Scoping
One of the most important aspects of an AWS pentest (or any type of pentest, really) is determining the scope of the engagement. AWS engagements are difficult to scope in the sense of traditional scoping methods, such as the number of IP addresses, number of users, size of the web application, and so on. It requires a little bit of a more personal touch, because, sure, almost regardless of the size, we could just run some scanners and call it a day, but that's not what pentesting is all about and it will reflect poorly on your own company if this is how you take care of things. Lots of manual effort needs to go into an AWS pentest to really dig deep and find the vulnerabilities that are there, so it is important to scope appropriately ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access