Key Concepts for Pentesting Today’s Cloud Networks
Before you perform your first cloud pentest or red team engagement, there are some concepts you need to learn.
Cloud platforms have policies for pentesting that you and your organization must abide by. It’s also important to understand and verify network performance with benchmark checks. Services enumeration is a way an attacker can learn things about your organization’s public cloud services that can help them cyber-attack it.
Assure that your organization’s public cloud has performed vulnerability assessments and that common cloud misconfigurations are addressed before you pentest.
Resources provided by MITRE’s Common Vulnerabilities and Exposures (CVE) database, the National Institute of Standards and Technology’s (NIST’s) National Vulnerability Database (NVD) database, and the Forum of Incident Response and Security Teams’ (FIRST’s) Exploit Prediction Scoring...