LIVE
2.28M influencer listings 🏢34.2K sponsor listings 🌍55.07B combined audience reach 📊13 platforms indexed 🗺️130+ countries covered 🏷️10,000+ niches 🦋751K Bluesky creators 🟣709.7K Twitch creators 🎙️419K podcast creators 🐘144K Mastodon creators ▶️73.5K YouTube creators 🥊69.6K Kick creators ✈️47.8K Telegram creators 𝕏36.7K X creators 🎵17.7K TikTok creators 🎮5.4K Discord creators 🎬3.4K Rumble creators 🧵1.2K Threads creators 2.28M influencer listings 🏢34.2K sponsor listings 🌍55.07B combined audience reach 📊13 platforms indexed 🗺️130+ countries covered 🏷️10,000+ niches 🦋751K Bluesky creators 🟣709.7K Twitch creators 🎙️419K podcast creators 🐘144K Mastodon creators ▶️73.5K YouTube creators 🥊69.6K Kick creators ✈️47.8K Telegram creators 𝕏36.7K X creators 🎵17.7K TikTok creators 🎮5.4K Discord creators 🎬3.4K Rumble creators 🧵1.2K Threads creators
ℹ️ This listing was auto-generated from Mastodon's public data. Hacking the Cloud hasn't claimed it, and it doesn't imply any partnership with or endorsement of SocialDB. Is this you? Claim it · Request removal (free).
Hacking the Cloud

Hacking the Cloud

🔄 Data last refreshed 3 days ago
🤝

Make a deal with Hacking the Cloud

🔒 Paid proposals held safely in escrow — released only when the work's approved.

Every booking is a normal escrow-protected deal.

Followers
649
Account age
3 yrs
🧰 Free analysis for Hacking the Cloud
🕵️ Fake follower check 📊 Engagement rate 💰 What they charge

📊 Post engagement

1
Avg engagement / post
0.2%
Engagement vs followers
Nov 2022
On Mastodon since

🔥 Top post: In AWS Organizations, the management account is often the real p · 1 likes + reposts

📊 Activity & format

Posting cadence
1.8 / week
A lower-frequency account — each post lands with more weight.
Content mix
Mostly text
Recent: 12 text · 0 image · 0 video.
Follower / following
649×
Follows 1 back. A strong ratio — an audience that follows them, not a follow-for-follow network.
🔥 Top post In AWS Organizations, the management account is often the real prize. Member accounts created through Organizations usually get `OrganizationAccountAccessRole` with `AdministratorAccess`, trusted back to the management account. This writeup covers that default path, plus the mor… ★ 1
Public AWS exposure is not just open S3. This playbook collects CLI-first attack paths for misconfigured resources: public buckets, AMIs, EBS snapshots, RDS snapshots, assumable roles, SSM documents, and CloudFront distributions backed by … A Cloud Workstations terminal can become much more than a dev shell if Docker-in-Docker exposes the host runtime. This post walks through escaping via /var/run/docker.sock, chrooting into the underlying GCE VM, pulling the VM service accou… IAM Roles Anywhere is designed for external workloads, but the trust model can be abused for persistence. This post walks through registering a malicious CA as a trust anchor, associating it with a role profile, and using aws_signing_helpe… Azure Storage soft delete can turn a cleanup mistake into exposed data. This Hacking the Cloud post walks through a practical path: find a connection string in app code, open the storage account, switch the blob view to include soft-delete… S3 streaming copy is a neat data movement trick: read from a victim bucket to stdout, pipe directly into an attacker bucket, and avoid writing the object locally. The post also explains why the victim sees the GetObject side, while the Put… GCP privilege escalation is easier to reason about when you can start from the exact permission. This reference maps permissions such as cloudbuild.builds.create, iam.serviceAccountKeys.create, iam.serviceAccounts.signJwt, and run.services… Found AWS IAM keys and need to identify the principal? sts:GetCallerIdentity is the obvious move, but this writeup shows alternatives: denied calls like sqs:ListQueues, pinpoint-sms-voice:SendVoiceMessage, and timestream-query:DescribeEndp… GCP service account names are useful breadcrumbs. This short reference walks through user-created service account formats, App Engine and Compute Engine defaults, common private-key filenames like service_account.json, and the GOOGLE_APPLI… Datadog Security Labs gets into a design detail worth watching in Entra Agent ID: the blueprint owns the credential path for every associated agent identity. That means a compromised blueprint can become a way into agent identities, agent … Verbose AWS `AccessDenied` errors can leak whether a resource policy is public. The trick: assume a role with a deny-all session policy, call the target resource, and read which policy layer AWS says blocked you. If the session policy is t… A public S3 bucket name can be enough to recover the owning AWS account ID. The trick is `s3:ResourceAccount`: because the condition supports wildcards, you can test prefixes and walk the account ID forward digit by digit. Useful on its ow…

🐘 Community & instance

Home server
infosec.exchange
A cybersecurity & infosec server — its members and audience skew toward that niche, so expect a community-aligned, engaged following.
✅ Link-verified
Verified link
Proved ownership of a website linked on their profile — Mastodon's green-check verification, a real identity signal rather than a paid badge.
On Mastodon since
Nov 2022
Joined in the Twitter-exodus wave of late 2022 — part of the migration that made Mastodon a real destination.

💡 Facts

🗓️Joined Mastodon in 2022 — 3 years ago.
👁️Averages 1 views per post.
📤Posts about 1.8× per week.

🕵️ Fake follower check

Estimated
52/100
Fair Credibility score
76%
Mixed Real audience
Medium Fake-follower risk
High Data confidence
  • Est. 76% real, active audience · Medium fake-follower risk.
  • Low engagement (~0.2% of followers engage each post) — a sign of an inflated or inactive audience.
  • Verified account.
  • Established account (3+ years old).

Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.

About

Hacking the Cloud: An open source encyclopedia of offensive security techniques that can be used in cloud environments. Created and maintained by @frichetten

✉ Message Hacking the Cloud

Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.

See Pro $9.95/mo →

Already Pro? Log in.

🎤 Event / appearance with Hacking the Cloud

Booking an event / appearance is a Pro feature. Upgrade to book Hacking the Cloud for an in-person or virtual appearance — payment held safely in escrow until the event is done.

See Pro $9.95/mo →

Already Pro? Log in.