Cloud benchmark

AWS and Azure cloud penetration testing benchmark

AWS and Azure cloud penetration testing benchmark, real results only: AWS S3 bucket exploitation, Azure Key Vault pentest and Entra ID ROPC MFA bypass, and GCP SSRF metadata token theft, each run autonomously and proven with a working exploit.

Darkmoon, the open source autonomous AI penetration testing tool, found 97 cloud vulnerabilities across 8 labs and proved 45 of them with a real exploit. The runs used AWS, Azure and GCP training labs; the model tokenizes real values through the Privacy Gateway so it works on placeholders.

Results

Cloud runs, finding by finding

Lab / targetFindingsSeverityExploitedModelEvidence
AWS · huge-logistics S3camp_20260802_03bfc67595C1H2M1L5claude-opus-4-6Write-up Report
AWS · pwnedlabs EBS/S3camp_20260802_611cece192H5M2L0claude-opus-4-6Write-up Report
Azure · Entra ID tenantcamp_20260802_7eee391f2811C10H4M3L12claude-opus-4-6Write-up Report
Azure · BloodHound / priv-esccamp_20260802_9d245c0c198C6H5M11claude-opus-4-6Write-up Report
Azure · Key Vault (extract)camp_20260802_38118fb8162C6H8M6claude-opus-4-6Write-up Report
Azure · Key Vault (pivot)camp_20260802_59e4e90573C2H2M4claude-opus-4-6Write-up Report
GCP · SSRF to metadatacamp_20260802_656007d343C1H3claude-opus-4-6Write-up Report
GCP · public GCS bucketcamp_20260802_3ced719653C1H1M4claude-opus-4-6Write-up Report
Attack chains

What each run proved

AWS · huge-logistics S3Anonymous S3 listing to hardcoded IAM keys to a PCI card-data dump and the CTF flag.
AWS · pwnedlabs EBS/S3A public unencrypted EBS snapshot and a public bucket mapped by a constrained IAM user, nothing exploited.
Azure · Entra ID tenantA deleted blob recovered, ROPC minted a token with no MFA, and the directory fully enumerated.
Azure · BloodHound / priv-escA helpdesk identity chained through four principals to Global Admin credentials in a storage blob.
Azure · Key Vault (extract)Three plaintext contractor passwords extracted from Key Vault through over-permissive RBAC.
Azure · Key Vault (pivot)A stolen Key Vault password reused to authenticate as a contractor and reach customer card data.
GCP · SSRF to metadataSSRF smuggled through gopher:// to steal a GCP service-account token and empty a bucket.
GCP · public GCS bucketA bucket name in an HTML comment led to a password-protected backup and 500 PII records.
FAQ

Cloud benchmark questions

What does the AWS and Azure cloud penetration testing benchmark cover?

Eight autonomous cloud runs across AWS, Azure and GCP: AWS S3 bucket exploitation to an IAM credential chain, Azure Key Vault pentest and Entra ID ROPC MFA bypass to tenant takeover paths, and GCP SSRF metadata token theft. Each run is published with the exact command per finding.

How many cloud vulnerabilities did Darkmoon find?

Darkmoon, the open source autonomous AI penetration testing tool, found 97 cloud vulnerabilities across 8 labs and proved 45 of them with a real exploit, from anonymous S3 listing to a PCI card-data dump and from a Key Vault secret to customer data.

Does the cloud benchmark keep my credentials off the model?

The open source Darkmoon CLI runs the assessment and its Privacy Gateway tokenizes real IPs, hosts and credentials so the model works on placeholders while the real values stay on your perimeter. The web dashboard and the remediation-to-PR loop are paid Pro capabilities.

Darkmoon's own benchmark on public cloud training labs. The offensive runs are produced by the open source Darkmoon CLI; the web dashboard and the remediation-to-PR loop are paid Pro. Raw reports live in the darkmoon-research corpus and the results feed the Darkmoon-Benchmarks leaderboard.

Point Darkmoon at your own cloud

Open source, self hosted and local first. Run the same AWS, Azure and GCP checks on an account you own. A star helps other teams find it.