Skip to main content

2 posts tagged with "Network"

Scanning, enumeration, pivoting and traffic analysis.

View All Tags

AWS penetration testing: what you may test, and what gets you banned

· 8 min read
Haythem Rehouma
Formateur en cybersécurité offensive

Short answer: AWS permits customer security testing of eight service categories — including EC2, RDS, Lambda, API Gateway and CloudFront — without prior approval, on resources you own. Denial of service, and anything touching another tenant or AWS's own infrastructure, remains forbidden and requires a separate process. Your customer's permission is still mandatory: AWS's policy is not authorisation to test somebody else's account.