Cloud Penetration Testing
Cloud environments move the attack surface from hosts to identities and managed services, and a network tester's habits do not transfer cleanly. This cloud penetration testing course covers Amazon Web Services, Azure and Google Cloud Platform, focusing on the attack paths each one actually exposes.
You find misconfigurations, escalate through identity and access management, or IAM, and pursue post-exploitation across managed services, all within accounts the academy provides under a written scope and provider testing rules.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Enterprise Penetration Testing
- Class size
- Capped at 12 learners

What you will be able to do
- Enumerate an AWS, Azure or GCP environment within provider testing rules
- Map IAM policies and find privilege escalation paths
- Discover misconfigurations in storage, networking and secrets handling
- Attack serverless, container and managed database services in a lab
- Pivot between accounts and establish cloud persistence
- Explain an identity-driven attack path to engineers and leaders
- Write a cloud penetration test report with prioritised remediation
Course outline
6 modules
- How cloud testing differs from on-premises
- Provider testing policies and authorization
- Enumerating accounts, services and regions
- Reading the shared responsibility boundary
What you need before you start
- Completion of Enterprise Penetration Testing or equivalent
- Working knowledge of at least one major cloud provider
- Comfort with the command line and provider CLIs
- Familiarity with IAM concepts and REST APIs
Who this course is for
- Penetration testers expanding into cloud engagements
- Cloud engineers who want to test their own environments
- Red teamers operating in cloud-hosted estates
- Advanced testers building toward the OSCP mindset in the cloud
Where this leads
Prepares you for
OSCP
Awarded by OffSec
The OSCP is conferred by OffSec after its hands-on exam, not by the academy. This course applies the same manual, methodical exploitation mindset the OSCP rewards to cloud environments, extending your engagement skills beyond the on-premises networks the exam centres on.
Questions about this course
More in offensive security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



