CARTP emphasizes practical Azure/Azure AD offensive security with identity-centric attack chains. For 2026, prioritize Entra ID attack primitives, token abuse, and tenant-level impact articulation.
Official PageAzure AD enumeration and token research toolkit.
pipx install roadreconroadrecon gatherAWS exploitation framework for IAM/data-plane testing.
pipx install pacupacuMulti-cloud security posture baseline and misconfiguration review.
pipx install scoutsuitescout awsTenant/resource enumeration and token-context validation.
curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bashaz account showUnderstand credential material handling and AD abuse paths in controlled labs.
Use in sanctioned lab scope onlyContainer/image/config scanning for cloud attack surface.
sudo apt install -y trivytrivy image <image>Kubernetes exposure checks in cloud estates.
pipx install kube-hunterkube-hunter --remote <ip>