Skip to content

ACHLYS autonomous pentest engine — ran against CloudGoat, looking for technical feedback #456

Description

@achlyssecurity1

Hi Rhino team — I’m a solo builder. I built ACH‑LYS, a read‑only autonomous AWS pentest engine. I ran it against CloudGoat scenarios using only a visitor‑badge audit role (no customer keys, no writes).

Result: CloudGoat’s trust policies correctly locked the engine out → Immunity Certificate issued.
When I ran it against a deliberately misconfigured account, it pivoted through 7 roles and stole Stripe keys in 90 seconds.

I’d be grateful for a brutally honest review of the approach and the two reports. I’m not selling anything — just want to know if this is actually useful from a red‑team perspective.

Happy to share the PDF reports here or by email. Thanks for your time.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions