AWS Privilege Escalation and Lateral Movements

  Рет қаралды 166

DevSecCon

DevSecCon

Күн бұрын

Elevate Your Cloud Security Game: From Initial Access to Admin Privileges in AWS
Initial Access: We specialize in exploiting vulnerabilities like SQLi, RFI, Command Injection, SSRF, and more. These techniques grant us entry, but the real challenge lies in privilege escalation and lateral movement-especially in complex, full-cloud environments where threats can multiply exponentially.
Focus of the Talk: This session dives deep into AWS cloud security, showcasing methods to leverage initial access for privilege escalation and lateral movement attacks, ultimately gaining administrative permissions in an AWS account.
Tool Spotlight - “nuvola”: Developed by Prima Assicurazioni, “nuvola” is an open-source tool designed for security analysts. It offers a high-level overview of an AWS account by gathering configurations and creating a digital twin of the cloud environment, simplifying the detection of potential security threats.
Key Takeaways:
- Effective techniques for initial access in AWS environments.
- Strategies for identifying and exploiting privilege escalation paths.
- Leveraging “nuvola” to navigate and secure AWS accounts.
Join us to transform your approach to cloud security and stay ahead of potential threats in the AWS ecosystem.

Пікірлер
Demystifying DevSecOps
1:17:43
DevSecCon
Рет қаралды 129
PEDRO PEDRO INSIDEOUT
00:10
MOOMOO STUDIO [무무 스튜디오]
Рет қаралды 26 МЛН
Underwater Challenge 😱
00:37
Topper Guild
Рет қаралды 47 МЛН
Dad Makes Daughter Clean Up Spilled Chips #shorts
00:16
Fabiosa Stories
Рет қаралды 7 МЛН
OWASP ML Security Top 10
57:09
DevSecCon
Рет қаралды 238
AWS PenTesting - EC2 Compromise Using the Mitre Attack Framework
43:23
NickGilbertCISSP
Рет қаралды 1,3 М.
What does a Cloud Security Engineer do? - Salaries, Skills & Job Outlook
23:18
Securing AWS Discover Cloud Vulnerabilities via Pentesting Techniques | Beau Bullock
57:41
Black Hills Information Security
Рет қаралды 10 М.
The Secret to Vulnerability Management
58:18
SANS Institute
Рет қаралды 21 М.
PEDRO PEDRO INSIDEOUT
00:10
MOOMOO STUDIO [무무 스튜디오]
Рет қаралды 26 МЛН