Learning path

Attacking and Defending AWS

Emulate attackers’ tools and techniques to compromise AWS services and understand defensive mitigations to prevent these attacks.

Modules

5

Hands-on labs

17

Difficulty level

intermediate

Enroll in path

Learn how attackers compromise AWS environments.

  • Compromise EC2 instances
  • Reduce the privileges of policies
  • Abuse Lambda Authorizers
  • Enumerate IAM users

Introduction

Amazon Web Services is the most popular cloud service provider in the world offering hundreds of services. With a large number of businesses adopting cloud technologies like AWS, cyber practitioners must understand the security implications of moving to the cloud.

This pathway will give you hands on access with common misconfigurations across AWS environments and understand defensive mitigations to prevent these attacks including

  • identifying, enumerating and exploiting overly permissive IAM users, roles and policies
  • exploring serverless infrastructure and common attack vectors present within these services
  • exploiting weaknesses in the most common AWS services including S3, EC2, VPC and more
Section 1
Introduction to AWS
Section 2
Introduction to IAM
Section 3
Attacking and Defending Core Services
Section 4
Attacking and Defending Serverless
Section 5
IAM Privilege Escalation
Certificate of Completion

Complete this learning path to develop your skills and earn a certificate of completion