Breaking the Oracle: Building an Offensive Security Toolkit for OCI
Oracle Cloud Infrastructure (OCI) delivers a cloud platform comparable to AWS and Google Cloud, yet its IAM and security model seems to lack the same level of tool verbosity. While learning OCI from a penetration-testing perspective, I encountered architectural and tooling gaps that hindered effective assessment. This talk presents a suite of open-source tools built to close those gaps, including an ANTLR-based OCI IAM policy parser, a Burp Suite extension for signing OCI API requests, an OCI reconnaissance framework with different execution modules, and an OpenGraph graph model that visualizes privilege escalation paths. Attendees will leave with a practical understanding of some OCI IAM attack-path analysis and how to use these tools.
Scott has given talks regarding public tooling he has published for AWS (Pacu modules)/GCP (GCPwn) at past fwd:cloudsec and Defcon Cloud Village conferences. From Southern California, he is currently based out of Minneapolis. In his spare time enjoys looking into various cloud-centric research focus as well as being stuck as the dungeon master in DND.