Hi Rhino team — I’m a solo builder. I built ACH‑LYS, a read‑only autonomous AWS pentest engine. I ran it against CloudGoat scenarios using only a visitor‑badge audit role (no customer keys, no writes).
Result: CloudGoat’s trust policies correctly locked the engine out → Immunity Certificate issued.
When I ran it against a deliberately misconfigured account, it pivoted through 7 roles and stole Stripe keys in 90 seconds.
I’d be grateful for a brutally honest review of the approach and the two reports. I’m not selling anything — just want to know if this is actually useful from a red‑team perspective.
Happy to share the PDF reports here or by email. Thanks for your time.
Hi Rhino team — I’m a solo builder. I built ACH‑LYS, a read‑only autonomous AWS pentest engine. I ran it against CloudGoat scenarios using only a visitor‑badge audit role (no customer keys, no writes).
Result: CloudGoat’s trust policies correctly locked the engine out → Immunity Certificate issued.
When I ran it against a deliberately misconfigured account, it pivoted through 7 roles and stole Stripe keys in 90 seconds.
I’d be grateful for a brutally honest review of the approach and the two reports. I’m not selling anything — just want to know if this is actually useful from a red‑team perspective.
Happy to share the PDF reports here or by email. Thanks for your time.