The public bucket
A storage bucket is set to public "just to test", and it is still public a year later. See how it is found and how to close it.
Most cloud incidents are configuration, not exploitation. These exercises walk the settings that matter: the bucket that went public, the role that could do anything, the admin console open to the internet, and the root account without a hardware key.
A storage bucket is set to public "just to test", and it is still public a year later. See how it is found and how to close it.
A service uses a wildcard permission because it was quicker. Trim it to least privilege before the credential is the whole account.
A management dashboard is reachable from anywhere with a default login. Understand exposure and put it behind the controls it needs.
The root account runs daily tasks and has no hardware key. Learn why it should be locked away and how access should really work.
When something happens, the logs are off or nobody looks. Set up the trail that turns an incident into an answer.
A disk snapshot is marked public to share with a contractor, and it holds a whole database. Trace the exposure and the safe alternative.