Threat reportThreat IntelligenceTL-2026-3064

CloudPEASS: Open-Source Cloud Privilege Escalation Enumeration Suite (AzurePEAS, GCPPEAS, AWSPEAS, K8sPEAS)

lowMONITORING

CloudPEASS: Open-Source Cloud Privilege Escalation (TL-2026-3064), also tracked as Cloud Privilege Escalation Awesome Script Suite, is a low-severity tracked intrusion set, first published 2026-10-09. It has no confirmed attribution, affects Microsoft Azure / Entra ID / Microsoft 365, maps to 10 MITRE ATT&CK techniques (T1069.003, T1078.004, T1087.004), and is covered by 9 detection rules and 9 indicators of compromise.

Severity
LOWAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
9Indicators of compromise

Key facts for TL-2026-3064

Threat ID
TL-2026-3064
Also known as
Cloud Privilege Escalation Awesome Script Suite, CloudPEASS
Severity
LOW
Status
MONITORING
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, cloud services, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
9

Malware and tooling in CloudPEASS: Open-Source Cloud Privilege Escalation

Malware and tooling: Python, CloudPEASS

How CloudPEASS: Open-Source Cloud Privilege Escalation works

CloudPEASS (Cloud Privilege Escalation Awesome Script Suite) is a public, dual-use red-team toolkit that enumerates the permissions held by a compromised cloud principal in Azure, GCP, AWS and Kubernetes and flags privilege escalation paths and sensitive-data access. It is documented as read-only, but its API activity is still recorded in cloud audit logs and can be detected.

CloudPEASS is an open-source suite hosted at github.com/peass-ng/CloudPEASS (repository description: red team scripts to find the permissions assigned to a compromised principal in AWS, GCP, Azure and Kubernetes). It is part of the PEASS-ng family and, per secondary sources, was created by Carlos Polop, who also maintains HackTricks Cloud. The suite has four Python modules: AzurePEAS.py (Azure Resource Manager and Entra ID), GCPPEAS.py (Google Cloud), AWSPEAS.py (AWS) and K8sPEAS.py (Kubernetes). Permission severity (Critical/High/Medium/Low) is derived from HackTricks Cloud categorizations, which the README says are synchronized weekly. This is a tooling and detection-coverage item, not a vulnerability: there is no CVE, exploitation, actor attribution or release date in the sources.

AzurePEAS authenticates through Azure CLI reuse (--use-az-cli), ARM/Graph tokens (arguments or AZURE_ARM_TOKEN / AZURE_GRAPH_TOKEN), device code with MFA, username/password or service-principal credentials, or a FOCI refresh token (--foci-refresh-token). It reads token claims (scp, roles, wids), queries effective ARM permissions across subscriptions and resource groups, reconstructs IAM assignments including PIM-eligible roles, reports read-only resource discovery, and can fall back to read-only Azure CLI commands. With a FOCI refresh token it also performs read-only checks of SharePoint, OneDrive, Outlook, Teams, OneNote, contacts and tasks to indicate which data is accessible; it is not intended to download the tenant.

GCPPEAS accepts a token (--token or CLOUDSDK_AUTH_ACCESS_TOKEN), a service-account key file (--sa-credentials-path or GOOGLE_APPLICATION_CREDENTIALS) or Application Default Credentials / workload metadata. It uses local clues and metadata-server data, Resource Manager and Cloud Asset Inventory discovery, batched queryTestablePermissions and testIamPermissions checks, and getIamPolicy reads. Its transport rejects non-read-only endpoints.

AWSPEAS uses a named profile, explicit access keys or the standard boto3 credential chain. It reads inline, attached and group IAM policies, runs read-only SimulatePrincipalPolicy, and performs live read-only probes (List, Get, Describe, BatchGet, Head, Lookup, Search). Managed-policy inference is labeled as inferred. It decodes the account ID locally from modern AKIA/ASIA key IDs and checks ARNs for canary patterns so it can stop before the first STS call; with --no-ask, suspected canary credentials stop the run.

K8sPEAS authenticates through kubeconfig, bearer token (K8S_TOKEN), client certificate and key, or in-Pod service-account credentials. It uses only GET requests and non-persisted self-review APIs: SelfSubjectReview, SelfSubjectRulesReview and SelfSubjectAccessReview. It also reads RBAC roles, bindings and Pod Security Admission labels, with an optional exhaustive resource/verb/subresource/namespace matrix. It does not exec, attach, port-forward or mint tokens.

Defensive relevance: the README states that read-only does not mean invisible, and read calls can appear in CloudTrail and other audit logs. Defenders should expect a burst of IAM, permission-test and discovery calls from a single principal (high-volume AccessDenied/403 responses, SimulatePrincipalPolicy, testIamPermissions, SelfSubjectRulesReview) following credential theft. Because the tool needs a valid credential, the primary controls are credential protection, least privilege, canary credentials and audit-log alerting.

MITRE ATT&CK techniques used in TL-2026-3064

Discovery

T1069.003 Cloud Groups; T1087.004 Cloud Account; T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery; T1613 Container and Resource Discovery; T1619 Cloud Storage Object Discovery

Initial Access

T1078.004 Cloud Accounts

Credential Access

T1528 Steal Application Access Token; T1552.005 Cloud Instance Metadata API

lateral-movement

T1550.001 Application Access Token

Affected products and versions in CloudPEASS: Open-Source Cloud Privilege Escalation

  • Microsoft — Azure / Entra ID / Microsoft 365
  • Google — Google Cloud Platform
  • Amazon — Amazon Web Services
  • Kubernetes — Kubernetes (RBAC)

Remediation for CloudPEASS: Open-Source Cloud Privilege Escalation

Immediate actions

  • Alert on bursts of IAM/permission-discovery API calls from a single principal (CloudTrail SimulatePrincipalPolicy and IAM List/Get calls, GCP testIamPermissions/queryTestablePermissions, Kubernetes SelfSubjectRulesReview/SelfSubjectAccessReview)
  • Deploy AWS canary credentials and alert on any use; AWSPEAS is documented to check for canary patterns but other tooling will not
  • Review Entra ID sign-ins for device code flow and FOCI refresh-token use from unexpected clients

Workarounds

  • Limit use of long-lived access keys, service-account key files and static tokens; prefer short-lived federated credentials
  • Block or conditionally restrict device code flow where not required

Longer-term hardening

  • Enforce least privilege and remove standing high-risk permissions; use PIM just-in-time access in Azure
  • Restrict who can call IAM simulation and policy-read APIs, and keep SCPs, permission boundaries and RBAC tight
  • Retain and centralize cloud audit logs (CloudTrail, Azure Activity/Entra logs, GCP Cloud Audit Logs, Kubernetes audit logs) for threat hunting
  • Run the tool defensively against your own principals to find over-permissioned identities

Timeline of CloudPEASS: Open-Source Cloud Privilege Escalation

  • Earliest commit visible in the repository history (window begins here): 'Expand tested Azure permission attack coverage'.
  • Commit 'Classify newer GCP service attack paths in the risk rules' extends GCPPEAS risk classification.
  • Commit integrates tested Azure permission attack paths and GCP risk classifications into the tools.
  • Commits 'Consume shared HackTricks permission data and sync weekly', 'Retry and bound canonical permission source fetches' and 'Align permission severities with latest HackTricks techniques' add the weekly HackTricks Cloud sync.
  • Commits expand AWSPEAS live read-only probing: 'Probe vetted AWS read operations beyond common prefixes' and 'Discover real AWS resource IDs during read-only probes'.
  • Most recent commit observed references K8sPEAS functionality.
  • Threat opened as a low-severity tooling and detection-coverage item under MONITORING; no CVE, KEV listing, exploitation or actor attribution in sources.
  • README documents AWSPEAS canary-account detection: it decodes the account ID from AKIA/ASIA key IDs and stops before the first STS call when canary patterns match.
  • README states that read-only scans can still appear in CloudTrail and other audit logs, making the tool detectable through audit-log analytics.
  • GitHub repository peass-ng/CloudPEASS observed at about 696 stars, 85 forks and 415 commits on the main branch; no tagged release versions visible.
  • CloudPEASS README retrieved and analyzed; it documents four modules (AzurePEAS, GCPPEAS, AWSPEAS, K8sPEAS) and states that operations are read-only. The source gives no release dates.

Sources cited for CloudPEASS: Open-Source Cloud Privilege Escalation

Detection coverage for TL-2026-3064

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3064 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
9 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats