Find an SSRF vulnerability - Access the cloud provider's metadata service (169.254.169.254) - Retrieve IAM role credentials - Use the credentials to access cloud resources (S3, Lambda, EC2)