Course Overview

Organizations are moving their data and their infrastructure to the cloud. With this change, new challenges are coming. Security is absolutely not handled in the same way in the cloud as it has always been on-premise. 

In this course, you will learn how to verify that necessary controls have been put in place in the AWS cloud. You will learn to assess security not only on basic AWS resources like EC2 or S3 but also on a large variety of AWS services that are often overlooked during a pentest—from serverless infrastructure to automated deployment pipelines.  

This course is the first of a series of two. You will find the continuation in the course named “Advanced AWS Pentesting.” 

By the end of this course, you will be able to identify possible vulnerable areas efficiently and secure your AWS cloud environment. 

What You Will Learn

  • Learn how to pentest AWS cloud features
  • such as S3
  • EC2
  • and IAM
  • Learn pentesting real-world AWS environments
  • Understand different techniques to test AWS cloud security and protect from the latest threats and attacks
  • Understand how to audit main AWS features including S3
  • EC2
  • and IAM
  • Learn how to pentest AWS Cloud

Program Curriculum

  • Introduction
  • $7 Million Cybersecurity Scholarship by EC-Council

  • Cloud Computing Service Models
  • AWS Pentesting Policy
  • Methodology
  • Recap
  • Chapter 2 Quiz

  • Installing Kali Linux
  • Installing a Vulnerable Windows
  • Installing a Vulnerable Linux
  • Hardening Kali Linux
  • Configure Guacamole
  • Create Snapshots
  • Recap
  • Chapter 3 Quiz

  • Introduction
  • AWS EC2 Instances Reconnaissance
  • AWS EC2 Service Reconnaissance
  • AWS EC2 Exploitation
  • AWS EC2 Privilege Escalation
  • AWS EC2 Post Exploitation
  • AWS EC2 Pivoting
  • AWS EC2 Persistence
  • Data Exfiltration
  • Chapter 4 Quiz

  • Introduction
  • S3 Permissions
  • Exploiting Upload Policy and Code Injection
  • Exploiting Pre-signed URLs
  • Exploiting unclaimed S3 Buckets
  • Chapter 5 Quiz
Load more modules

Instructor

David Rolin

David Rolin is an experienced IT security professional. He has been working for major international companies helping them securely move their IT infrastructure to the cloud. He earned numerous IT security certifications including EC-Council CEH, CHFI, ECSA, CISSP, GIAC Certified Penetration Tester, AWS Certified Solutions Architect - Professional (SAP), as well as some vendor certifications such as Cisco CCNP security or F5 professional. He has always been working in companies, keeping hands-on, real-world experience, and providing courses for training companies or universities.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Empower Your Learning with Our Flexible Plans

Invest in your future with our flexible subscription plans. Whether you're just starting out or looking to enhance your expertise, there's a plan tailored to meet your needs. Gain access to in-demand skills and courses for your continuous learning needs.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 600+ courses and diverse Learning Paths to enhance your skills.

$ 499.00
Billed annually or $59.00 billed monthly

What is included

  • 700+ Premium Short Courses
  • 50+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs, CTF Challenges, and exclusive EC-Council certifications for comprehensive skill-building.

$ 599.00
Billed annually or $69.00 billed monthly

Everything in Pro and

  • 800+ Practice Lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Practice Labs and Challenges added every month
  • 3 Official EC-Council Essentials Certifications¹ (retails at $897!)
    Exclusive Bonus with Annual Plans

¹This plan includes Digital Forensics Essentials (DFE), Ethical Hacking Essentials (EHE), and Network Defense Essentials (NDE) certifications. No other EC-Council certifications are included.

Related Courses

1 of 8