Before jumping into a pentest and hacking away, it is important to go through the kickoff process with your client to ensure everyone has an understanding of the scope of the pentest, the type of access to be granted to the environment, the goal of the pentest, and more. This process is necessary because no one likes surprises in the pentesting business, and communication makes everyone happy. In this section, we will be covering some of the important aspects of what needs to be done prior to when the pentest begins.
Pentest kickoff
Scoping
One of the most important aspects of an AWS pentest (or any type of pentest, really) is determining the scope of the engagement. AWS engagements are difficult to scope in the sense of traditional...