Rhino Security Labs

Strategic Blog

CloudGoat Official Walkthrough Series: ‘glue_privesc’

John De Armas

CloudGoat is Rhino Security Labs’s tool for deploying “vulnerable by design” AWS infrastructure. This blog post will walk through one of the newest CloudGoat scenarios, glue_privesc. where you will attempt to move through an AWS…

Working-As-Intended:
RCE to IAM Privilege Escalation in GCP Cloud Build

The Capital One Breach
& “cloud_breach_s3” CloudGoat Scenario

Escalating AWS IAM Privileges with an
Undocumented CodeStar API

Spencer Gietzen

There are an extensive amount of individual APIs available on AWS, which also means there are many ways to misconfigure permissions to those APIs. These misconfigurations can give attackers the ability to abuse APIs to gain more privileges…