AWS Penetration Testing
Course Description
AWS is the leading cloud provider. Learn to identify and exploit misconfigurations, IAM weaknesses, and service vulnerabilities.
Learning Objectives
- Enumerate AWS environments
- Exploit IAM misconfigurations
- Attack S3 buckets and data storage
- Compromise Lambda functions
- Pivot through AWS networks
- Evade CloudTrail and GuardDuty
Course Structure
Modules
Module 1: AWS Fundamentals (5h)
- AWS architecture
- IAM basics
- Service overview
- Penetration testing policy
Module 2: Reconnaissance (6h)
- AWS enumeration tools
- Public resource discovery
- S3 bucket enumeration
- Subdomain takeover
Module 3: IAM Exploitation (8h)
- Privilege escalation paths
- Policy analysis
- Role assumption
- Cross-account attacks
Module 4: S3 Attacks (6h)
- Bucket misconfigurations
- ACL exploitation
- Object enumeration
- Data exfiltration
Module 5: EC2 Exploitation (7h)
- Metadata service attacks
- IMDSv2 bypass
- User data exploitation
- SSM abuse
Module 6: Network Attacks (6h)
- VPC enumeration
- Security group bypass
- NAT gateway abuse
- VPC peering attacks
Module 7: Serverless (6h)
- Lambda exploitation
- Event injection
- Function enumeration
- Secrets extraction
Module 8: Persistence (5h)
- Backdoor IAM users
- Lambda persistence
- EC2 persistence
- Cross-account persistence
Module 9: Evasion (6h)
- CloudTrail evasion
- GuardDuty bypass
- Log manipulation
- Detection avoidance
Tools
| Tool | Purpose |
|---|---|
| Pacu | AWS exploitation |
| ScoutSuite | Cloud auditing |
| Prowler | Security assessment |
| enumerate-iam | IAM enumeration |
| CloudMapper | Visualization |
📄️ Overview
Amazon Web Services security testing: IAM, S3, Lambda, and cloud exploitation