IAM Access Analyzer, STS, and Authorization Controls
SCS-C03 Domain 4 — IAM Access Analyzer findings, unused access, AssumeRole and session policies, permission boundaries, IAM Roles Anywhere, policy simulation, and ABAC/RBAC
SCS-C03 Domain 4 — IAM Access Analyzer findings, unused access, AssumeRole and session policies, permission boundaries, IAM Roles Anywhere, policy simulation, and ABAC/RBAC
A hands-on lab demonstrating how to escape a Kubernetes pod, steal the service account token, abuse IRSA to call AWS APIs, and escalate from a container to full AWS account access — then harden with RBAC, network policy, and scoped IRSA roles.
SCS-C03 Domain 4 — IAM Identity Center permission sets, SCIM provisioning, ABAC with attributes, IdP federation, multi-account access, and troubleshooting authentication
A hands-on lab demonstrating four ways to steal AWS credentials from GitHub Actions pipelines — pull_request_target exploitation, workflow injection, command injection, and malicious actions — then replacing all long-lived keys with OIDC to eliminate the attack surface entirely.
SCS-C03 Domain 3 — SSM Session Manager, Patch Manager, Network Firewall, VPC endpoints, Verified Access, security group and NACL controls, and Network Access Analyzer
A hands-on lab demonstrating 8 documented IAM privilege escalation paths — from a low-privilege identity to full AdministratorAccess — and how to detect each one with GuardDuty and Access Analyzer, then fix them with permission boundaries.
SCS-C03 Domain 5 — Secrets Manager rotation, cross-account secrets, VPC endpoints, ACM certificate lifecycle, AWS Private CA hierarchy, and data-in-transit controls
A hands-on lab demonstrating how a Server-Side Request Forgery (SSRF) vulnerability in a web application lets an attacker steal EC2 IAM credentials through the Instance Metadata Service — and exactly how IMDSv2 and WAF cut this attack at the root.
SCS-C03 Domain 5 — KMS key types, key policies, grants, envelope encryption, imported key material, multi-region keys, CloudHSM, and cross-account access
A hands-on lab simulating a full EC2 attack chain — WordPress exploitation, reverse shell, IMDS credential theft, S3 exfiltration, and IAM privilege escalation — all observed through GuardDuty findings in real time.