# CloudPEASS: Open-Source Cloud Privilege Escalation Enumeration Suite (AzurePEAS, GCPPEAS, AWSPEAS, K8sPEAS)

> CloudPEASS (Cloud Privilege Escalation Awesome Script Suite) is a public, dual-use red-team toolkit that enumerates the permissions held by a compromised cloud principal in Azure, GCP, AWS and Kubernetes and flags privilege escalation paths and sensitive-data access. It is documented as read-only, but its API activity is still recorded in cloud audit logs and can be detected.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3064
- **ID:** TL-2026-3064
- **Severity:** LOW
- **Category:** THREAT_INTEL
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 9 (full data via the Threadlinqs MCP server — Purple tier)

## Description

CloudPEASS is an open-source suite hosted at github.com/peass-ng/CloudPEASS (repository description: red team scripts to find the permissions assigned to a compromised principal in AWS, GCP, Azure and Kubernetes). It is part of the PEASS-ng family and, per secondary sources, was created by Carlos Polop, who also maintains HackTricks Cloud. The suite has four Python modules: AzurePEAS.py (Azure Resource Manager and Entra ID), GCPPEAS.py (Google Cloud), AWSPEAS.py (AWS) and K8sPEAS.py (Kubernetes). Permission severity (Critical/High/Medium/Low) is derived from HackTricks Cloud categorizations, which the README says are synchronized weekly. This is a tooling and detection-coverage item, not a vulnerability: there is no CVE, exploitation, actor attribution or release date in the sources.

AzurePEAS authenticates through Azure CLI reuse (--use-az-cli), ARM/Graph tokens (arguments or AZURE_ARM_TOKEN / AZURE_GRAPH_TOKEN), device code with MFA, username/password or service-principal credentials, or a FOCI refresh token (--foci-refresh-token). It reads token claims (scp, roles, wids), queries effective ARM permissions across subscriptions and resource groups, reconstructs IAM assignments including PIM-eligible roles, reports read-only resource discovery, and can fall back to read-only Azure CLI commands. With a FOCI refresh token it also performs read-only checks of SharePoint, OneDrive, Outlook, Teams, OneNote, contacts and tasks to indicate which data is accessible; it is not intended to download the tenant.

GCPPEAS accepts a token (--token or CLOUDSDK_AUTH_ACCESS_TOKEN), a service-account key file (--sa-credentials-path or GOOGLE_APPLICATION_CREDENTIALS) or Application Default Credentials / workload metadata. It uses local clues and metadata-server data, Resource Manager and Cloud Asset Inventory discovery, batched queryTestablePermissions and testIamPermissions checks, and getIamPolicy reads. Its transport rejects non-read-only endpoints.

AWSPEAS uses a named profile, explicit access keys or the standard boto3 credential chain. It reads inline, attached and group IAM policies, runs read-only SimulatePrincipalPolicy, and performs live read-only probes (List, Get, Describe, BatchGet, Head, Lookup, Search). Managed-policy inference is labeled as inferred. It decodes the account ID locally from modern AKIA/ASIA key IDs and checks ARNs for canary patterns so it can stop before the first STS call; with --no-ask, suspected canary credentials stop the run.

K8sPEAS authenticates through kubeconfig, bearer token (K8S_TOKEN), client certificate and key, or in-Pod service-account credentials. It uses only GET requests and non-persisted self-review APIs: SelfSubjectReview, SelfSubjectRulesReview and SelfSubjectAccessReview. It also reads RBAC roles, bindings and Pod Security Admission labels, with an optional exhaustive resource/verb/subresource/namespace matrix. It does not exec, attach, port-forward or mint tokens.

Defensive relevance: the README states that read-only does not mean invisible, and read calls can appear in CloudTrail and other audit logs. Defenders should expect a burst of IAM, permission-test and discovery calls from a single principal (high-volume AccessDenied/403 responses, SimulatePrincipalPolicy, testIamPermissions, SelfSubjectRulesReview) following credential theft. Because the tool needs a valid credential, the primary controls are credential protection, least privilege, canary credentials and audit-log alerting.

## MITRE ATT&CK

- T1078.004 Cloud Accounts
- T1528 Steal Application Access Token
- T1552.005 Cloud Instance Metadata API
- T1550.001 Application Access Token
- T1580 Cloud Infrastructure Discovery
- T1526 Cloud Service Discovery
- T1087.004 Cloud Account
- T1069.003 Cloud Groups
- T1619 Cloud Storage Object Discovery
- T1613 Container and Resource Discovery

## Sources

- [CloudPEASS README (peass-ng/CloudPEASS)](https://raw.githubusercontent.com/peass-ng/CloudPEASS/main/README.md)
- [peass-ng/CloudPEASS GitHub repository](https://github.com/peass-ng/CloudPEASS)
- [CloudPEASS permission severity policy](https://github.com/peass-ng/CloudPEASS/blob/main/docs/permission-severity-policy.md)
- [CloudPEASS K8sPEAS guide](https://github.com/peass-ng/CloudPEASS/blob/main/docs/K8sPEAS.md)
- [HackTricks Cloud (permission categorization source)](https://cloud.hacktricks.wiki/)
- [CloudPEASS project summary (SourcePulse)](https://www.sourcepulse.org/projects/2336155)
- [CloudPEASS commit history (peass-ng/CloudPEASS)](https://github.com/peass-ng/CloudPEASS/commits/main)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3064
