Test lab
Preparation
Notes on techniques
IAM
API Gateway
More
Pentester Academy labs for identifying, enumerating and exploiting overly permissive IAM users, roles and policies.
AWS Policies are a key foundation in good cloud security, but they are often overlooked.
IAM enumeration
Misconfigured trust policy
Overly permissive permission I
Dangerous policy combination I
Dangerous policy combination II
Overly permissive permission II
Pass Role: EC2
Pass Role: Lambda
Pass Role: CloudFormation