AWS
Last updated
Last updated
Amazon provides a specific set of criteria for authorized testing without specific permission.
Amazon has provided guidance on their website: − https://aws.amazon.com/security/penetration-testing/
Permitted services include:
• Elastic Compute Cloud (EC2), NAT Gateways, and Load Balancers
• Relational Database Service (RDS)
• CloudFront (CDN)
• Aurora (Relational Database)
• API Gateways
• AWS Lambda and Lambda Edge
• LightSail (EC2 Lightweight service)
• Elastic Beanstalk Service (PaaS)
hide01.ir
Azure references CARTP heavily
AWS references SEC 588 heavily
GCP Does not yet exist
Is general external cloud enumeration and tools
Is for Docker, Kubernetes, etc., as they are encountered in the cloud
Learning Environments:
• Purple Cloud: https://github.com/iknowjason/PurpleCloud
• CloudGoat: https://github.com/RhinoSecurityLabs/cloudgoat
• Bad Pods: https://bishopfox.com/blog/kubernetes-pod-privilege-escalation
• TerraGoat: https://github.com/bridgecrewio/terragoat
• CI/CD Goat: https://github.com/cider-security-research/cicd-goat
• kCTF: https://google.github.io/kctf/