From Dev to Prod: AWS Cross Account Privilege Escalation
A hands-on journey through AWS attack paths, from individual escalation primitives to a capstone spanning three accounts and conditional access controls.
About the workshop
The lab covers IAM, EC2, SSM, EKS, CloudFormation, KMS, Lambda, and S3, then brings the pieces together in a cross-account attack-path exercise. Participants use AWSHound to analyze the environment and identify the paths an attacker could follow.