<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>abusethe.cloud</title>
    <link>https://abusethe.cloud</link>
    <description>A practical reference for reproducing, detecting, and defending against cloud abuse techniques.</description>
    <language>en</language>
    <atom:link href="https://abusethe.cloud/feed.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Add cross-account access with a bucket policy</title>
      <link>https://abusethe.cloud/techniques/s3-cross-account-bucket-policy/</link>
      <guid isPermaLink="true">https://abusethe.cloud/techniques/s3-cross-account-bucket-policy/</guid>
      <description>Grant a controlled external AWS principal direct object access without creating an identity in the bucket&amp;apos;s account.</description>
      <pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate>
      <category>S3</category>
      <category>Exfiltration</category>
    </item>
    
    <item>
      <title>Pivot through OrganizationAccountAccessRole</title>
      <link>https://abusethe.cloud/techniques/organization-account-access-role/</link>
      <guid isPermaLink="true">https://abusethe.cloud/techniques/organization-account-access-role/</guid>
      <description>Use the management account&amp;apos;s default member-account role to reach administrative permissions in an approved test account.</description>
      <pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate>
      <category>Organizations</category>
      <category>Privilege escalation</category>
    </item>
    
  </channel>
</rss>
