Cloud Security — Index
Cloud Security — Index
BLUF: Begin with provider hierarchy, identity and responsibility boundaries, then run read-only, zero-cost validation in owned disposable environments. Every exercise requires explicit IDs, seeded resources, audit telemetry, benign proof, stop conditions, and cleanup.
Mandatory gate
Complete Cloud Testing Scope and Rules of Engagement and record:
- provider, tenant/organization, subscription/account/project IDs and regions;
- authorized principals, resource tags/prefixes, exclusions and production prohibition;
- request/lockout limits, UTC window, zero-cost default and billing ceiling;
- approved mutations, seeded canaries, audit-log readiness and known gaps;
- emergency contact, stop authority, evidence rules and cleanup owner.
Use Cloud Validation Catalog as the exercise contract.
Curriculum order
| Stage | Entry | Exit result |
|---|---|---|
| Cloud foundations | Clouds | Shared responsibility, hierarchy, identity, data, network, cost, quotas, resilience, and logging are identified |
| Scope and telemetry | Scoping | Exact IDs and log sources match authorization before any test |
| Azure/Entra foundations | 1.3.1 Learn Cloud/0.1.2 Azure/ | Entra roles, Azure RBAC, management groups, subscriptions, resource groups and data-plane authorization are separated |
| AWS foundations | 1.3.1 Learn Cloud/0.1.3 AWS/ | Organizations, management account, OUs, accounts, IAM, Regions, VPC, IMDSv2, CloudTrail and data events are understood |
| Read-only validation | Cloud Validation Catalog | One seeded behavior or control per card with audit evidence |
| Gated labs | 1.3.2 Attack Cloud/ | Third-party lab/version is current, owned, bounded, sanitized, and reversible |
| Detection and reporting | Provider identity, control-plane and data-plane logs | Finding includes coverage gaps, cost, mitigation, evidence and cleanup |
| Archive | Retired APIs, transcripts and historical tool output | Clearly non-executable and excluded from the active path |
Current publication holds
- AiTM/Evilginx procedure: real-domain and session capture/replay workflow.
- Azure Entra page: privileged mutations and data-access examples pending full conversion.
- AWS enumeration: snapshot mutation, metadata credential retrieval and token handling pending full conversion.
- Azure PwnedLabs transcript: password spray, lockout, retired Graph and secret-like historical evidence.
Mapping rules
Use ATT&CK only for an observed behavior. A public bucket, broad role, missing log, tool, API or provider service is not automatically a technique. Record “no direct ATT&CK mapping” for configuration reviews rather than forcing one.