aws 46
- Lab Secrets Manager and KMS Key Abuse: When One Shared Key Decrypts Everything
- AWS Audit Manager, Artifact, and Compliance — Evidence and Assurance
- Lab CloudTrail Tampering and GuardDuty Evasion: How Attackers Go Dark
- AWS Firewall Manager and Resource Access Manager — Centralized Policy Enforcement
- Lab — Lambda Attack Chain: From API Gateway Injection to AWS Account Pivot
- AWS Organizations and Control Tower — Multi-Account Governance
- Lab — Cross-Account Role Chaining: One Compromised Account to Full Org Access
- Amazon Cognito and Verified Permissions — App Identity and Fine-Grained Authorization
- Lab — S3 Misconfiguration Deep Dive: Public Buckets, Presigned URLs, Terraform State, and Snapshot Exposure
- IAM Access Analyzer, STS, and Authorization Controls
- Lab — Kubernetes Pod Escape and IRSA Abuse: From Container to AWS Account
- AWS IAM Identity Center — SSO, Permission Sets, and Federated Access
- Lab — CI/CD Pipeline Attack: GitHub Actions Secret Theft and OIDC Hardening
- AWS Systems Manager and Network Security Controls
- Lab — IAM Privilege Escalation: 8 Paths from Low-Privilege to Admin
- AWS Secrets Manager and ACM — Credential Rotation and TLS Certificates
- AWS KMS — Key Management, Envelope Encryption, and CloudHSM
- Lab — EC2 Attack Chain: Reverse Shell, IMDS Credential Theft, and GuardDuty Detection
- AWS WAF, Shield, and Amazon Inspector — Edge Protection and Vulnerability Scanning
- Cloud Incident Response and Amazon Detective — IR Playbooks and Investigation
- AWS Security Hub and Amazon Macie — CSPM and Data Classification
- AWS CloudTrail and AWS Config — Audit Logging and Compliance
- Amazon GuardDuty — Threat Detection, Finding Types, and Automation
- AWS CodePipeline and CodeBuild — CI/CD on AWS
- Lab — GuardDuty Sample Findings: What It Actually Detects (Zero Cost, Zero Risk)
- AWS CloudFormation and CDK — Infrastructure as Code
- AWS DynamoDB — NoSQL, Keys, Indexes, Streams, and DAX
- AWS RDS and Aurora — Managed Relational Databases, Multi-AZ, and Read Replicas
- AWS EBS and EFS — Block Storage, Shared Filesystems, and FSx
- AWS S3 — Object Storage, Storage Classes, Security, and Replication
- AWS ECS and EKS — Containers, Fargate, and Managed Kubernetes
- AWS Lambda — Serverless Functions, Triggers, and Execution Model
- AWS EC2 — Instances, AMIs, Storage, Auto Scaling, and Pricing
- AWS VPC Architecture Patterns — Inbound, Outbound, and Inspection VPCs
- AWS VPC — Virtual Private Cloud Full Walkthrough
- AWS Global Infrastructure — Regions, AZs, and Edge Locations
- AWS Load Balancers — ALB, NLB, Target Groups, and Listeners
- AWS CloudFront — CDN, Distributions, Cache Policies, and Security
- AWS Route 53 — DNS, Routing Policies, and Health Checks
- AWS CLI & IAM — Credentials, Roles, Policies, and Attack Paths
- Terraform Full Walkthrough
- Phase 5: Observability & Security Hardening — CloudWatch, Secrets Manager, and Structured Logging
- Phase 4: CI/CD Pipeline with GitHub Actions — Complete Walkthrough
- Phase 3: Provisioning a 3-Tier AWS Network with Terraform — Walkthrough
- Phase 0: Setting-Up-The-Infrastructure
- Phase 0: MindCraft Overview