mirror of
https://github.com/HackTricks-wiki/hacktricks-cloud.git
synced 2026-03-12 21:22:57 -07:00
4a16d25bfe51a53a06db0bf77699346eb0ef1efd
Add a new guide documenting privilege escalation paths for GCP Cloud Workstations. Covers Docker-in-Docker container breakout via /var/run/docker.sock, step-by-step escape to the host VM, stealing the VM service account token from IMDS, persistence by backdooring the host home, network pivot techniques, and recommended countermeasures. Includes reference to an automation script and training banners.
HackTricks Cloud
{{#include ./banners/hacktricks-training.md}}

Hacktricks logos & motion designed by @ppieranacho.
Run HackTricks Cloud Locally
# Download latest version of hacktricks cloud
git clone https://github.com/HackTricks-wiki/hacktricks-cloud
# Select the language you want to use
export LANG="master" # Leave master for English
# "af" for Afrikaans
# "de" for German
# "el" for Greek
# "es" for Spanish
# "fr" for French
# "hi" for Hindi
# "it" for Italian
# "ja" for Japanese
# "ko" for Korean
# "pl" for Polish
# "pt" for Portuguese
# "sr" for Serbian
# "sw" for Swahili
# "tr" for Turkish
# "uk" for Ukrainian
# "zh" for Chinese
# Run the docker container indicating the path to the hacktricks-cloud folder
docker run -d --rm --platform linux/amd64 -p 3377:3000 --name hacktricks_cloud -v $(pwd)/hacktricks-cloud:/app ghcr.io/hacktricks-wiki/hacktricks-cloud/translator-image bash -c "mkdir -p ~/.ssh && ssh-keyscan -H github.com >> ~/.ssh/known_hosts && cd /app && git checkout $LANG && git pull && MDBOOK_PREPROCESSOR__HACKTRICKS__ENV=dev mdbook serve --hostname 0.0.0.0"
Your local copy of HackTricks Cloud will be available at http://localhost:3377 after a minute.
Pentesting CI/CD Methodology
In the HackTricks CI/CD Methodology you will find how to pentest infrastructure related to CI/CD activities. Read the following page for an introduction:
pentesting-ci-cd-methodology.md
Pentesting Cloud Methodology
In the HackTricks Cloud Methodology you will find how to pentest cloud environments. Read the following page for an introduction:
pentesting-cloud-methodology.md
License & Disclaimer
Check them in:
Github Stats
{{#include ./banners/hacktricks-training.md}}
Description
Languages
CSS
30.8%
JavaScript
28.3%
Python
24%
Handlebars
13.9%
Shell
1.5%
Other
1.5%