Rhino Security Labs

Strategic & Technical Blog

CloudGoat Official Walkthrough Series: ‘glue_privesc’

John De Armas

CloudGoat is Rhino Security Labs’s tool for deploying “vulnerable by design” AWS infrastructure. This blog post will walk through one of the newest CloudGoat scenarios, glue_privesc. where you will attempt to move through an AWS…

CloudGoat detection_evasion Scenario:
Avoiding AWS Security Detection and Response

CloudGoat goes Serverless:
A walkthrough of Vulnerable Lambda Functions

Cloud Malware:
Resource Injection in CloudFormation Templates

Ryan Gerstenkorn

As a process, CloudFormation deployments are modular, with the template upload being a distinct step from the deployment itself. Templates can be made through the web console or through 3rd party tools, but as CloudFormation is an AWS-…