Description
SEC588: Cloud Penetration Testing. This course is a comprehensive, hands-on training for security professionals designed to effectively assess modern cloud environments. Bridging the gap between traditional penetration testing and cloud-specific challenges, this course covers important topics such as microservices, serverless functions, and Kubernetes deployments. Participants will learn about unique cloud security threats, including service-side vulnerabilities, shared hosting environments, and cloud-native application assessments, and will learn practical techniques for testing AWS and Azure environments. In hands-on labs, attendees will assess security risks in cloud platforms, conduct penetration testing of microservices, analyze container and CI/CD pipeline vulnerabilities, and attack targets such as Kubernetes, serverless functions, and cloud identity systems. Also, understanding the structure of a cloud environment, gathering evidence, and distinguishing between cloud-native, multi-cloud, and hybrid infrastructures are other outcomes of this course. Finally, graduates will be able to apply the acquired knowledge directly to their organization, perform cloud penetration tests, assess environments for vulnerabilities, and report findings.
What you will learn
- Cloud-specific attack methods and vulnerability assessment: Learn cloud-specific attack methods and service page vulnerability assessment techniques.
- Penetration testing of cloud environments: testing microservices, serverless functions, and Kubernetes environments.
- AWS and Azure Strategies and Tools: Implement AWS and Azure penetration testing strategies and use tools specific to these platforms.
- Cloud storage systems evaluation: Evaluation of cloud storage systems including buckets and in-memory datastores.
- Mastery of security testing and exploitation of cloud-native applications: Mastery of security testing methods and exploitation of cloud-native applications.
This course is suitable for people who:
- Security Professionals: Security professionals focused on attack or defense will benefit greatly from this course by understanding vulnerabilities, insecure configurations, and the business risk associated with them.
- Penetration Testers and Vulnerability Analysts: People who work in the roles of penetration tester, vulnerability analyst, risk assessor, DevOps engineer, site reliability engineer, and many other areas.
- People who want to expand their knowledge: People who are looking to expand their knowledge from traditional security to cloud security.
Course Details SEC588: Cloud Penetration Testing
- Publisher: SANS
- Instructor: Aaron Cure , Moses Frost
- Training level: Beginner to advanced
- Training duration: 15 hours and 15 minutes
- Number of lessons: 523
Course headings

Prerequisites for SEC588: Cloud Penetration Testing
- Courses that can lead up to SEC588 include:
- SEC488: Cloud Security Essentials
- SEC542: Web Application Penetration Testing and Ethical Hacking
- SEC540: Cloud Native Security and DevSecOps Automation
- SEC560: Enterprise Penetration Testing
- This course has many labs that are run from the command line, so students must come prepared with the following base level of knowledge:
- Familiarity with Linux bash; not expert level, but a basic understanding.
- Basic familiarity with Azure and AWS CLI tools. Watching a simple introductory video will suffice.
- Basic understanding of networking and TCP/IP.
- A sense of how Port Pivots work using Netcat and SSH
Course images

Sample course video
Installation Guide
After Extract, view with your favorite player.
Subtitles: None
Quality: 720p
PDF file download link
USB file download link
Video file download link
File(s) password: www.downloadly.ir
File size
41 MB, 15.3 GB, 2.5 GB