{"product_id":"certified-cloud-penetration-tester","title":"Certified Cloud Penetration Tester","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Certified Cloud Penetration Tester\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Hackers Academy\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"color: rgb(224, 21, 21);\"\u003e\u003cstrong\u003eImportant Note:\u003c\/strong\u003e This training is exclusively available to \u003cstrong\u003egovernment entities and participants from GCC countries\u003c\/strong\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eThis course provides a comprehensive introduction to cloud penetration testing for beginners, covering theoretical concepts, hands-on exercises, and practical strategies to breaching the top 3 cloud vendors: Azure, AWS \u0026amp; GCP.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eAs organizations increasingly adopt cloud services, securing cloud environments becomes paramount. Azure, AWS and GCP cloud platforms, are widely used across industries, making them a prime target for cyber threats. This course provides a comprehensive introduction to cloud penetration testing for beginners, covering theoretical concepts, hands-on exercises, and practical strategies to breaching the top 3 cloud vendors.\u003c\/p\u003e\n\u003cp\u003eWith over 20 immersive labs, learn how real attackers target AWS, Azure, and Google Cloud Platform. Through dynamic labs, guided simulations, and red-team thinking, you'll uncover the techniques adversaries use to breach, move and blend inside modern cloud environments.\u003c\/p\u003e\n\u003cp\u003eYou'll explore how identity, networking, automation, serverless, storage, and logging systems become both the attack surface and the battlefield.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics covered include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnumerating services and usernames\u003c\/li\u003e\n\u003cli\u003eVariety of initial access tailored for Azure, AWS and GCP\u003c\/li\u003e\n\u003cli\u003eBypassing defenses like Conditional Access Policies and MFA\u003c\/li\u003e\n\u003cli\u003eUsing cloud native tools to blend in avoid detection\u003c\/li\u003e\n\u003cli\u003eHacking service like storage in Azure, AWS and GCP\u003c\/li\u003e\n\u003cli\u003eCompromising compute for RCE and tokens\u003c\/li\u003e\n\u003cli\u003ePillaging secrets from key vaults\u003c\/li\u003e\n\u003cli\u003eAbusing serverless for privilege escalation\u003c\/li\u003e\n\u003cli\u003eIdentifying IAM weaknesses to create persistent backdoors\u003c\/li\u003e\n\u003cli\u003eAnd a lot more!\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch3\u003e3.1 Azure Pentesting\u003c\/h3\u003e\n\u003ch4\u003eIntroduction \u0026amp; Lab Setup\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e Introduction to Microsoft Azure, AWS and GGP and some of the most used services\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Important concepts and terminology: tenant, subscription, resource groups, resource, IAM, VM, EC2, Storage, S3, etc.\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Running the lab scripts to build up the attack scenarios\u003c\/p\u003e\n\u003ch3\u003e3.2 Azure Recon\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e Tenant availability and gather tenant information\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Validating tenant availability\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Azure subdomains recon as outsider\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Identifying Azure services in use\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Enumerating subdomains\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e User enumeration in Azure\u003cbr\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Understanding error codes\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Enumerating usernames\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e3.3 Azure Initial Access\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e Password Spraying\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Password spraying\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e Consent Phishing\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Consent grant\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e Device Code Phishing\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Device Code Phishing\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.4\u003c\/strong\u003e Adversary-in-The-Middle\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: AiTM\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e3.4 Conditional Access Policies\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e Understanding CAPs\u003cbr\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e What CAPs can and cannot do\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Understanding CAP gaps\u003cbr\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e CAP bypass strategies: membership, location, device, application …\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Bypass CAP\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.5\u003c\/strong\u003e Lab: Bypassing CAP with stolen tokens\u003c\/p\u003e\n\u003ch3\u003e3.5 Azure IAM (RBAC)\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e IAM vs. Entra roles\u003cbr\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Primary resource roles\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e Separation of IAM and Entra roles\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Global admin elevation to RBAC – Case Study: Dev-1084 APT\u003c\/p\u003e\n\u003ch3\u003e3.6 Azure Storage Attacks\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Storage types\u003cbr\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e Storage accounts\u003cbr\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e Storage endpoints\u003cbr\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Storage Access Levels\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Enumerate and access public storage\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.5\u003c\/strong\u003e Storage Account Access\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSAS\u003c\/li\u003e\n\u003cli\u003eEntra ID authorization\u003c\/li\u003e\n\u003cli\u003eShared Keys\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.6\u003c\/strong\u003e Lab: Storage access with SAS\u003cbr\u003e\u003cstrong\u003e3.6.7\u003c\/strong\u003e Lab: Storage access with shared key\u003c\/p\u003e\n\u003ch3\u003e3.7 Azure Virtual Machines \u0026amp; IMDS\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.1\u003c\/strong\u003e Azure VMs\u003cbr\u003e\u003cstrong\u003e3.7.2\u003c\/strong\u003e Managed identities\u003cbr\u003e\u003cstrong\u003e3.7.3\u003c\/strong\u003e IMDS\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: requesting tokens from IMDS\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e3.8 Azure Key Vaults\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.1\u003c\/strong\u003e Understanding key vaults\u003cbr\u003e\u003cstrong\u003e3.8.2\u003c\/strong\u003e Key vault access policies\u003cbr\u003e\u003cstrong\u003e3.8.3\u003c\/strong\u003e Key vault IAM\u003cbr\u003e\u003cstrong\u003e3.8.4\u003c\/strong\u003e Managed IDs and Key Vaults\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLab: Retrieving secrets from key vaults\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.5\u003c\/strong\u003e Key vault tampering for persistence\u003c\/p\u003e\n\u003ch3\u003e3.9 AWS Pentesting\u003c\/h3\u003e\n\u003ch3\u003e3.10 AWS Introduction\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.1\u003c\/strong\u003e Intro to AWS\u003cbr\u003e\u003cstrong\u003e3.10.2\u003c\/strong\u003e Attacker’s view and AWS APIs\u003cbr\u003e\u003cstrong\u003e3.10.3\u003c\/strong\u003e Understanding ARNs\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eCommon Services\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eS3\u003c\/li\u003e\n\u003cli\u003eEC2\u003c\/li\u003e\n\u003cli\u003eLambda\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e3.11 AWS Storage\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.11.1\u003c\/strong\u003e Understanding S3 common usages\u003cbr\u003e\u003cstrong\u003e3.11.2\u003c\/strong\u003e Where to look for S3 information\u003cbr\u003e\u003cstrong\u003e3.11.3\u003c\/strong\u003e Lab: S3 enumeration\u003c\/p\u003e\n\u003ch3\u003e3.12 AWS Initial Access\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.12.1\u003c\/strong\u003e Cloud attack lifecycle\u003cbr\u003e\u003cstrong\u003e3.12.2\u003c\/strong\u003e AWS access keys\u003cbr\u003e\u003cstrong\u003e3.12.3\u003c\/strong\u003e Searching for leaked keys\u003cbr\u003e\u003cstrong\u003e3.12.4\u003c\/strong\u003e Lab: Finding leaked keys\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch3\u003e3.13 AWS Pentesting (Cont.)\u003c\/h3\u003e\n\u003ch3\u003e3.14 AWS IAM\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.14.1\u003c\/strong\u003e What is IAM and what does it do?\u003cbr\u003e\u003cstrong\u003e3.14.2\u003c\/strong\u003e Policies, actions in policies and reading JSON\u003cbr\u003e\u003cstrong\u003e3.14.3\u003c\/strong\u003e AWS Roles\u003cbr\u003e\u003cstrong\u003e3.14.4\u003c\/strong\u003e AWS permissions\u003cbr\u003e\u003cstrong\u003e3.14.5\u003c\/strong\u003e Roles vs. Users\u003cbr\u003e\u003cstrong\u003e3.14.6\u003c\/strong\u003e Lab: Compromised user IAM user and role\u003c\/p\u003e\n\u003ch3\u003e3.15 Insider Recon\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.15.1\u003c\/strong\u003e Understanding cloud attacker mindset\u003cbr\u003e\u003cstrong\u003e3.15.2\u003c\/strong\u003e Important questions for post initial access\u003cbr\u003e\u003cstrong\u003e3.15.3\u003c\/strong\u003e Important AWS cli commands to know for situational awareness\u003cbr\u003e\u003cstrong\u003e3.15.4\u003c\/strong\u003e Lab: Post initial access, determine users, roles, policies and resources\u003c\/p\u003e\n\u003ch3\u003e3.16 EC2 \u0026amp; IMDS\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.16.1\u003c\/strong\u003e What is EC2\u003cbr\u003e\u003cstrong\u003e3.16.2\u003c\/strong\u003e Enumerating role assignments to EC2\u003cbr\u003e\u003cstrong\u003e3.16.3\u003c\/strong\u003e Understanding IMDS\u003cbr\u003e\u003cstrong\u003e3.16.4\u003c\/strong\u003e IMDS v1 vs. IMDS v2\u003cbr\u003e\u003cstrong\u003e3.16.5\u003c\/strong\u003e Lab: Hacking an EC2 with IMDS v1 to retrieve tokens\u003cbr\u003e\u003cstrong\u003e3.16.6\u003c\/strong\u003e Lab: Trying to hack an EC2 with MDS v2\u003c\/p\u003e\n\u003ch3\u003e3.17 AWS Lambda\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.1\u003c\/strong\u003e Understanding serverless and Lambda\u003cbr\u003e\u003cstrong\u003e3.17.2\u003c\/strong\u003e Examples of Lambda usage\u003cbr\u003e\u003cstrong\u003e3.17.3\u003c\/strong\u003e Enumerating role assignments to Lambda\u003cbr\u003e\u003cstrong\u003e3.17.4\u003c\/strong\u003e Lambda misconfigurations and exploitation\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSecrets\u003c\/li\u003e\n\u003cli\u003eCommand injection\u003c\/li\u003e\n\u003cli\u003eOverly permissive roles\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.5\u003c\/strong\u003e RCE example abusing Lambda function\u003cbr\u003e\u003cstrong\u003e3.17.6\u003c\/strong\u003e Lab: Pillaging Lamda functions for secrets\u003c\/p\u003e\n\u003ch3\u003e3.18 AWS Privilege Escalation\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.18.1\u003c\/strong\u003e What to look for in AWS\u003cbr\u003e\u003cstrong\u003e3.18.2\u003c\/strong\u003e Common paths to root\u003cbr\u003e\u003cstrong\u003e3.18.3\u003c\/strong\u003e Hunting for interesting permissions\u003cbr\u003e\u003cstrong\u003e3.18.4\u003c\/strong\u003e Finding admin\/root users\u003cbr\u003e\u003cstrong\u003e3.18.5\u003c\/strong\u003e Lab: hunting for privileged users\u003cbr\u003e\u003cstrong\u003e3.18.6\u003c\/strong\u003e Lab: Identifying exploitable permissions for privesc\u003c\/p\u003e\n\u003ch3\u003e3.19 AWS Persistence\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.19.1\u003c\/strong\u003e Paths to persistence in AWS\u003cbr\u003e\u003cstrong\u003e3.19.2\u003c\/strong\u003e Backdooring users\u003cbr\u003e\u003cstrong\u003e3.19.3\u003c\/strong\u003e Backdooring access keys\u003cbr\u003e\u003cstrong\u003e3.19.4\u003c\/strong\u003e Backdooring IAM Role trust\u003cbr\u003e\u003cstrong\u003e3.19.5\u003c\/strong\u003e Lab: assign admin permissions to user and create backdoored access key\u003c\/p\u003e\n\u003ch3\u003e3.20 GCP Introduction\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.20.1\u003c\/strong\u003e GCP intro and attacker setup\u003cbr\u003e\u003cstrong\u003e3.20.2\u003c\/strong\u003e What is GCP and how is it different than AWS and Azure\u003cbr\u003e\u003cstrong\u003e3.20.3\u003c\/strong\u003e The attacker’s view of GCP\u003cbr\u003e\u003cstrong\u003e3.20.4\u003c\/strong\u003e GCP hierarchy and why it matters\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eGCP Common Services\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eGCE\u003c\/li\u003e\n\u003cli\u003eStroage\u003c\/li\u003e\n\u003cli\u003eSQL\u003c\/li\u003e\n\u003cli\u003eBigQuery\u003c\/li\u003e\n\u003cli\u003eGatekeeper\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e3.21 GCP IAM\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.21.1\u003c\/strong\u003e What IAM in GCP looks like\u003cbr\u003e\u003cstrong\u003e3.21.2\u003c\/strong\u003e Understanding Principals\u003cbr\u003e\u003cstrong\u003e3.21.3\u003c\/strong\u003e IAM Roles\u003cbr\u003e\u003cstrong\u003e3.21.4\u003c\/strong\u003e IAM Resources and some examples\u003cbr\u003e\u003cstrong\u003e3.21.5\u003c\/strong\u003e IAM Policies and Policy Binding\u003cbr\u003e\u003cstrong\u003e3.21.6\u003c\/strong\u003e Service Accounts\u003cbr\u003e\u003cstrong\u003e3.21.7\u003c\/strong\u003e Service Account Keys\u003cbr\u003e\u003cstrong\u003e3.21.8\u003c\/strong\u003e Tokens\u003cbr\u003e\u003cstrong\u003e3.21.9\u003c\/strong\u003e Dangerous default accounts\u003c\/p\u003e\n\u003ch3\u003e3.22 GCP Initial Access\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eGCP Attack LifeCycle\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.22.1\u003c\/strong\u003e GCP Attack Playbook\u003cbr\u003e\u003cstrong\u003e3.22.2\u003c\/strong\u003e Evading detection\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eInitial Access\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.22.3\u003c\/strong\u003e The reality of most breaches\u003cbr\u003e\u003cstrong\u003e3.22.4\u003c\/strong\u003e Leaked service account keys\u003cbr\u003e\u003cstrong\u003e3.22.5\u003c\/strong\u003e Where to find keys\u003cbr\u003e\u003cstrong\u003e3.22.6\u003c\/strong\u003e Most exploited misconfigurations\u003cbr\u003e\u003cstrong\u003e3.22.7\u003c\/strong\u003e Default Compute Service Account example\u003cbr\u003e\u003cstrong\u003e3.22.8\u003c\/strong\u003e RCE to short-lived tokens\u003c\/p\u003e\n\u003ch3\u003e3.23 Enumeration\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.23.1\u003c\/strong\u003e Tools for post-breach recon\u003cbr\u003e\u003cstrong\u003e3.23.2\u003c\/strong\u003e How to blend it when the dev team\u003cbr\u003e\u003cstrong\u003e3.23.3\u003c\/strong\u003e What to avoid\u003cbr\u003e\u003cstrong\u003e3.23.4\u003c\/strong\u003e Key questions for situation awareness\u003cbr\u003e\u003cstrong\u003e3.23.5\u003c\/strong\u003e Key commands for gcloud cli\u003cbr\u003e\u003cstrong\u003e3.23.6\u003c\/strong\u003e Hunting for valuable data\u003cbr\u003e\u003cstrong\u003e3.23.7\u003c\/strong\u003e Lab: Insider enum\u003c\/p\u003e\n\u003ch3\u003e3.24 Cloud Storage\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.24.1\u003c\/strong\u003e What is Google cloud storage?\u003cbr\u003e\u003cstrong\u003e3.24.2\u003c\/strong\u003e What are high value targets in cloud storage?\u003cbr\u003e\u003cstrong\u003e3.24.3\u003c\/strong\u003e Abusing common misconfigurations\u003cbr\u003e\u003cstrong\u003e3.24.4\u003c\/strong\u003e Lab: list storage buckets, identify permission gaps and exfil sensitive data\u003c\/p\u003e\n\u003ch3\u003e3.25 Compute Engine \u0026amp; Metadata Exploitation\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.25.1\u003c\/strong\u003e What is GCP compute engine\u003cbr\u003e\u003cstrong\u003e3.25.2\u003c\/strong\u003e What is it a valuable target\u003cbr\u003e\u003cstrong\u003e3.25.3\u003c\/strong\u003e What is the Metadata Service\u003cbr\u003e\u003cstrong\u003e3.25.4\u003c\/strong\u003e Why target the Metadata Service\u003cbr\u003e\u003cstrong\u003e3.25.5\u003c\/strong\u003e Legacy v0.1 endpoints and how Google fixed it\u003cbr\u003e\u003cstrong\u003e3.25.6\u003c\/strong\u003e Modern attack vectors\u003cbr\u003e\u003cstrong\u003e3.25.7\u003c\/strong\u003e RCE to steal tokens\u003cbr\u003e\u003cstrong\u003e3.25.8\u003c\/strong\u003e How to use stolen tokens\u003cbr\u003e\u003cstrong\u003e3.25.9\u003c\/strong\u003e Lab: exploit a vulnerable app to steal tokens\u003c\/p\u003e\n\u003ch3\u003e3.26 Secret Manager\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.26.1\u003c\/strong\u003e What is Google Secret Manager\u003cbr\u003e\u003cstrong\u003e3.26.2\u003c\/strong\u003e What to expect if it’s exploited\u003cbr\u003e\u003cstrong\u003e3.26.3\u003c\/strong\u003e Secret Manager common misconfigurations\u003cbr\u003e\u003cstrong\u003e3.26.4\u003c\/strong\u003e Lab: Listing secrets and retrieving their values\u003c\/p\u003e\n\u003ch3\u003e3.27 Privilege Escalation in GCP\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.27.1\u003c\/strong\u003e GCP’s unique model\u003cbr\u003e\u003cstrong\u003e3.27.2\u003c\/strong\u003e The concept of chained impersonations\u003cbr\u003e\u003cstrong\u003e3.27.3\u003c\/strong\u003e Service account impersonation and how it works\u003cbr\u003e\u003cstrong\u003e3.27.4\u003c\/strong\u003e Impersonation attack flow\u003cbr\u003e\u003cstrong\u003e3.27.5\u003c\/strong\u003e Other privesc path\u003cbr\u003e\u003cstrong\u003e3.27.6\u003c\/strong\u003e Lab: from low priv user to generating tokens to privesc\u003c\/p\u003e\n\u003ch3\u003e3.28 Persistence in GCP\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.28.1\u003c\/strong\u003e GCP persistence TTPs: Backdooring keys, users and hijacking accounts\u003cbr\u003e\u003cstrong\u003e3.28.2\u003c\/strong\u003e Techniques for org level persistence\u003cbr\u003e\u003cstrong\u003e3.28.3\u003c\/strong\u003e Lab: Backdooring org with service account and new keys\u003c\/p\u003e\n\u003ch3\u003e3.29 BigQuery – Bonus Section if Time Allows\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.29.1\u003c\/strong\u003e What is BigQuery\u003cbr\u003e\u003cstrong\u003e3.29.2\u003c\/strong\u003e Why is it a valuable target\u003cbr\u003e\u003cstrong\u003e3.29.3\u003c\/strong\u003e BigQuery common misconfigurations: permissions, datasets, service accounts\u003cbr\u003e\u003cstrong\u003e3.29.4\u003c\/strong\u003e BigQuery enumeration\u003cbr\u003e\u003cstrong\u003e3.29.5\u003c\/strong\u003e BigQuery exfil\u003cbr\u003e\u003cstrong\u003e3.29.6\u003c\/strong\u003e Lab: Finding PII in BigQue\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eStudents should have:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eStudents are not expected to have knowledge of cloud services. However, it would help to have a basic level understanding of cyber security concepts, networking and operating systems.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStudents should bring a laptop with RDP client.\u003c\/li\u003e\n\u003cli\u003eAll labs are cloud based.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStudents will be provided with all course material. This includes over 300 slides and over 70 pages of lab manuals.\u003c\/li\u003e\n\u003cli\u003eCloud labs will be available for each student for 90 hours usage (within 15 days from the start of the training).\u003c\/li\u003e\n\u003cli\u003eThe instructors will share their own lab guides and scripts so students can replicate the setup in their private labs.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer Bio\u003c\/h2\u003e\n\u003ch3\u003eTarek Naja\u003c\/h3\u003e\n\u003cp\u003eTarek Naja is the founder of AstraSec.io and HackersAcademy.com. Tarek holds an MSc. in Information Security, is an international trainer who teaches at Blackhat, HiTB and other major conferences. He is also the technical advisor for GISEC, the largest security conference in the Middle East and is a previous OWASP Dubai Chapter Leader.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003eDEF CON Training Code of Conduct\u003c\/a\u003e and the registration terms and conditions listed above.\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942335914227,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/default_DCT_photo.webp?v=1786559556","url":"https:\/\/me.shop.defcon.org\/products\/certified-cloud-penetration-tester","provider":"DEF CON MIDDLE EAST","version":"1.0","type":"link"}