release dates.
Sources cited for CloudPEASS: Open-Source Cloud Privilege Escalation
Detection coverage for TL-2026-3064
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3064 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.