SlideShare a Scribd company logo
Cloud Assessments
Aakash Goel & Ankit Arora
Security Compass
Reality Check.
Cloud is real.
• Net worth of software market affected by cloud
computing - US$384 billion1 and growing.
• Bridging the cost-computing gap
• Automation
• Agility
• Disaster Recovery
• Centralised Control
• Visibility
Industry
Leaders
Shared Responsibility Model
Customer -
Security ‘in’
the cloud
Provider -
Security ‘of’
the cloud
Cloud Pentest
Configurations Access Control
Sensitive data
at rest
Log Visibility
What to look at
Knowing what services you
have running
01
Knowing what resources
those services create, are
they making instances,
endpoints, other things.
What are the default
configurations of those
resources.
02
Making sure you are testing
the right thing. Testing the
authentication checks.
something like API Gateway
enforces is a fruitless
endeavour and you are less
testing your actual code
than you are cloud.
03
Automated
Tools
AWS Trusted Advisor
AWS Config
Scout2
Prowler
Security Monkey
Cloud Custodian
CloudSploit
AWS vs GCP
vs Azure
Security Views
Technical Jargons
Tooling
Flaws Challenge
http://flaws.cloud
We’re hiring
Associates -
https://grnh.se/f5j5jxo51
Consultants -
https://grnh.se/a0xc7kv41
Seniors -
https://grnh.se/ix4fx2is1

More Related Content

PDF
Using Splunk or ELK for Auditing AWS/GCP/Azure Security posture
CloudVillage
 
PPTX
AWS ReInvent 2020: SEC313 - A security operator’s guide to practical AWS Clou...
Brian Andrzejewski
 
PPTX
Securing AWS environments by Ankit Giri
OWASP Delhi
 
PPTX
How to implement DevSecOps on AWS for startups
Aleksandr Maklakov
 
PPTX
Security Operations in the Cloud
Armor
 
KEY
AWS Security: A Practitioner's Perspective
Jason Chan
 
PPTX
CSS17: DC - The AWS Shared Responsibility Model in Practice
Alert Logic
 
PDF
AWS Cloud Governance & Security through Automation - Atlanta AWS Builders
James Strong
 
Using Splunk or ELK for Auditing AWS/GCP/Azure Security posture
CloudVillage
 
AWS ReInvent 2020: SEC313 - A security operator’s guide to practical AWS Clou...
Brian Andrzejewski
 
Securing AWS environments by Ankit Giri
OWASP Delhi
 
How to implement DevSecOps on AWS for startups
Aleksandr Maklakov
 
Security Operations in the Cloud
Armor
 
AWS Security: A Practitioner's Perspective
Jason Chan
 
CSS17: DC - The AWS Shared Responsibility Model in Practice
Alert Logic
 
AWS Cloud Governance & Security through Automation - Atlanta AWS Builders
James Strong
 

Similar to Cloud assessments by :- Aakash Goel (20)

PDF
Using Splunk/ELK for auditing AWS/GCP/Azure security posture
Jose Hernandez
 
PDF
Cloud Security Assessment Guide: Ensuring Robust Protection for Your Cloud En...
unicloudm
 
PPTX
Cloud computing and Cloud security fundamentals
Viresh Suri
 
PDF
The 3 Recommendations for Cloud Security
VAST
 
PDF
Practical Cloud Security A Guide For Secure Design And Deployment 1st Edition...
jaromdembo
 
PDF
Cloudbusting insights #2 first steps of cloud security
Daniel Tovey
 
PDF
Cloud Computing Security
Arunvignesh Venkatesh
 
PPT
Cloud Computing Security Issues
Discover Cloud Computing
 
PDF
AWS November meetup Slides
JacksonMorgan9
 
PDF
AWS User Group November
PolarSeven Pty Ltd
 
PDF
Security Considerations When Using Cloud Infrastructure Services.pdf
Ciente
 
PDF
Presentation on Cloud Security 101 - 2024
Sanjeev Kumar Jaiswal
 
PPTX
Cloud Security Zen: Principles to Meditate On
Samuel Reed
 
PDF
Enterprise Cloud Governance: A Frictionless Approach
RightScale
 
PDF
AWS Architecture Fundamentals - Denver
Nicole Maus
 
PPTX
Cloud Achitecture and Security.pptx
IssahakukuwereJalilu
 
PDF
How Secure Is Cloud
William Lam
 
PDF
Reality Check: Security in the Cloud
Alert Logic
 
PDF
Peering Through the Cloud Forrester EMEA 2010
graywilliams
 
PPTX
Isaca cloud security presentation duncan unwin 16 jul13
Duncan Unwin
 
Using Splunk/ELK for auditing AWS/GCP/Azure security posture
Jose Hernandez
 
Cloud Security Assessment Guide: Ensuring Robust Protection for Your Cloud En...
unicloudm
 
Cloud computing and Cloud security fundamentals
Viresh Suri
 
The 3 Recommendations for Cloud Security
VAST
 
Practical Cloud Security A Guide For Secure Design And Deployment 1st Edition...
jaromdembo
 
Cloudbusting insights #2 first steps of cloud security
Daniel Tovey
 
Cloud Computing Security
Arunvignesh Venkatesh
 
Cloud Computing Security Issues
Discover Cloud Computing
 
AWS November meetup Slides
JacksonMorgan9
 
AWS User Group November
PolarSeven Pty Ltd
 
Security Considerations When Using Cloud Infrastructure Services.pdf
Ciente
 
Presentation on Cloud Security 101 - 2024
Sanjeev Kumar Jaiswal
 
Cloud Security Zen: Principles to Meditate On
Samuel Reed
 
Enterprise Cloud Governance: A Frictionless Approach
RightScale
 
AWS Architecture Fundamentals - Denver
Nicole Maus
 
Cloud Achitecture and Security.pptx
IssahakukuwereJalilu
 
How Secure Is Cloud
William Lam
 
Reality Check: Security in the Cloud
Alert Logic
 
Peering Through the Cloud Forrester EMEA 2010
graywilliams
 
Isaca cloud security presentation duncan unwin 16 jul13
Duncan Unwin
 
Ad

More from OWASP Delhi (20)

PDF
Getting Started With Hacking Android & iOS Apps? Tools, Techniques and resources
OWASP Delhi
 
PDF
Securing dns records from subdomain takeover
OWASP Delhi
 
PDF
Effective Cyber Security Report Writing
OWASP Delhi
 
PPTX
Data sniffing over Air Gap
OWASP Delhi
 
PPTX
UDP Hunter
OWASP Delhi
 
PDF
Demystifying Container Escapes
OWASP Delhi
 
PPTX
Automating WAF using Terraform
OWASP Delhi
 
PPTX
Actionable Threat Intelligence
OWASP Delhi
 
PDF
Threat hunting 101 by Sandeep Singh
OWASP Delhi
 
PPTX
Owasp top 10 vulnerabilities
OWASP Delhi
 
PPTX
Recon with Nmap
OWASP Delhi
 
PDF
DMARC Overview
OWASP Delhi
 
PDF
Pentesting Rest API's by :- Gaurang Bhatnagar
OWASP Delhi
 
ODP
Wireless security beyond password cracking by Mohit Ranjan
OWASP Delhi
 
PDF
IETF's Role and Mandate in Internet Governance by Mohit Batra
OWASP Delhi
 
PDF
Malicious Hypervisor - Virtualization in Shellcodes by Adhokshaj Mishra
OWASP Delhi
 
PPTX
ICS Security 101 by Sandeep Singh
OWASP Delhi
 
PDF
Thwarting The Surveillance in Online Communication by Adhokshaj Mishra
OWASP Delhi
 
ODP
Hostile Subdomain Takeover by Ankit Prateek
OWASP Delhi
 
PDF
DFIR using Docker Containers by Deep Shankar Yadav
OWASP Delhi
 
Getting Started With Hacking Android & iOS Apps? Tools, Techniques and resources
OWASP Delhi
 
Securing dns records from subdomain takeover
OWASP Delhi
 
Effective Cyber Security Report Writing
OWASP Delhi
 
Data sniffing over Air Gap
OWASP Delhi
 
UDP Hunter
OWASP Delhi
 
Demystifying Container Escapes
OWASP Delhi
 
Automating WAF using Terraform
OWASP Delhi
 
Actionable Threat Intelligence
OWASP Delhi
 
Threat hunting 101 by Sandeep Singh
OWASP Delhi
 
Owasp top 10 vulnerabilities
OWASP Delhi
 
Recon with Nmap
OWASP Delhi
 
DMARC Overview
OWASP Delhi
 
Pentesting Rest API's by :- Gaurang Bhatnagar
OWASP Delhi
 
Wireless security beyond password cracking by Mohit Ranjan
OWASP Delhi
 
IETF's Role and Mandate in Internet Governance by Mohit Batra
OWASP Delhi
 
Malicious Hypervisor - Virtualization in Shellcodes by Adhokshaj Mishra
OWASP Delhi
 
ICS Security 101 by Sandeep Singh
OWASP Delhi
 
Thwarting The Surveillance in Online Communication by Adhokshaj Mishra
OWASP Delhi
 
Hostile Subdomain Takeover by Ankit Prateek
OWASP Delhi
 
DFIR using Docker Containers by Deep Shankar Yadav
OWASP Delhi
 
Ad

Recently uploaded (20)

PPTX
ppt lighfrsefsefesfesfsefsefsefsefserrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrt.pptx
atharvawafgaonkar
 
PPTX
AI ad its imp i military life read it ag
ShwetaBharti31
 
PPTX
Different Generation Of Computers .pptx
divcoder9507
 
PPTX
Slides Powerpoint: Eco Economic Epochs.pptx
Steven McGee
 
PPT
Transformaciones de las funciones elementales.ppt
rirosel211
 
PPTX
The Internet of Things (IoT) refers to a vast network of interconnected devic...
chethana8182
 
PPTX
dns domain name system history work.pptx
MUHAMMADKAVISHSHABAN
 
PPTX
Blue and Dark Blue Modern Technology Presentation.pptx
ap177979
 
PDF
KIPER4D situs Exclusive Game dari server Star Gaming Asia
hokimamad0
 
PDF
KIPER4D situs Exclusive Game dari server Star Gaming Asia
hokimamad0
 
PDF
LOGENVIDAD DANNYFGRETRRTTRRRTRRRRRRRRR.pdf
juan456ytpro
 
PPTX
The Internet of Things (IoT) refers to a vast network of interconnected devic...
chethana8182
 
PPTX
LESSON-2-Roles-of-ICT-in-Teaching-for-learning_123922 (1).pptx
renavieramopiquero
 
PDF
BGP Security Best Practices that Matter, presented at PHNOG 2025
APNIC
 
PDF
DNSSEC Made Easy, presented at PHNOG 2025
APNIC
 
PPTX
Black Yellow Modern Minimalist Elegant Presentation.pptx
nothisispatrickduhh
 
PPTX
B2B_Ecommerce_Internship_Simranpreet.pptx
LipakshiJindal
 
PPTX
Unlocking Hope : How Crypto Recovery Services Can Reclaim Your Lost Funds
lionsgate network
 
PDF
KIPER4D situs Exclusive Game dari server Star Gaming Asia
hokimamad0
 
PPTX
Artificial-Intelligence-in-Daily-Life (2).pptx
nidhigoswami335
 
ppt lighfrsefsefesfesfsefsefsefsefserrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrt.pptx
atharvawafgaonkar
 
AI ad its imp i military life read it ag
ShwetaBharti31
 
Different Generation Of Computers .pptx
divcoder9507
 
Slides Powerpoint: Eco Economic Epochs.pptx
Steven McGee
 
Transformaciones de las funciones elementales.ppt
rirosel211
 
The Internet of Things (IoT) refers to a vast network of interconnected devic...
chethana8182
 
dns domain name system history work.pptx
MUHAMMADKAVISHSHABAN
 
Blue and Dark Blue Modern Technology Presentation.pptx
ap177979
 
KIPER4D situs Exclusive Game dari server Star Gaming Asia
hokimamad0
 
KIPER4D situs Exclusive Game dari server Star Gaming Asia
hokimamad0
 
LOGENVIDAD DANNYFGRETRRTTRRRTRRRRRRRRR.pdf
juan456ytpro
 
The Internet of Things (IoT) refers to a vast network of interconnected devic...
chethana8182
 
LESSON-2-Roles-of-ICT-in-Teaching-for-learning_123922 (1).pptx
renavieramopiquero
 
BGP Security Best Practices that Matter, presented at PHNOG 2025
APNIC
 
DNSSEC Made Easy, presented at PHNOG 2025
APNIC
 
Black Yellow Modern Minimalist Elegant Presentation.pptx
nothisispatrickduhh
 
B2B_Ecommerce_Internship_Simranpreet.pptx
LipakshiJindal
 
Unlocking Hope : How Crypto Recovery Services Can Reclaim Your Lost Funds
lionsgate network
 
KIPER4D situs Exclusive Game dari server Star Gaming Asia
hokimamad0
 
Artificial-Intelligence-in-Daily-Life (2).pptx
nidhigoswami335
 

Cloud assessments by :- Aakash Goel