Live Demo: siteq8.github.io/CloudMCP-Arsenal
Two MCP servers — one for offense, one for defense:
┌─────────────────────────────────────────────────────┐
│ AI AGENT (Claude / GPT / Local LLM) │
│ "Assess cloud security of target.com" │
│ │
│ ┌─────────────────┐ ┌─────────────────────┐ │
│ │ 🗡️ ATTACK SERVER │ │ 🛡️ DEFENSE SERVER │ │
│ │ Port 9090 │ │ Port 9091 │ │
│ ├─────────────────┤ ├─────────────────────┤ │
│ │ cloud_s3_enum │ │ defense_rate_limit │ │
│ │ cloud_metadata │ │ defense_anomaly │ │
│ │ cloud_cert_trans │ │ defense_containment │ │
│ │ cloud_waf_detect │ │ defense_deception │ │
│ │ cloud_dns_prov │ │ defense_cis_cloud │ │
│ │ cloud_iam_miscon │ └─────────────────────┘ │
│ │ cloud_playbook │ │
│ └─────────────────┘ │
└─────────────────────────────────────────────────────┘
git clone https://github.com/SiteQ8/CloudMCP-Arsenal.git
cd CloudMCP-Arsenal
# Attack Server
python3 scripts/mcp-servers/cloud_recon_server.py --port 9090
# Defense Server (in another terminal)
python3 scripts/defenses/cloud_defense_server.py --port 9091# S3 Bucket Enumeration
curl -X POST http://localhost:9090 \
-d '{"method":"tools/call","params":{"name":"cloud_s3_enum","arguments":{"bucket_name":"company-backup"}}}'
# Certificate Transparency Search
curl -X POST http://localhost:9090 \
-d '{"method":"tools/call","params":{"name":"cloud_cert_transparency","arguments":{"domain":"target.com"}}}'
# Containment Playbook
curl -X POST http://localhost:9091 \
-d '{"method":"tools/call","params":{"name":"defense_containment","arguments":{"threat_type":"exposed_bucket","target_resource":"company-backup"}}}'| Tool | Description | MITRE |
|---|---|---|
cloud_s3_enum |
S3 bucket enumeration, public listing, sensitive file scan | T1530 |
cloud_metadata |
Cloud metadata SSRF probe (AWS/GCP/Azure/DO) | T1552.005 |
cloud_cert_transparency |
CT log search for subdomains + cloud service detection | T1596.004 |
cloud_waf_detect |
WAF/CDN fingerprinting (7 vendors) | T1595.002 |
cloud_dns_provider |
Cloud provider detection from DNS | T1590.002 |
cloud_iam_misconfig |
IAM misconfiguration checklist (12 checks) | T1078 |
cloud_attack_playbook |
6-phase cloud attack playbook generator | T1190 |
| Tool | Description | Framework |
|---|---|---|
defense_rate_limit |
AI-speed attack detection + adaptive throttling | NIST M1031 |
defense_anomaly |
Behavioral anomaly detection (risk scoring 0-100) | NIST DS0029 |
defense_containment |
Auto-containment: exposed bucket, cred theft, SSRF | NIST M1030 |
defense_deception |
Cloud honeytokens: fake keys, honey buckets, canaries | MITRE M1056 |
defense_cis_cloud |
CIS Benchmarks for AWS (8), Azure (6), GCP (6) | CIS |
- Deploy AI Red Team Agents — Run CloudMCP monthly against all accounts
- Automated Containment < 5 min — Playbooks for top 3 threat scenarios
- Rate Limit All Cloud APIs — Adaptive: 60→10→0 RPM
- Deploy Cloud Honeytokens — 5 per cloud account
- Enforce IMDSv2 Everywhere — Block SSRF credential theft
- CIS Benchmarks Continuous — Alert on drift, not annual check
Ali AlEnezi · @SiteQ8 · 3li.info
Security Architecture Principal · National Bank of Kuwait (NBK Group) 🇰🇼