Cloud Security (CCPE)

Cloud Security (CCPE)

Potpuno novo, iz 2019. godine, ovaj dvodnevni kurs rešava misteriju Cloud Servisa (uključujući AWS, Azure i G-ClouD) i otkriva ranjivosti koje leže ispod. Kurs pokriva mnogobrojne servise i objašnjava ono što ih razlikuje, kao i šta im je zajedničko, u odnosu na hakovanje i obezbeđivanje tradicionalne mrežne infrastrukture.

Bez obzira da li ste Arhitekta, Programer, Pen Tester, Security ili DevOps Inženjer ili bilo ko ko ima potrebu da razume i upravlja ranjivostima u Cloud okruženju, savladaćete relevantne tehnike hakovanja i kako da zaštiti sebe. Kurs pokriva teoriju, ali i mnogobrojne moderne tehnike koje se mogu koristiti da kompromituju različite Cloud servise i infrastrukturu.

Cloud Administratorima, Programerima, Arhitektama rešenja, DevOps Inženjerima, SOC Analitičarima, Pen Testerima, Network Inženjerima, Security entuzijastima i bilo kome ko želi da unapredi svoje veštine.

Iskustvo u pen testiranju nije neophodno, međutim, neko znanje o Cloud Servisima i poznavanje zajedničke komandne linije je velika prednost.

Prior pen test / security experience is not a strict requirement, however, some

knowledge of Cloud Services and a familiarity with common Unix command line syntax

will be beneficial. The syllabus for the class is as follows:

• Introduction to Cloud Computing

• Why cloud matters

• How cloud security differs from conventional security

• Types of cloud services

• Legalities around attacking / pen testing cloud services.

• Understanding the Attack Surfaces of variousCloud offerings, such as IaaS, PaaS,

SaaS, FaaS

• Exploiting serverless applications

• Owning cloud machines

• Attacking cloud services such as storage service or database services

• Examples and case studies of various cloud hacks

• Privilege escalation (horizontal and vertical) and pivoting techniques in cloud

• Obtaining persistence in cloud

• Exploiting dormant assets: Id’s, services, resources groups, security groups and more

• Cloud Infrastructure Defence

• Monitoring and logging

• Benchmarks

• Auditing Cloud Infrastructure (Manual and automated approach)

• Base Images / Golden Image auditing for Virtual Machine / Container Infrastructure

• Preventive measures against cloud attacks

• Host-based Defence

• Using Cloud services to perform defence

• Ending CTF to reinforce the learning

Date:

  • 22 - 23 oktobar 2019
  • 19 - 20 novembar 2019
  • 17 - 18 decembar 2019

Duration: 2 dana

Location: on-line training

Attachments:

hacking-point-hacking-securing-cloud-infrastructure-training-course-overview.pdf

Price:

 Register here

* U cenu nije uračunat PDV