Federated CI/CD (OIDC) trust abused for cross-account pivot — partial, ambiguous audit trail
A extremely-hard Cloud Infrastructure scenario on Cloud Cross-Tenant CI/CD Trust Abuse.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 3 templates in this Track + Difficulty pool.
catalog id · cloud-cross-tenant-cicd-trust-abuse
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Contain abuse of a federated CI/CD trust pivoting across cloud accounts
- Reconstruct a partial cross-account trail and harden pipeline trust
- Trusted Relationship · Initial AccessT1199 · TA0001MappedHigh confidence
Trains response to abuse of a trusted federated CI/CD relationship to reach production cloud accounts.
- Valid Accounts: Cloud Accounts · Privilege EscalationT1078.004 · TA0004MappedMedium confidence
Trains bounding the cross-account role assumptions the federated identity performed.
- User Account ContainmentD3-UACMappedHigh confidence
Trains revoking active role sessions and tokens for the abused federated identity.
- Resource Access Policy AuditingD3-RAPAMappedHigh confidence
Trains auditing and tightening the federated trust policy and the assumed-role permissions.
- Identity Management, Authentication, and Access Control · ProtectPR.AA · PRMappedHigh confidence
Trains least-privilege, narrowly-scoped trust conditions for federated automation identities.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detecting unexpected cross-account role assumption by the pipeline identity.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains containing the trust without breaking production and restricting cross-account assumption.
- IR lifecycle phasePost-Incident ActivityMappedMedium confidence
Trains hardening to unique per-job federated identities and trust-change alerting.
- Detecting Relevant Threats and TTPs3.AMappedHigh confidence
Trains the detection baseline for anomalous cross-account assumption.
- Log Collection2.TMappedMedium confidence
Trains preserving cloud, IdP token-issuance, and CI/CD run logs to reconstruct the partial trail.
- Access Control ManagementControl 6MappedHigh confidence
Trains scoping the federated trust and assumed-role permissions to least privilege.
- Application Software SecurityControl 16MappedMedium confidence
Trains hardening the CI/CD pipeline trust as part of secure software delivery.