Filtered View
Tag: #aws
6 posts
HTB Sherlock: Nubilum-1
AWS CloudTrail investigation of unauthorized EC2 activity, exposed S3 access, attacker infrastructure changes, and PoshC2 activity.
AWS Detection + Blue Team
Phase 4 notes: AWS detection, CloudTrail analysis, Athena queries, Macie, Security Hub, Amazon Detective, and credential abuse response.
Cloud Docs, Challenges, and Cheatsheets
Curated cloud learning resources including challenge platforms and practical attack/defense references.
AWS Privilege Escalation + Service Abuse
Phase 3 notes: privilege escalation paths, trust-policy abuse, and service-level exploitation across S3, IAM, Cognito, SQS, and Lambda.
Web-to-Cloud Attack Chains
Phase 2 notes: chaining web vulnerabilities into AWS credential theft, secret discovery, and cloud resource compromise.
AWS Storage + IAM Foundation
Phase 1 notes: S3, IAM, account ID discovery, CloudTrail investigation, and exposure risks in EBS/RDS.