No description
  • CSS 42.4%
  • JavaScript 39.9%
  • Nunjucks 17.7%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Humpty/Tony ae38dddf6a
All checks were successful
Build and deploy / Deploy to Cloudflare Pages (push) Successful in 1m3s
Clarify attacker objectives in article openings
2026-09-04 18:41:19 -04:00
.forgejo/workflows Use available Forgejo Docker runner 2026-08-29 20:16:06 -04:00
lib Add interactive article wizard and service URLs 2026-08-30 19:45:08 -04:00
scripts Revise technique taxonomy and attack articles 2026-09-02 16:38:23 -04:00
src Clarify attacker objectives in article openings 2026-09-04 18:41:19 -04:00
.gitignore Publish Lambda credential beaconing research 2026-09-01 11:40:27 -04:00
AGENTS.md Add Session Manager SSH article and refine content and layout 2026-09-04 18:23:11 -04:00
eleventy.config.js Add Session Manager SSH article and refine content and layout 2026-09-04 18:23:11 -04:00
package-lock.json Publish Lambda credential beaconing research 2026-09-01 11:40:27 -04:00
package.json Publish Lambda credential beaconing research 2026-09-01 11:40:27 -04:00
README.md Add Session Manager SSH article and refine content and layout 2026-09-04 18:23:11 -04:00
template.md Add Session Manager SSH article and refine content and layout 2026-09-04 18:23:11 -04:00
USAGE.md Add Session Manager SSH article and refine content and layout 2026-09-04 18:23:11 -04:00

abusethe.cloud

A Markdown-first Eleventy wiki that explains practical cloud attack techniques, why they work, and how defenders can find and stop them.

Mental model

Each article answers five questions:

  1. What does the attacker do?
  2. What does the attacker get?
  3. Why does AWS let it work?
  4. What can defenders see?
  5. What stops it?

The article explains the relevant relationship and conditions, uses a diagram when it helps, and connects a compact CloudTrail event table and field projection to detection and hardening guidance. AGENTS.md defines the editorial standard; the authoring template provides prompts and components, not a mandatory outline.

Article pages show the original publication date and one summary before the body. The primitive field supports editorial scope and search rather than a second introductory panel. Prose stays within a 72ch reading measure on wide screens, with responsive tables, code, and diagrams.

When several AWS services enable the same attack and require the same defensive response, they belong in one article. Split them when the attacker action, result, or defensive response changes.

Setup

Requires Node.js 22 or newer.

npm install

Add an article

Run the authoring wizard:

npm run new

The wizard asks for the title, summary, objective, plain-language explanation, validated AWS services, publication date, stable slug, and optional legacy aliases. It writes src/techniques/<slug>.md as a draft using template.md.

Preview drafts with:

npm run dev

Canonical URLs are service-independent:

/techniques/<technique-slug>/

When the article is ready, set status: "complete", change draft to false, and run:

npm run build

Production output is written to _site/; drafts are excluded. The build generates /feed.xml. Legacy service-scoped URLs listed in aliases render static redirect pages to the canonical technique URL.

New technique or new implementation?

Create a new technique when the attacker action, result, required conditions, or defensive response materially changes.

Add a new implementation when another AWS mechanism produces the same result through the same important behavior. Only validated mechanisms belong in the article.

The site groups techniques under current MITRE ATT&CK tactic names. Services are a secondary filter.

Client-side search covers article titles, summaries, objectives, primitives, and normalized service names. Objective and service filters use shareable query parameters.

Content and deployment

Publications live directly under src/techniques/. src/techniques/techniques.11tydata.js validates canonical data and assigns the layout and permalink. Do not add layout or permalink to article frontmatter.

Deploy _site/ as the web root. Update src/_data/site.json before deploying to another hostname so feed links use the correct origin. See USAGE.md for the complete workflow, redirects, and publishing checks.