Group Purchasing
Group Purchasing

SEC588: Cloud Penetration Testing

SEC588Offensive Operations
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Moses FrostAaron Cure
Moses Frost & Aaron Cure
SEC588: Cloud Penetration Testing
Course authored by:
Moses FrostAaron Cure
Moses Frost & Aaron Cure
  • GIAC Cloud Penetration Tester (GCPN)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 24 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Cloud security starts with thinking like the adversary—hack, test, and assess cloud environments built from real-world attacks.

Course Overview

SEC588 is a specialized course that focuses on penetration testing in Cloud environments. The course itself is part of both the Offensive Operations and Cloud Curricula. It equips Penetration Testers, Red Team Operators, Cloud Practitioners, Cloud Architects, and those involved in incident response with the tools to assess and operate in various cloud environments. The course features AWS, Azure, Microsoft 365, and Kubernetes to provide students with hands-on experience across the broadest range of environments, ensuring comprehensive coverage. Apply offense and defense capabilities in the cloud immediately.

Be Ready To Test Tomorrow's IT Landscape

SEC588 is a Course Designed around testing and assessment of environments as they move from legacy Data Centers into the more modern Cloud Infrastructure. Some of our students come from environments that utilize hybrid cloud, fully cloud-based, or purely SaaS applications. Evaluating how these systems are integrated into the business becomes increasingly important to organizations. Students will learn how to perform assessment work on both the identity layer and the infrastructure layer of cloud infrastructure.

SEC588 training prepares you to confront scenarios that we increasingly see in penetration testing—focusing on the components that are most encountered and asked about. The methodologies are flexible enough to be applied to other types of clouds, as many of their similarities are exposed.

A big focus of the class is on hands-on labs, in environments that are typically difficult to set up and expensive to operate. The students will spend 50% of the class time in their labs. Students will also be able to apply the course content to the practical applicability directly in those labs. Many multipart labs increase the learner’s ability by simulating challenging operational environments.

In the SEC588 course, we only use toolsets that have a proven record and have been used in real-world engagements. This provides students with the ability to fulfill the SANS promise of being able to return to the workplace and immediately apply what was learned in the course. Whether you are a consultant looking to enhance your own skill set or are on the defensive side, seeking to build detections, we believe SEC588 Cloud Penetration Testing will make your training investment immediately valuable day one.

Author Statement

When this course was first launched in April 2020, the concept of cloud penetration testing was a known yet still emerging and specialized field, gaining significance as a key area of concern. In 2025, to address the continually evolving landscape and focus, the course underwent its fifth and most substantial update to date. My goal was to incorporate as many real-world assessment methods as possible across various cloud platforms, a commitment we will maintain until the pace of innovation in this field decelerates. Ultimately, I hope this class will continue to empower both the red and blue teams to build stronger defenses and enhance the security of these environments.

- Moses Frost

What You'll Learn

  • Conduct end-to-end IaaS, PaaS, and SaaS Penetration Testing Scenarios
  • Learn modern attack techniques in real-world ranges
  • Build a methodology to assess weaknesses in Cloud Environments
  • Modern attacks on Microsoft and AWS Environments
  • Use Modern C2 Toolsets to move laterally in Cloud Environments

Business Takeaways

  • Comprehensive risk analysis on Modern Cloud environments
  • Enhanced security posture by learning offensive techniques on cloud and SaaS systems
  • Scalable testing methodologies to tackle the most modern datacenters
  • Learn to examine critical business assets
  • Build a transferable offensive skillset

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC588: Cloud Penetration Testing.

Section 1Architecture, Discovery, and Recon at Scale

How do clouds work? How do the offensive teams operate in these environments? What are the limits of testing? How do we scan for vulnerabilities externally and internally in a safe manner? The first section of the course is designed to help the student begin their Cloud Assessment journey.

Topics covered

  • Cloud Architectures for Scoping a Test
  • External Network Discovery Using The Asset Discovery Pipeline
  • Internal Cloud Vulnerability Scanning
  • Cloud Authentication Overview

Labs

  • Course Overview Immersion Lab
  • External Attack Surface Discovery
  • Internal Cloud Enumerations
  • Hawkins Research Lab Scavenger Hunt

Overview

In Section 1, we introduce learners to the structure of a test as well as what is allowed and not permitted in many cloud environments. We provide guidance on how to structure assessments as a consultant or procure them as an internal team. We introduce you to the Asset Discovery Pipeline, which enables consistent internal and external testing.

Full Lab Details

  • Lab 1.1 Course Overview Lab: Immersive Course Preview Lab
  • Lab 1.2 External Attack Surface Discovery Lab
  • Lab 1.3 Internal Cloud Enumerations
  • Lab 1.4 Hawkins Scavenger Hunt

Full Topic Details

  • The testing process
    • Cloud architectures
    • Testing and Limits
    • Scoping and Assumed Breach
  • External Scanning
    • The asset discovery pipeline
    • Bruteforcing of External Systems
    • Vulnerability Scanning in the Cloud
    • Visualizations during scans
  • Internal Cloud Enumerations
  • Cloud Authentication Standards
  • Cloud CLI Tools and their use
  • Data Structures, Querying, and Filtering using JMESPath and JQ

Section 2Attacking Identity Systems

While Section One covered the mechanisms for starting and evaluating an environment, Section Two deals with a core component of the cloud. Identity Systems are core to most cloud environments, so we dedicate a whole section to evaluating them. This includes a comprehensive evaluation of Microsoft Entra ID and its key strengths.

Topics covered

  • Authentication Standards
  • Microsoft Cloud Services and Entra ID
  • Malicious App Consents
  • Microsoft Graph
  • File Storage Attacks

Labs

  • Single Factor Authentications
  • Working with Authentication Attacks Tools
  • Microsoft Graph and Malicious App Consents
  • Hunting for Unauthenticated File Shares

Overview

Section 2 provides background on critical protocols in the cloud, such as OpenID Connect. The section provides the tester with the ability to evaluate several Initial Access Methods (IAM), such as how Identity is the new perimeter. Students will learn how to utilize lower-tiered access to find attack paths to higher-privileged accounts. Students will also move from user identity to application identity.

Full Lab Details

  • Lab 2.1 Single Factor Authentications: Attacking and discovering accounts
  • Lab 2.2 Working with attack tools to elevate privileges
  • Lab 2.3 Persistence with App Consents and Microsoft Graph
  • Lab 2.4 Hunting Open File Shares

Full Topic Details

  • Authentication Standards
    • OAuth and OpenIDConnect
    • API Authentication
    • FiDO2 and Passkeys
  • Attacking Accounts
    • Username Harvesting
    • Passwords and Password Attacks
    • Single Factor Attacks
  • Microsoft Entra ID and Cloud Services
    • Defeating Smart Lockout
    • Conditional Access Policies (CAP)
    • Testing for CAP Bypasses
  • Gathering Authentication Material
    • Bypassing Authentications
    • Attacker in the Browser Scenarios
    • Using CursedChrome and Remote Debugger
    • Roadtools for Token Manipulation
    • GraphRunner for Exfiltration
    • Using GraphSpy
  • File Storage and Authenticated Access
    • Hunting for Open or Incorrectly Secured File Shares

Section 3Attacking and Abusing Cloud Services

In Section 3, students will attack the cloud infrastructure assets. Students will learn how to leverage these assets to navigate cloud environments further, elevate privileges, and persist. Cloud Infrastructures can be highly complex, and in that complexity, the students will learn how to navigate and assess the risk each attack path poses.

Topics covered

  • Compute Attack Scenarios
  • AWS IAM and Privilege Escalations
  • Using AWS Attack Tools and C2
  • Azure Compute
  • Code Execution in Azure

Labs

  • AWS End-to-End Attack Lab
  • AssumeRole and Confused Deputy
  • Azure VMs
  • Running Commands on Azure and Azure Managed VMs

Overview

In Section 3, students will now be able to leverage the privileges they have gained throughout the previous two sections of the course to construct attacks on the internal architecture. Throughout the course and during each lab, students have been able to find ways to authenticate into each cloud through a series of attack paths. Using multiple compute attack paths, students will learn to navigate throughout a single cloud and even from cloud to on-premises scenarios, leveraging various techniques.

Full Lab Details

  • End-to-End AWS Attack Lab with multiple attack paths
  • Confused Deputy and AssumeRole attacks
  • Extracting Data from Live VMs
  • Running Commands on Azure VMs in the Cloud and On-Prem

Full Topic Details

  • AWS Compute
    • Computer attack scenarios
    • Persistence Techniques in the Cloud
  • AWS IAM
    • AWS IAM
    • AWS IAM and Privilege Escalation Techniques
  • AWS Attack Tools
    • PACU
  • Sliver and C2 Infrastructure
  • Confused Deputy
    • AssumeRole
  • Azure Compute Attacks
    • Disk Layer Attacks
    • Running Command on Azure VMs
    • Azure Arc Attack Paths

Section 4Vulnerabilities in Cloud Native Applications

Section 4 will walk the students through workloads in the cloud. Applications in the cloud are one of the most common workloads in the cloud, beyond internal data center migration. One of the key features of many of these applications is their cloud-integrated nature. Learning how to assess these systems will be crucial during assessment work.

Topics covered

  • Infrastructure as Code and CI/CD Attacks
  • Web Applications and API Attacks
  • Common Web Attack Paths
  • Attacking Serverless Functions
  • Databases, Datalakes, and LLMs

Labs

  • Terraform and CI/CD Hijacking
  • SSRF and RCE Attacks
  • Serverless Functions
  • Database Attacks

Overview

One of the many workloads that a practitioner will encounter or protect will be applications that are integrated into cloud environments. These cloud-native systems come in various forms and architectures. Cloud-native applications can have their own unique attack paths; as such, an entire section is dedicated to assessing each one, from the base deployment process to the application stack. Attention is given to exploring more common surfaces.

Full Lab Details

  • Lab 4.1: Terraform
  • Lab 4.2: Abusing CI/CD Pipelines with Polluted Execution
  • Lab 4.3: Web Application Discovery Labs
  • Lab 4.4: Modern SSRF Attack Labs
  • Lab 4.5: Remote Code Executions in Modern Apps
  • Lab 4.6: Serverless Function Attacks
  • Lab 4.7: Databases

Full Topic Details

  • Infrastructure
    • IaC and Terraform
    • CI/CD Pipelines and Pipeline Abuse
  • Mapping Applications and APIs
    • Dealing with WAFs and CDNs
    • Common API Attacks
  • Common Web Attacks
    • SSRFs
    • RCE and Command Line Injections Flaws
    • Deserialization Issues in M/L Models
  • Serverless Functions
    • Lambda Attacks
    • How Azure Functions Work
  • Cloud Databases
    • NoSQL and ElasticSearch
    • SQL Injection in Modern Stacks
    • LLMs as a Datasource

Section 5Infrastructure Attacks and Red Teaming

Section 5 provides the student with an overview of infrastructure core components that are cloud-agnostic. Containers comprise a significant portion of cloud workloads. This section provides students with a methodology for assessing container and container workloads. The section concludes with an assessment of work on Kubernetes.

Topics covered

  • Red Team Operations in the Cloud
  • Containers, Docker, and Docker Vulnerabilities
  • Kubernetes
  • Backdooring Workloads

Labs

  • Intro to Containers
  • Breaking out of Container Environments
  • Pivoting through Container Workloads
  • Kubernetes Assessments
  • Persistence and Pivoting in Kubernetes

Overview

Containers are one of the core components in a cloud environment. They make up the building blocks of both serverless functions, cloud-native services, and customer-controlled workloads. They come in a myriad of deployment vehicles. Being able to assess them to provide a workflow that fully protects the company's supply chain. Kubernetes is one of the more common deployment vehicles for these systems. The Kubernetes infrastructure is both complex and powerful. Students have an entire section to work from, container breakouts to Kubernetes meshes.

Full Lab Details

  • Lab 5.1: Intro to Containers
  • Lab 5.2: Docker Breakouts and Pivots
  • Lab 5.3: Kubernetes Assessments and Vulnerabilities
  • Lab 5.4: Deploying Kubernetes Persistence and Pivoting in a Mesh

Full Topic Details

  • Red Team Operations
  • Using the Cloud Infrastructure for Red Team Operations
  • Stealthily moving data through cloud environments
  • Cloud CDNs and Domain Fronting
  • Containers
  • Intro to Generic Containers
  • Docker
  • Vulnerabilities in Container Architectures
  • Docker Misconfigurations
  • Kubernetes
  • Kubernetes Architecture
  • Kubernetes Authorization and RBAC
  • EKS
  • Vulnerability Scanning Kubernetes Workloads
  • Pierates
  • Kubernetes Persistence
  • Backdooring Containers
  • Pivoting with Kubernetes

Section 6Capstone Event

In a final capstone event, we demonstrate cloud penetration testing's unique demands and the specialized expertise required to go beyond traditional security assessments. Students collaboratively bring their new knowledge to bear on a simulated end-to-end test, reinforcing theory and practice and producing an effective, readable report.

Overview

In the final section, be prepared to work as a team to complete an end-to-end assessment in a new cloud environment. The applications and settings are all newly designed to imitate real-world environments. This capstone event allows students to put together the all the knowledge acquired during the week, reinforce theory and practice, and simulate an end-to-end test. Students will be asked to write a report using a method that is easy to read for both developers and administrative staff. We will provide students with a few rubrics and ways to work through the scenarios. There are always new and novel solutions, and we like students to share what they have learned and how they did what they did with one another.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system that meets all the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

The infrastructure for this course is designed to be lightweight and highly compatible.

  • Architecture: No restrictions. This course fully supports Apple Silicon (M1/M2/M3), Intel, and AMD 64-bit CPUs.
  • Operating System: Any modern OS (Windows, macOS, or Linux) is acceptable.
  • Memory: Minimum 4GB RAM.
  • Connectivity: Wireless networking (802.11 standard) is required. Please note that wired internet access is typically not available in the classroom.

Mandatory Host Configuration and Software Requirements

  • HTML5-Compliant Browser: You must have a modern browser installed (e.g., Google Chrome, Mozilla Firefox, or Microsoft Edge).
  • SSH Client: A terminal with an SSHv2-compatible client that supports Local Port Forwarding is required.
    • Windows: OpenSSH (built-in), PowerShell, or Windows Terminal.
    • macOS/Linux: The native Terminal application.
  • No Virtualization Required: You do not need to install VMware, VirtualBox, or download any Virtual Machines (VMs) for this course.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 10 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have questions about the laptop specifications, please contact customer service.

SEC588 is appropriate for:

  • Penetration Testers, Red Team Operators, or Offensive Roles wanting to expand their Cloud Assessment Knowledge
  • Systems Architects, Engineers, and Operators who want to harden their environments to the latest Cloud Attacks
  • Systems Integrators and Manufacturers that are building Offensive and Defensive Products
  • People, Leaders, and Managers who wish to understand the current Cloud attack landscape better.

The GIAC Cloud Penetration Tester (GCPN) certification validates a practitioner's ability to conduct cloud-focused penetration testing and assess the security of systems, networks, architecture, and cloud technologies.

  • Cloud Penetration Testing Fundamentals, Environment Mapping, and Service Discovery
  • AWS and Azure Cloud Services and Attacks
  • Cloud Native Applications with Containers and CI/CD Pipelines

More Certification Details

  • Course Materials, including 4 months of lab access
  • Printed and digital course books with a hands-on workbook
  • Ondemand access for all SEC588 Students
  • MP3 audio files of the full course
  • Video walkthroughs for all labs are included with the On-Demand Portions

SEC588 was written as a Venn Diagram between Network-based Penetration Testing, Web Applications Penetration Testing, and a Site Reliability Engineer (SRE). Having a base knowledge in any of those disciplines will ensure an easier transition for those in the course.

This course has many labs that are run from the command line, so students must come prepared with the following base level of knowledge:

  • Familiarity with Linux bash; not expert level, but a base understanding.
  • Basic familiarity with Azure and AWS CLI tools. Watching a simple introductory video will suffice.
  • Base understanding of networking and TCP/IP.
  • A sense of how Port Pivots work using Netcat and SSH

Courses that can lead up to SEC588 include any of the following:

SEC588 training is part of the Specialized Offensive Operations Learning Path, which equips professionals with advanced skills in cloud-specific penetration testing and adversary simulation. This path is designed for those focused on leveraging modern cloud infrastructure environments, such as AWS and Azure, by utilizing containerized applications, serverless functions, Identity and access management, cloud-native applications, and deployment pipelines. SEC588 is also aligned with the Cloud Security Specialization Path, enabling learners to adapt traditional penetration testing expertise to cloud-native technologies and infrastructure, with an emphasis on identifying business risk in shared-hosting and cloud-first environments.

Cloud penetration testing involves simulating a cyberattack on cloud-based environments—such as AWS, Azure, or Google Cloud—to identify vulnerabilities, misconfigurations, and security gaps before malicious attackers can exploit them. As organizations rapidly shift to the cloud, traditional security testing falls short. Cloud pen testing is crucial for identifying vulnerabilities in cloud-native technologies, including Kubernetes, containers, serverless functions, and identity and access management (IAM) services. By proactively testing cloud security, organizations can strengthen their defenses, ensure regulatory compliance, and protect sensitive data in highly dynamic cloud infrastructures.

SEC588: Cloud Penetration Testing equips you with cutting-edge skills that are in high demand across the cybersecurity industry. You will learn how to conduct real-world cloud security assessments on platforms like AWS and Azure, attacking IdP infrastructure such as Entra ID, master modern attack techniques, and gain hands-on experience with container security, serverless functions, and cloud IAM abuse. Completing this course positions you as a go-to expert in cloud security and offensive operations, boosts your resume with the GCPN certification, and opens doors to roles such as cloud security analyst, penetration tester, red team operator, and DevSecOps engineer.

Relevant Job Roles

Cloud Threat Detection and Response

Cloud Security

Monitor, test, detect, and investigate threats to cloud environments.

Explore learning path

Vulnerability Assessment

SCyWF: Protection And Defense

This role tests IT systems and networks and assesses their threats and vulnerabilities. Find the SANS courses that map to the Vulnerability Assessment SCyWF Work Role.

Explore learning path

Vulnerability Assessment (VUAS)

Skills Framework for the Information Age

Identification and classification of vulnerabilities across systems, applications, and networks. Findings are used to guide patching, mitigation, and security control enhancements.

Explore learning path

Vulnerability Analysis (OPM 541)

NICE: Protection and Defense

Responsible for assessing systems and networks to identify deviations from acceptable configurations, enclave policy, or local policy. Measure effectiveness of defense-in-depth architecture against known vulnerabilities.

Explore learning path

Application Pen Tester

Offensive Operations

Application penetration testers probe the security integrity of a company’s applications and defenses by evaluating the attack surface of all in-scope vulnerable web-based services, clientside applications, servers-side processes, and more. Mimicking a malicious attacker, app pen testers work to bypass security barriers in order to gain access to sensitive information or enter a company’s internal systems through techniques such as pivoting or lateral movement.

Explore learning path

Penetration Tester

European Cybersecurity Skills Framework

Assess the effectiveness of security controls, reveals and utilise cybersecurity vulnerabilities, assessing their criticality if exploited by threat actors.

Explore learning path

Penetration Testing (PENT)

Skills Framework for the Information Age

Performance of authorised tests to identify vulnerabilities in networks, applications, and systems. Findings support remediation planning and risk reduction across the enterprise.

Explore learning path

Systems Testing and Evaluation (OPM 671)

NICE: Design and Development

Responsible for planning, preparing, and executing system tests; evaluating test results against specifications and requirements; and reporting test results and findings.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Japan September 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    ¥1,335,000 JPY*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Paris September 2026

    Paris, FR

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €8,230 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS DC Metro September 2026

    Bethesda, MD, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS London November 2026

    London, GB & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    £7,160 GBP*Prices exclude applicable taxes | EUR price available during checkout
    Registration Options
  • Location & instructor

    SANS Cloud Security South Asia 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,900 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Dallas 2026

    Dallas, TX, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Tokyo January 2027

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    ¥1,335,000 JPY*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Amsterdam February 2027

    Amsterdam, NL & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €8,230 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Austin 2027

    Austin, TX, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
Showing 10 of 10

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources