Lab 05 — Enterprise AWS Cloud Penetration Test
Lab Information
Section titled “Lab Information”| Item | Value |
|---|---|
| Module | Module 02 — AWS Cloud Penetration Testing |
| Lab | Lab 05 — Enterprise AWS Cloud Penetration Test |
| Difficulty | Advanced |
| Estimated Time | 4–6 Hours |
| Lab Type | Enterprise Capstone |
| Tools | AWS CLI, Prowler, ScoutSuite, Pacu (Optional), PMapper (Optional), Trivy, kube-bench (Optional), kubectl |
| Prerequisites | Completion of Module 02 Lessons & Labs |
| Assessment Type | End-to-End Enterprise AWS Penetration Test |
Mission Brief
Section titled “Mission Brief”Congratulations.
CloudNova Technologies has assigned you as the Lead Cloud Penetration Tester for your first enterprise consulting engagement.
Your customer, FinSecure Bank Ltd, operates a multi-account AWS environment supporting online banking, internal applications and Kubernetes workloads.
The customer has requested a complete penetration testing engagement to determine whether an attacker could compromise critical business systems.
You are responsible for conducting the engagement exactly as a professional cloud security consultant would.
Learning Objectives
Section titled “Learning Objectives”After completing this lab you will be able to:
- Scope an enterprise AWS penetration test
- Enumerate cloud infrastructure
- Assess IAM security
- Review networking architecture
- Assess EC2 security
- Review Amazon S3 security
- Assess Kubernetes security
- Review Lambda security
- Validate attack paths
- Produce executive penetration testing reports
Enterprise Environment
Section titled “Enterprise Environment”The enterprise contains:
- AWS Organizations
- 20 AWS Accounts
- Amazon EC2
- Amazon S3
- Amazon RDS
- Amazon VPC
- Amazon EKS
- AWS Lambda
- Secrets Manager
- CloudTrail
- GuardDuty
- AWS Config
- Security Hub
- AWS Organizations
- CI/CD Pipelines
Lab Architecture
Section titled “Lab Architecture”Internet
↓
CloudFront
↓
Application Load Balancer
↓
Amazon EC2
↓
Amazon EKS
↓
IAM
↓
Secrets Manager
↓
Amazon S3
↓
Amazon RDS
↓
Customer DataConsulting Engagement Phases
Section titled “Consulting Engagement Phases”Project Kickoff
↓
Scope Validation
↓
Reconnaissance
↓
Enumeration
↓
Identity Assessment
↓
Infrastructure Assessment
↓
Attack Path Validation
↓
Business Impact Analysis
↓
Reporting
↓
Executive PresentationSuccess Criteria
Section titled “Success Criteria”You successfully complete this lab when you can:
- Complete the assessment methodology
- Discover enterprise attack paths
- Produce technical evidence
- Prioritize risks
- Write an executive report
- Present remediation recommendations
Phase 1 — Rules of Engagement
Section titled “Phase 1 — Rules of Engagement”Review:
- Scope
- Testing Window
- Allowed Accounts
- Excluded Resources
- Emergency Contacts
- Communication Plan
Deliverable:
✔ Rules of Engagement Document
Phase 2 — Environment Enumeration
Section titled “Phase 2 — Environment Enumeration”Identify:
- AWS Accounts
- Regions
- IAM Users
- IAM Roles
- VPCs
- EC2 Instances
- Lambda Functions
- S3 Buckets
- EKS Clusters
Useful commands
aws organizations list-accountsaws ec2 describe-instancesaws eks list-clustersaws s3 lsDeliverable
✔ Asset Inventory
Phase 3 — IAM Assessment
Section titled “Phase 3 — IAM Assessment”Review:
- IAM Users
- IAM Groups
- IAM Roles
- Policies
- Trust Relationships
- MFA
- Access Keys
Identify:
- Administrator Accounts
- Wildcard Policies
- PassRole
- AssumeRole
- Privilege Escalation
Deliverable
✔ IAM Security Assessment
Phase 4 — Network Assessment
Section titled “Phase 4 — Network Assessment”Review:
- VPC Architecture
- Security Groups
- NACLs
- Route Tables
- Transit Gateway
- VPC Peering
- Internet Gateways
- NAT Gateways
Identify:
- Public Services
- Flat Networks
- Weak Segmentation
Deliverable
✔ Network Security Review
Phase 5 — EC2 Assessment
Section titled “Phase 5 — EC2 Assessment”Review:
- Public Instances
- Security Groups
- IMDS
- IAM Roles
- EBS Encryption
- User Data
- Patch Levels
Deliverable
✔ EC2 Security Assessment
Phase 6 — Amazon S3 Assessment
Section titled “Phase 6 — Amazon S3 Assessment”Review:
- Public Buckets
- Bucket Policies
- Encryption
- Versioning
- Logging
- Cross-Account Access
Deliverable
✔ Storage Security Assessment
Phase 7 — Amazon EKS Assessment
Section titled “Phase 7 — Amazon EKS Assessment”Review:
- RBAC
- Service Accounts
- IRSA
- Secrets
- Network Policies
- Container Images
- Worker Nodes
Deliverable
✔ Kubernetes Security Assessment
Phase 8 — Serverless Assessment
Section titled “Phase 8 — Serverless Assessment”Review:
- Lambda Functions
- Execution Roles
- Environment Variables
- Secrets
- Layers
- Event Sources
Deliverable
✔ Serverless Security Assessment
Phase 9 — Logging & Detection Assessment
Section titled “Phase 9 — Logging & Detection Assessment”Review:
- CloudTrail
- GuardDuty
- Security Hub
- AWS Config
- CloudWatch
- Security Lake
Deliverable
✔ Logging & Detection Assessment
Phase 10 — Attack Path Validation
Section titled “Phase 10 — Attack Path Validation”Validate realistic enterprise attack chains.
Scenario 1
Section titled “Scenario 1”Public EC2
↓
IAM Role
↓
Amazon S3
↓
Sensitive Customer DataScenario 2
Section titled “Scenario 2”Compromised Lambda
↓
Secrets Manager
↓
Amazon RDS
↓
Banking DatabaseScenario 3
Section titled “Scenario 3”Developer IAM User
↓
PassRole
↓
Administrator Role
↓
Production AccountScenario 4
Section titled “Scenario 4”Compromised Pod
↓
IRSA
↓
Amazon S3
↓
Customer BackupsDocument:
- Entry Point
- Privilege Escalation
- Lateral Movement
- Persistence
- Business Impact
Phase 11 — Risk Assessment
Section titled “Phase 11 — Risk Assessment”Classify every finding.
| Finding | Severity |
|---|---|
| Public EC2 | Critical |
| Public S3 Bucket | Critical |
| Administrator Role Abuse | Critical |
| Missing MFA | Critical |
| IMDSv1 Enabled | High |
| Weak Security Groups | High |
| Weak IRSA | High |
| Missing CloudTrail | High |
| Missing GuardDuty | Medium |
| Missing Encryption | High |
Phase 12 — Executive Dashboard
Section titled “Phase 12 — Executive Dashboard”Create a dashboard.
| Metric | Result |
|---|---|
| AWS Accounts | |
| EC2 Instances | |
| IAM Roles | |
| Critical Findings | |
| High Findings | |
| Medium Findings | |
| Attack Paths | |
| Public Assets | |
| S3 Buckets | |
| Kubernetes Clusters |
Phase 13 — Executive Report
Section titled “Phase 13 — Executive Report”Prepare a professional report containing:
Executive Summary
Section titled “Executive Summary”Business overview.
Accounts assessed.
Services assessed.
Regions assessed.
Methodology
Section titled “Methodology”Assessment methodology.
Testing tools.
Industry standards followed.
Findings
Section titled “Findings”Technical Details
Evidence
Risk Rating
Business Impact
Recommendations
Attack Chains
Section titled “Attack Chains”Visual diagrams.
Business impact.
MITRE ATT&CK mapping.
Remediation Roadmap
Section titled “Remediation Roadmap”Immediate Actions
30-Day Plan
90-Day Plan
Long-Term Improvements
Phase 14 — Executive Presentation
Section titled “Phase 14 — Executive Presentation”Prepare a 15-minute presentation covering:
- Engagement Scope
- Executive Summary
- Critical Risks
- Attack Chains
- Business Impact
- Compliance Risks
- Priority Recommendations
- Security Roadmap
Deliver findings in language suitable for executives, technical teams and auditors.
Bonus Challenges
Section titled “Bonus Challenges”Challenge 1
Section titled “Challenge 1”Run Prowler and compare results with your manual assessment.
Challenge 2
Section titled “Challenge 2”Run ScoutSuite and identify additional risks.
Challenge 3
Section titled “Challenge 3”Use PMapper to generate IAM privilege escalation graphs.
Challenge 4
Section titled “Challenge 4”Use Pacu modules to validate privilege escalation opportunities in a controlled lab environment.
Challenge 5
Section titled “Challenge 5”Map every finding to:
- MITRE ATT&CK
- NIST CSF
- CIS AWS Foundations Benchmark
- AWS Well-Architected Security Pillar
Deliverables
Section titled “Deliverables”Produce the following consulting deliverables:
- Executive Summary
- Rules of Engagement
- Asset Inventory
- IAM Assessment Report
- Network Security Assessment
- EC2 Assessment
- Amazon S3 Assessment
- Amazon EKS Assessment
- Serverless Security Assessment
- Logging & Detection Assessment
- Attack Path Diagrams
- Risk Register
- Executive Dashboard
- Final Penetration Testing Report
- Executive Presentation Deck
Expected Outcome
Section titled “Expected Outcome”After completing this lab, you will have:
- Conducted a full enterprise AWS penetration testing engagement.
- Assessed AWS identity, networking, compute, storage, Kubernetes and serverless security.
- Identified realistic attack paths and business risks.
- Produced consulting-grade reports suitable for technical teams, executives and auditors.
- Demonstrated the practical skills expected of an Enterprise Cloud Penetration Tester working in a consulting or internal red team role.
Key Takeaways
Section titled “Key Takeaways”- Enterprise cloud penetration testing is a structured consulting engagement, not just vulnerability scanning.
- Effective assessments combine technical validation with business risk analysis.
- Identity, networking, storage, compute, Kubernetes and monitoring must be evaluated together to identify complete attack paths.
- Professional reporting, evidence collection and executive communication are as important as technical findings.
- The skills developed in this capstone closely reflect the responsibilities of Cloud Security Consultants, Red Team Operators and Cloud Penetration Testers in enterprise environments.
Module Completion
Section titled “Module Completion”🎉 Congratulations!
You have successfully completed Module 02 — AWS Cloud Penetration Testing.
You are now able to:
- Perform professional AWS cloud penetration tests.
- Assess IAM, networking, EC2, Amazon S3, Amazon EKS and Lambda security.
- Identify privilege escalation, persistence and lateral movement opportunities.
- Build enterprise attack chains.
- Produce executive-ready penetration testing reports.
- Deliver consulting-quality security recommendations.
You are now ready to continue to Module 03 — Azure Cloud Penetration Testing, where you will apply these same offensive security methodologies to Microsoft Azure enterprise environments.