Last updated: April 29, 2026
Cloud red teaming is different from AD. No NT hashes; tokens. No Kerberos; OAuth/STS. Different tools, different OPSEC.
The cloud kill chain
- Initial credential acquisition (phishing dev for AWS keys, or compromise endpoint with cached cli credentials)
- Discovery — what services, what permissions
- Privilege escalation — IAM-misconfig paths (covered Cloud Module 8-9)
- Lateral movement — cross-account, cross-region, cross-cloud
- Persistence — backdoor IAM users, Lambda triggers, S3 lifecycle policies that auto-recreate access
- Exfiltration — large reads from S3, BigQuery, Cosmos DB
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.