Chapter 10: Pentesting Best Practices
Pentesting is not a one-size-fits-all type of assessment. What applies to one pentest may differ from another. It's essential to stay on top of trends and skillsets, and have an understanding of what it means to pentest. It's also important to understand that AWS pentesting may differ from traditional pentesting, as we have seen throughout this book and will see further in this chapter. It's vital that we understand both the technical and non-technical parts of AWS pentesting – which is exactly what this chapter is all about. We will begin with an overview of the steps to be carried out during a pentest. We will then look at the unknowns of AWS pentesting. We will learn about prepping your environment before conducting a pentest, and finally, we will discuss some practical steps that need to be carried out after the pentest.
In this chapter, we'll cover the following topics:
- Pentesting methodology for AWS ...