Scan, audit, review, and remediate -- AWS cloud security exercises
Investigate public S3 buckets, misconfigured ACLs, and data leak risks via bucket enumeration.
Audit admin policies on service accounts, role chaining vectors, and privilege escalation paths in AWS IAM.
Identify security group misconfigurations, public database endpoints, and unencrypted storage across cloud databases.
Investigate environment variable secrets, event data injection, and execution role abuse in AWS Lambda functions.
Exploit SSRF to access the EC2 instance metadata service at 169.254.169.254, steal IAM role credentials via IMDSv1, and understand token-based IMDSv2 mitigations.
Detect CloudTrail trail deletion, identify log delivery gaps, investigate S3 log bucket tampering, and analyze audit trail integrity.
Investigate privileged container breakouts, host filesystem mount abuse, and lateral movement to Kubernetes node-level access.
Analyze malicious S3 and SQS event payloads that exploit deserialization and command injection vulnerabilities in Lambda trigger functions.
Investigate confused deputy attacks, role assumption chains across AWS accounts, and external ID bypass vectors in cross-account trust relationships.
Audit unencrypted EBS volumes, S3 bucket default encryption settings, and KMS key policies to identify data-at-rest protection gaps.
Analyze VPC peering risks, transit gateway misconfigurations, PrivateLink exposure, and subnet routing failures that undermine network segmentation.
Investigate CodeBuild secrets exposure, GitHub Actions OIDC trust abuse, and artifact poisoning in cloud-native CI/CD pipelines.