Cloud Infrastructure Attacks
Cloud infrastructure attacks and misconfigurations across AWS, Azure, and GCP.
Cloud infrastructure attacks exploit misconfigurations and weaknesses across AWS, Azure, and GCP environments: IAM misconfigurations, credential leakage through metadata services and SSRF, privilege escalation, and lateral movement between cloud resources. These cloud attack techniques are documented by Vid Grosek, lead penetration tester at Telprom d.o.o., based in Ljubljana, Slovenia. For the defensive view, see the cloud security expertise page or browse related articles and research.
Coming soon.
Frequently Asked Questions
What is a cloud infrastructure attack?
A cloud infrastructure attack exploits misconfigurations and weaknesses in AWS, Azure, and GCP environments, such as IAM misconfigurations, metadata leakage via SSRF, privilege escalation, and lateral movement across cloud resources.
How are AWS, Azure and GCP environments tested?
Cloud penetration testing reviews identity and access (IAM) configurations, exposed storage and metadata services, container and Kubernetes security, and privilege escalation and lateral movement paths to demonstrate real attack chains in each environment.