name: chain-ssrf-to-rce description: Build and validate SSRF pivot chains toward metadata/infra control and final code execution impact. metadata: subdomain: web-exploitation when_to_use: "ssrf chain rce remote code execution pivot cloud metadata imds iam role gopher dns rebinding"
Chain: SSRF to RCE
Canonical path
- SSRF reaches metadata/internal control plane.
- Extract credential/token or access internal admin API.
- Use credential to deploy or execute payload.
- Confirm code execution and business impact.
Graph guidance
- Add
enablesedges for each pivot. - Lower weights for direct pivots; higher for speculative pivots.
- Run
plan_attack_chainsand thensuggest_objectives_from_chains.