WS3 - AWS Cloud Security 101: From IAM Misconfigurations to Account Takeover
Description
Instructed by: “zeta”
Level of Difficulty: Beginner, Intermediate
Abstract:
The shortest path from a marketing-site SSRF to production root often runs through AWS, and most defenders can't see it happening. This workshop teaches you to walk that path yourself.
Working whitebox in provided lab accounts, you'll move through eight hands-on modules: reading IAM policies for privilege escalation gadgets, turning a single SSRF into a working CLI session via IMDS, abusing cross-account trust, exploiting resource policies across S3/KMS/Lambda, compromising serverless functions, and evading CloudTrail. The workshop closes with a full-chain challenge: build a Python exploit that goes from external SSRF to administrative access in one script.
Pre-Requisites:
Basic AWS familiarity (console + CLI), comfort reading JSON policies, Python. Bring a laptop with AWS CLI v2 and Python 3.10+ installed. No prior offensive cloud experience required.
Required:
· Comfort with a command line (bash or PowerShell)
· Working understanding of HTTP, web applications, and proxy interception (e.g., Burp Suite)
· Ability to read and modify Python scripts (no Python wizardry required)
· Comfort reading JSON
Helpful but not required:
· Prior AWS console or CLI exposure
· Familiarity with any cloud provider
· Experience with offensive tooling (Burp, sqlmap, etc.)
Explicitly NOT required:
· Prior offensive cloud experience
· Deep AWS service knowledge, the workshop teaches what you need
· Pacu, CloudFox, or boto3 familiarity
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


