Skip to content
← LibraryTechnique entry
CI-OIDC-WILDCARDInitial Access

CI/CD OIDC Trust Wildcard

Cloud IAM role trusts CI OIDC with wildcard 'sub' claim — any attacker repo / branch / environment can assume the role.

§ Where this technique fits

CI-OIDC-WILDCARD is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 0 approved dossiers in the registry, typically.