Skip to content
Antisyphon Training

Antisyphon Training

  • Home
  • News & Updates
  • Calendar
  • Training
    • Course Catalog
    • Live Training
      • Live Courses Catalog
      • Live Training Calendar
    • On-Demand Training
      • On-Demand Catalog
      • Security for MSPs
    • Pay What You Can Training
    • Cybersecurity Training for Businesses
    • The Vault Program
    • Training Roadmap
  • Summits
    • Upcoming Summits
    • Past Summits
  • Cyber Range
    • About Our Cyber Range
    • ACE-T™ Certification
    • Purchase Subscription
  • About
    • Mission
    • FAQ
    • Our Instructors
    • Giving Back
    • Testimonials
  • Contact Us
  • Toggle search form
Loading Events

« All Events

Event Series Event Series: Snake Oil? Summit 2023

Breaching the Cloud

December 8 @ 10:00 am – 6:00 pm EST

Instructor: Beau Bullock
Course Length: 16 Hours

Includes: Twelve months of complimentary access to the Antisyphon Cyber Range, certificate of participation, six months access to class recordings.

Pricing:

$575 per person
Tags
Beau Bullock, Breaching the Cloud, Red Team, Snake Oil? Summit 2023, Summit Training
Event Categories:
Live, Virtual

Location:

Online

  • Google Calendar
  • iCalendar
  • Outlook 365
  • Outlook Live

This class is part of the Antisyphon Snake Oil? Summit 2023. Registration for any Snake Oil? Summit class includes registration for the summit and all of its presentations, talks, and streams.

Register Here!

Clicking on the button above will take you
to our registration form on Cvent.


Course Description

Do you want to level up your cloud penetration testing skills? The attack surface of many organizations has changed to include third-party hosted services such as Amazon Web Services, Microsoft Azure, and Google Cloud Platform. In this training course, hacking concepts will be introduced for each of those services.

This training walks through a complete penetration testing methodology of cloud-based infrastructure. Starting with no information other than the company name you will learn to discover what cloud-specific assets your target is using. Following the enumeration of cloud services, you will learn how to discover misconfigurations that commonly expose sensitive data as well as a thorough understanding of how to get an initial foothold into a cloud-based organization.

Post-compromise techniques of cloud infrastructure differ from the techniques used in typical on-premise environments. You will learn situational awareness techniques that ultimately will impact how you will escalate privileges in the cloud. With most cloud-based authentication being publicly exposed this presents new and interesting persistence techniques that are non-existent to on-premise environments. With productivity tools like G-Suite and Microsoft 365 many organizations are making their email and other data that is normally protected by a firewall available to remote employees. You will learn how to discover, pillage, and exfiltrate data from these services.

Many organizations are fully leveraging cloud services for their production infrastructure. This can include web servers, SQL databases, storage, virtual machines, and more. In this training, you will learn how to assess and compromise these resources. Some cloud deployments are directly connected to on-premise environments via VPN. This presents an opportunity to pivot access from cloud to on-prem or vice-versa.

Finally, in this training, we will not only be attacking cloud infrastructure but also leveraging it for red team operations. You will learn techniques that leverage cloud services for techniques such as phishing, domain fronting, and command & control.

Tools and techniques used on real-world penetration tests against cloud assets will be shared including hands-on demonstrations. At the end of this training, you will have new skills for assessing cloud-based infrastructure!

Key Takeaways

  • A thorough understanding of the attack surface cloud-based organizations face
  • A full methodology for compromising cloud environments
  • Instruction on how to utilize open-source tools during cloud assessments

Who Should Take This Course

  • Penetration testers
  • Red teamers
  • Cloud security architects
  • Ethical hackers
  • General security practitioners

Audience Skill Level

Everyone. This course somewhat doubles as a general pentesting “crash course” as there are many commonalities between cloud-based pentesting and traditional on-prem pentesting.

Student Requirements

  • A credit card (You will be signing up for cloud service accounts such as Microsoft Azure and AWS. These services require a credit card for signing up.)
  • Check that both Amazon AWS and Microsoft Azure services are available in your country. (Note that if you cannot sign up for these services you will not be able to participate in the labs)
  • Internet access

System Requirements

  • Stable Internet access
  • x86 architecture CPU clocked at 2 GHz or higher that is capable of nested virtualization
    (Apple Silicon is currently not supported)
  • A computer with at least 8 GB of RAM. 16 GB is recommended
  • VMWare Workstation or VMWare Fusion
    (VirtualBox and other VM software is not supported)
  • Windows 10/11, MacOSX+, or a currently supported Linux Distribution 
  • Full Administrator/root access to your computer or laptop

System should also have at least 40GB of available disk space to accommodate two VMs.


Trainer & Author

Beau Bullock
Beau Bullock

Beau Bullock is a Senior Security Analyst and Penetration Tester and has been with Black Hills Information Security since 2014. Beau has a multitude of security certifications (OSCP, OSWP, GXPN, GPEN, GWAPT, GCIH, GCIA, GCFA, GSEC) and maintains his extensive skills by routinely taking training, learning as much as he can from his peers, and researching topics that he lacks knowledge in. He is a constant contributor to the infosec community by authoring open-source tools, writing blogs, and frequently speaking at conferences and on webcasts.

Related Events

  • Secure Ideas - Introduction to PCI (PCI 101)

    Introduction to PCI (PCI 101)

    October 3 @ 12:00 pm – 4:00 pm EDT Event Series
  • Secure Ideas - Professionally Evil CISSP Mentorship

    Professionally Evil CISSP Mentorship Program

    October 3 @ 2:00 pm – 4:00 pm EDT Event Series
  • Professionally Evil Application Security (PEAS): Unveiling Server-Side Discovery and Exploitation

    October 4 @ 12:00 pm – 4:00 pm EDT Event Series

Event Navigation

  • « x86_32 Assembly and Shellcode-Lab for Linux
Join the Antisyphon Training Discord Server!
  • Twitter
  • LinkedIn
  • Mastodon
PROMPT#

Copyright © 2023 Antisyphon

Powered by PressBook Dark WordPress theme