Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Python: Pen Testing AWS

Python: Pen Testing AWS

1h 52mAdvanced2021-04-28

Authors

Malcolm Shore

Malcolm Shore

Cybersecurity Expert, Former Director of GCSB

Course details

Pen testing is a standard technique for on-site systems, but the way testing is carried out in the cloud is different. This course explores the different types of vulnerabilities in the cloud, the techniques used to test cloud deployments, and key open-source tools for testing Amazon Web Service deployments: CloudGoat, the AWS CLI, and the AWS Python Software Development Kit, known as boto3. Instructor Malcolm Shore shows how to set up your test environment and then use Python to enumerate policies, programmatically create users, manage secrets, list EC2 and RDS instances, and more. He also shows how to get a quick summary of the resources in your AWS account with the PATE tool and use other Python-based testing tools such as PACU. The skills you learn in this course will help you test your AWS deployments for the weaknesses that others will exploit and design your own customs scripts for testing.

Skills covered

Cloud SecurityPythonProgramming LanguagesCloud ComputingOpen SourceSoftware DevelopmentOne-Off

Concepts

0. Introduction

  • 01 - Using Python to test for cloud deployment weaknesses through pen testing
  • 02 - What you need to know

1. Using Python to Manage AWS

  • 03 - Understanding AWS
  • 04 - Rules for pen testing AWS
  • 05 - Setting up an AWS account
  • 06 - Provisioning an AWS resource
  • 07 - Setting up the Windows Subsystem for Linux
  • 08 - AWS Command Line Interface
  • 09 - Automating cloud deployments with Terraform

2. Using CloudGoat for Testing

  • 10 - Understanding the CloudGoat testing paradigm
  • 11 - Installing CloudGoat
  • 12 - Launching CloudGoat scenarios
  • 13 - Listing the user policy
  • 14 - Gaining privileges by changing policies
  • 15 - Exploiting a misconfigured server
  • 16 - Closing down a CloudGoat scenario

3. Using the AWS Robot Framework

  • 17 - Taking a first look at the Python boto3 AWS library
  • 18 - Enumerating policies
  • 19 - Adding sessions to your Python scripts
  • 20 - Checking for guards
  • 21 - Managing IAM programmatically
  • 22 - Creating users programmatically
  • 23 - Managing secrets using Python
  • 24 - Listing all EC2 instances
  • 25 - Listing all RDS instances
  • 26 - Challenge
  • 27 - Solution

4. The Python AWS Trace Enumerator

  • 28 - The Python AWS Trace Enumerator
  • 29 - Looking inside Pate
  • 30 - Challenge
  • 31 - Solution

5. Python Testing Tools

  • 32 - Looking at a weird Python script
  • 33 - The PACU pen testing framework
  • 34 - Navigating the PACU console
  • 35 - Exploring PACU test modules
  • 36 - Account privilege escalation
  • 37 - Deploying the ec2 ssrf scenario
  • 38 - Pen testing Lambda with PACU
  • 39 - Cleaning up your cloud

Conclusion

  • 40 - What's next

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal