Cloud Console Session Reader — canary simulation
canary_cloud_consoleDetect hijacked agents by simulating a cloud credential access attempt, raising an alert with a trace token for attack context.
Instructions
Synthetic canary decoy for security testing only. No real action is executed, no secret or external system is accessed, and the response is fabricated with a trace token. Represents an attempted cloud-session or credential read. It never contacts AWS, GCP, Azure, metadata services, or an identity provider.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| provider | Yes | aws | gcp | azure |