Back

Cloud Pentesting Engineer

This course is designed to provide a beginner-friendly yet comprehensive guide to cloud penetration testing, with a strong emphasis on hands-on learning and real-world attack scenarios. By the end of the course, participants will have gained the skills and confidence to conduct basic cloud penetration tests in AWS, Azure, and GCP environments.

Tarek

Lead Trainer

Course PriceFree
Description

Course Curriculum

Introduction Cloud Environments

4 lessons

Overview of Cloud Computing Models: IaaS, PaaS, SaaS

Intro to Azure

Intro to AWS

Intro to GCP

Interacting With The Cloud

3 lessons

Interacting using PowerShell

Interacting using command line clients

Interacting using portals/consoles

Cloud Recon

3 lessons

Determining what cloud is in use

Recon of cloud services

Identifying cloud services in use

Initial Access

6 lessons

Username recon

Password spraying attacks

Different types of phishing attacks

Different types of phishing attacks

Adversary in the middle attack

Bypassing initial defenses like MFA

Exploiting Public Storage

4 lessons

Finding public storage in Azure, AWS and GCP

Accessing public Azure blobs

Accessing public AWS buckets

Accessing public GCP buckets

Exploiting Public VMs

3 lessons

Exploiting Azure VMs

Exploiting AWS EC2 instances

Exploiting GCP VMs

Understanding Access Control

3 lessons

Understanding and exploiting RBAC in Azure

Understanding and exploiting RBAC in AWS

Understanding and exploiting RBAC in GCP

Cloud Post-Exploitation

4 lessons

Recon as an insider

Identifying further services privilege escalation

Identifying further services for persistence

Looting secrets