YoVDO

Fighting the Previous War - Attacking and Defending in the Era of the Cloud

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Amazon Web Services (AWS) Courses Cloud Security Courses DDoS Attacks Courses Privilege Escalation Courses Lateral Movement Courses Footprinting Courses

Course Description

Overview

Explore a comprehensive conference talk that updates attack and defense playbooks for the cloud era. Delve into the interdependence of cloud systems and learn about pivoting through and defending these setups. Examine topics such as DDoS, footprinting, exploitation, persistence, and lateral movement in AWS environments. Discover techniques for searching S3 buckets, utilizing API keys, and manipulating Cloud Formation templates. Investigate privilege escalation methods, Lambda persistence, and federation in cloud setups. Gain insights on both offensive and defensive strategies for modern cloud-based infrastructures, equipping red and blue teamers with updated knowledge for the current threat landscape.

Syllabus

Intro
Why we are here
DDoS
Footprinting
Uber SendGrid
Canary Tokens
Would you know
Exploitation
Compromise
Persistence
AWS
Functions in AWS
AWS Permissions
Search Space
Search the Internet
S3 buckets
Open S3 buckets
SQS
Queue URLs
AWS Forums
API Keys
Identity Documents
AMIs
AMIs in private lists
Side effects of API calls
We call 888
Lateral Movement
Cloud Formation
Modifying Cloud Formation Templates
Cloud Formation Templates in Language
Simple System Management
Privilege Escalation
Lambda Persistence
Lambda Persistence Example
Subverting Lambdas
Credentials
Lockout
Federation
Reusing Roles
Organizations
Login Disruption


Taught by

Black Hat

Related Courses

CNIT 127: Exploit Development
CNIT - City College of San Francisco via Independent
Enterprise Security Fundamentals
Microsoft via edX
Penetration Testing - Post Exploitation
New York University (NYU) via edX
Ultimate Ethical Hacking and Penetration Testing (UEH)
Udemy
Hands-on Penetration Testing Labs 4.0
Udemy