From the course: Complete Guide to Cybersecurity: A Practical Approach

Unlock this course with a free trial

Join today to access over 24,500 courses taught by industry experts.

Discovering cloud assets

Discovering cloud assets

- [Instructor] Let's go over how to perform reconnaissance and discover cloud assets. And one of the most important things whenever it comes to cloud asset discoveries is understanding the scope, right? Define the scope of the assessment, including cloud providers, the regions, and service, any assets involved, and make sure that you have proper authorization. And if you're participating in bug bounty, make sure that you are reading very carefully the scope statement of that bug bounty. Now, whenever you perform passive reconnaissance, of course you can gather publicly available information about a target using the tools that we already cover. Things like Shodan and Recon-ng, and many other recon tools as well. Now, whenever you perform active reconnaissance, you directly interact with the target system, in this case with AWS or Azure, or Google Cloud platform, and so on. You can use cloud specific tools like CloudMapper, ScoutSuite, or any native cloud providers tools. And I'm going…

Contents