How security testing works
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
When the perimeter is a token: accounts, keys, consents, cloud exposure and mapping the paths from a foothold to privilege.
Network boundaries matter less every year. The practical perimeter is identity, and the practical attack surface is every account, key, token and consent that can authenticate — plus whatever a cloud account exposes by default.
This course covers enumerating the identity surface, controlling credentials and consents, finding cloud exposure, and mapping the paths from an ordinary account to the thing an attacker wants.
4 lessons · 57 min
Enumerating accounts, factors, exclusions and the machine identities nobody counts.
Long-lived credentials, OAuth grants and the quiet routes into a tenant.
The short list of settings behind most cloud incidents, and preventing rather than finding them.
Thinking in graphs: from one ordinary account to the objective, and which link to cut.
Sign in and enrol to leave a review.
No reviews yet — be the first once you have worked through it.
2 min read
2 min read
2 min read
2 min read
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
A methodical way through an application: mapping, authentication flows, access control and business logic.
Discovery, service enumeration, configuration weaknesses and proving that segmentation exists outside the diagram.