- CSS 42.4%
- JavaScript 39.9%
- Nunjucks 17.7%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
Build and deploy / Deploy to Cloudflare Pages (push) Successful in 1m3s
|
||
| .forgejo/workflows | ||
| lib | ||
| scripts | ||
| src | ||
| .gitignore | ||
| AGENTS.md | ||
| eleventy.config.js | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| template.md | ||
| USAGE.md | ||
abusethe.cloud
A Markdown-first Eleventy wiki that explains practical cloud attack techniques, why they work, and how defenders can find and stop them.
Mental model
Each article answers five questions:
- What does the attacker do?
- What does the attacker get?
- Why does AWS let it work?
- What can defenders see?
- What stops it?
The article explains the relevant relationship and conditions, uses a diagram when it helps, and connects a compact CloudTrail event table and field projection to detection and hardening guidance. AGENTS.md defines the editorial standard; the authoring template provides prompts and components, not a mandatory outline.
Article pages show the original publication date and one summary before the body. The primitive field supports editorial scope and search rather than a second introductory panel. Prose stays within a 72ch reading measure on wide screens, with responsive tables, code, and diagrams.
When several AWS services enable the same attack and require the same defensive response, they belong in one article. Split them when the attacker action, result, or defensive response changes.
Setup
Requires Node.js 22 or newer.
npm install
Add an article
Run the authoring wizard:
npm run new
The wizard asks for the title, summary, objective, plain-language explanation, validated AWS services, publication date, stable slug, and optional legacy aliases. It writes src/techniques/<slug>.md as a draft using template.md.
Preview drafts with:
npm run dev
Canonical URLs are service-independent:
/techniques/<technique-slug>/
When the article is ready, set status: "complete", change draft to false, and run:
npm run build
Production output is written to _site/; drafts are excluded. The build generates /feed.xml. Legacy service-scoped URLs listed in aliases render static redirect pages to the canonical technique URL.
New technique or new implementation?
Create a new technique when the attacker action, result, required conditions, or defensive response materially changes.
Add a new implementation when another AWS mechanism produces the same result through the same important behavior. Only validated mechanisms belong in the article.
Browsing and search
The site groups techniques under current MITRE ATT&CK tactic names. Services are a secondary filter.
Client-side search covers article titles, summaries, objectives, primitives, and normalized service names. Objective and service filters use shareable query parameters.
Content and deployment
Publications live directly under src/techniques/. src/techniques/techniques.11tydata.js validates canonical data and assigns the layout and permalink. Do not add layout or permalink to article frontmatter.
Deploy _site/ as the web root. Update src/_data/site.json before deploying to another hostname so feed links use the correct origin. See USAGE.md for the complete workflow, redirects, and publishing checks.