Catalog
cloud-securityintermediate
Cloud Penetration Testing
AWS, Azure, and GCP: IAM abuse, storage misconfig, and privilege escalation across every major cloud.
8 modules34 lessons16h
#cloud-security#aws#azure#gcp#iam#kubernetes#privilege-escalation
What you'll learn
- Explain the shared responsibility model and how it defines what you can and can't test
- Enumerate and exploit AWS IAM misconfigurations for privilege escalation
- Find and exploit exposed S3 buckets and other AWS storage misconfigurations
- Attack the AWS/GCP/Azure instance metadata services via SSRF for credential theft
- Enumerate and attack Azure AD/Entra ID and GCP IAM misconfigurations
- Assess container and Kubernetes deployments for escape and RBAC abuse vulnerabilities
- Use real cloud security tooling (Prowler, ScoutSuite, Pacu) in an actual assessment workflow
- Scope, execute, and report a cloud penetration test within provider acceptable-use policies
Who this course is for
Pentesters and cloud/DevOps engineers who want a structured path into cloud security testing: one of the highest-demand specializations as organizations move critical infrastructure to AWS, Azure, and GCP. Basic Linux command-line comfort and general networking fundamentals assumed; no prior cloud platform experience required.
A complete cloud security testing track covering AWS, Azure, and GCP: the shared responsibility model, IAM misconfiguration and privilege escalation, storage bucket exposure, metadata service (SSRF) attacks, container and Kubernetes security, and the real tooling (Prowler, ScoutSuite, Pacu) working cloud pentesters actually use. Every module pairs the platform-specific theory with a hands-on lab against a real (or realistically simulated) cloud environment.
Curriculum
Course content
01Cloud Fundamentals for Pentesters
5 lessons- Welcome: Why Cloud Pentesting Is DifferentEnroll to view
- The Shared Responsibility ModelEnroll to view
- IAM Concepts Across AWS, Azure, and GCP
Reviews
No reviews yet.