Identify tools and techniques to secure and perform a penetration test on an AWS infrastructure using Kali Linux
Key Features
- Learn not only to cover loopholes but also automate security monitoring and alerting within your cloud-based deployment pipelines
- Efficiently perform penetration testing techniques on your public cloud instances
- A step-by-step guide that will help you leverage the most widely used security platform to secure your AWS-cloud environment.
Book Description
The cloud is taking over the Information Technology industry. Any organization that is housing a large amount of data or infrastructure has started moving cloud-ward - and AWS rules the roost when it comes to Cloud Service providers with the closest competitor having less than half of its market share. This brings to light the importance of security on the cloud, especially on AWS. While a lot has been said (and written) about how cloud environments can be secured, performing external security assessments a la penetration tests on AWS still falls into the category of dark arts.
This book aims to help the pentesters as well as seasoned system administrators with a hands-on approach to penetration testing of the various cloud-services provided by Amazon through AWS using Kali Linux. To make things easier for novice penetration testers, the book focuses on building a practice lab and polishing penetration testing with Kali Linux on the cloud. This is not only helpful for beginners but also for a pentester who would want to set up a Pentesting environment in his private cloud, using Kali Linux, to perform a white-box assessment of his own cloud resources. Besides this, there is a lot of in-depth coverage of the large variety of AWS services that are often overlooked during a pentest - from serverless to automated deployment pipelines.
By the end of this book, you will be able to identify possible vulnerable areas efficiently securing your AWS-cloud environment.
What you will learn
- Guide a penetration tester through the process of enumerating and Pentesting the most common external facing AWS services.
- Guide a system administrator through the process of auditing his own infrastructure and identify flaws, weaknesses, and loopholes.
- Demonstrate the process of lateral and vertical movement through a partially compromised AWS account.
- Demonstrate the process of maintaining stealth and persistence within a compromised AWS account.
- Providing a hands-on approach accompanied by process-based examples for all of the above.
- Highlight a number of automated tools that would ease the process of continuously assessing and improving the security stance of an AWS infrastructure
Who This Book Is For
If you are a security analyst or a penetration tester who is interested in exploiting Cloud environment to find out vulnerable areas an securing them, then this book is for you.
Basic understanding of penetration testing, cloud computing, and its security concepts would be needed.
Kirit Sankar Gupta is a Penetration Tester and Security Generalist who has been actively associated with some organizations in India and abroad over the past 6-7 years. He is a part of the Data Security Council of India, Kolkata chapter as well as a contributor to OWASP Kolkata Chapter.
Kirit has earlier been associated with Rhino Security Labs, a boutique security firm based out of Seattle, as well as his Penetration Testing firm in Kolkata, ISOAH Data Securities. He is currently leading the Penetration Testing Task Force for Intel Corporation in India.
He's also contributed to some open-source code-bases that are widely used in all varieties of application stacks such as ImageMagick, GraphicsMagick, LAME, FFmpeg, tcpdump, Wireshark and holds more than 20 CVEs to his name. His primary interest is in security research for open-source libraries, fuzzing, kernel exploitation and red-teaming. In that past he has worked on numerous application pentests, infrastructure pentests and product pentests for various clients.