threatfound
All paths
Intermediate · 3 modules

Cloud Security

IAM, storage, metadata and misconfigurations across AWS, GCP and Azure.

▸ the territory
3 / 3 live

A map, not a checklist, see exactly where you are and what comes next.

  1. IAM: the real cloud p…9m
  2. Public buckets & stor…9m
  3. The metadata service…9m

Lessons

read · then do
01IAM: the real cloud perimeterWhy identity, not the network, is where cloud breaches happen. 9 min read
02Public buckets & storage exposureObject storage left readable or writable to the world is a top recurring cloud leak; this lesson explains how it happens, how it's found, and how to lock it down. 9 min read
03The metadata service & SSRF-to-credentialsHow a server-side request forgery flaw becomes full cloud account access by tricking a vulnerable app into reading temporary IAM credentials from the instance metadata service, and how IMDSv2 and least privilege break the chain. 9 min read