Skip to content

Identity and cloud attack surface

When the perimeter is a token: accounts, keys, consents, cloud exposure and mapping the paths from a foothold to privilege.

Free on glitchdata advanced 4 lessons 57 min

What you'll learn

  • Enumerate the identity surface, including machine credentials and consents
  • Reduce standing privilege and long-lived credentials
  • Find the cloud misconfigurations behind most incidents
  • Map and shorten the paths from a foothold to privilege

About this course

Network boundaries matter less every year. The practical perimeter is identity, and the practical attack surface is every account, key, token and consent that can authenticate — plus whatever a cloud account exposes by default.

This course covers enumerating the identity surface, controlling credentials and consents, finding cloud exposure, and mapping the paths from an ordinary account to the thing an attacker wants.

Before you start

  • Experience with cloud platforms and an identity provider
  • Understanding your attack surface, or equivalent

Course content

4 lessons · 57 min

  1. 1
    Identity as the perimeter

    Enumerating accounts, factors, exclusions and the machine identities nobody counts.

    Free preview 15 min
  2. 2
    Keys, tokens and consent

    Long-lived credentials, OAuth grants and the quiet routes into a tenant.

    14 min
  3. 3
    Cloud exposure and misconfiguration

    The short list of settings behind most cloud incidents, and preventing rather than finding them.

    14 min
  4. 4
    Mapping paths to privilege

    Thinking in graphs: from one ordinary account to the objective, and which link to cut.

    14 min

What learners say

Sign in and enrol to leave a review.

No reviews yet — be the first once you have worked through it.

More in Cyber security