No video

AWS Privilege Escalation and Lateral Movements

  Рет қаралды 150

DevSecCon

DevSecCon

2 ай бұрын

Elevate Your Cloud Security Game: From Initial Access to Admin Privileges in AWS
Initial Access: We specialize in exploiting vulnerabilities like SQLi, RFI, Command Injection, SSRF, and more. These techniques grant us entry, but the real challenge lies in privilege escalation and lateral movement-especially in complex, full-cloud environments where threats can multiply exponentially.
Focus of the Talk: This session dives deep into AWS cloud security, showcasing methods to leverage initial access for privilege escalation and lateral movement attacks, ultimately gaining administrative permissions in an AWS account.
Tool Spotlight - “nuvola”: Developed by Prima Assicurazioni, “nuvola” is an open-source tool designed for security analysts. It offers a high-level overview of an AWS account by gathering configurations and creating a digital twin of the cloud environment, simplifying the detection of potential security threats.
Key Takeaways:
- Effective techniques for initial access in AWS environments.
- Strategies for identifying and exploiting privilege escalation paths.
- Leveraging “nuvola” to navigate and secure AWS accounts.
Join us to transform your approach to cloud security and stay ahead of potential threats in the AWS ecosystem.

Пікірлер
Demystifying DevSecOps
1:17:43
DevSecCon
Рет қаралды 124
CyberSecurity vs Cloud Security - Which One Should You Choose?
12:14
Tech With Soleyman
Рет қаралды 28 М.
What is a Security Engineer?
13:16
Nicolas Moy
Рет қаралды 9 М.
Securing AWS Discover Cloud Vulnerabilities via Pentesting Techniques | Beau Bullock
57:41
Black Hills Information Security
Рет қаралды 9 М.
Cover your apps: 3 pillars of AppSec
15:17
DevSecCon
Рет қаралды 43
SQL Injection Attack Tutorial - I didn't know you can do that
12:59
Loi Liang Yang
Рет қаралды 32 М.
Cloud Security Tutorial For Beginners | What is Cloud Security?
16:05
Tech With Soleyman
Рет қаралды 12 М.
What does a Cloud Security Engineer do? - Salaries, Skills & Job Outlook
23:18
Zero Trust Principles in DevSecOps
44:16
DevSecCon
Рет қаралды 177
OWASP ML Security Top 10
57:09
DevSecCon
Рет қаралды 214