Cloud Penetration Testing
AWS, Azure, and GCP: IAM abuse, storage misconfig, and privilege escalation across every major cloud.
Course overview
A complete cloud security testing track covering AWS, Azure, and GCP: the shared responsibility model, IAM misconfiguration and privilege escalation, storage bucket exposure, metadata service (SSRF) attacks, container and Kubernetes security, and the real tooling (Prowler, ScoutSuite, Pacu) working cloud pentesters actually use. Every module pairs the platform-specific theory with a hands-on lab against a real (or realistically simulated) cloud environment.
What you'll learn
- Explain the shared responsibility model and how it defines what you can and can't test
- Enumerate and exploit AWS IAM misconfigurations for privilege escalation
- Find and exploit exposed S3 buckets and other AWS storage misconfigurations
- Attack the AWS/GCP/Azure instance metadata services via SSRF for credential theft
- Enumerate and attack Azure AD/Entra ID and GCP IAM misconfigurations
- Assess container and Kubernetes deployments for escape and RBAC abuse vulnerabilities
- Use real cloud security tooling (Prowler, ScoutSuite, Pacu) in an actual assessment workflow
- Scope, execute, and report a cloud penetration test within provider acceptable-use policies
Who this course is for
Pentesters and cloud/DevOps engineers who want a structured path into cloud security testing: one of the highest-demand specializations as organizations move critical infrastructure to AWS, Azure, and GCP. Basic Linux command-line comfort and general networking fundamentals assumed; no prior cloud platform experience required.
Curriculum
Module 1: Cloud Fundamentals for Pentesters
- Welcome: Why Cloud Pentesting Is Different
- The Shared Responsibility Model
- IAM Concepts Across AWS, Azure, and GCP
- Scoping a Cloud Engagement and Provider Rules of Engagement
- Module 1 Knowledge Check
Module 2: AWS Penetration Testing Fundamentals
- AWS IAM Enumeration and Common Misconfigurations
- AWS IAM Privilege Escalation Paths
- Exploiting Exposed S3 Buckets
- The EC2 Metadata Service and SSRF-to-Credentials
On completion of every module, enrolled students receive a verifiable certificate of completion. Full curriculum, hands-on labs, and instructor support are available at pentestnotes.tech/courses/cloud-penetration-testing.