OCLP focuses on cloud attack-path identification and exploitation across identity, misconfiguration, and service abuse scenarios. For 2026, prioritize IAM abuse paths, hybrid identity risk, and evidence-rich reporting.
Official PageAzure AD enumeration and token research toolkit.
pipx install roadreconroadrecon gatherAWS exploitation framework for IAM/data-plane testing.
pipx install pacupacuMulti-cloud security posture baseline and misconfiguration review.
pipx install scoutsuitescout awsTenant/resource enumeration and token-context validation.
curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bashaz account showStructured notes for report-grade evidence capture.
Use for methodology + proof trackingContainer/image/config scanning for cloud attack surface.
sudo apt install -y trivytrivy image <image>Kubernetes exposure checks in cloud estates.
pipx install kube-hunterkube-hunter --remote <ip>