CloudFormation bajo la mirada de un atacante
- Date:
- Thursday, September 17, 2026
- Time:
- 2pm ET / 7pm BST
In this fully hands-on, offensive-focused cloud security workshop, participants will start with limited IAM permissions and learn how to identify and exploit misconfigured CloudFormation execution roles by abusing iam:PassRoleservice roles and Lambda-backed Custom Resources. Throughout the lab, they will use CloudFormation templates as an offensive tool to establish persistence mechanisms within specific IAM paths , without requiring direct administrative privileges.
The workshop delves into realistic attack routes against AWS environments, the abuse of delegated execution models, and the risks introduced by automation processes with excessive permissions. Attendees will understand how functionality designed to facilitate infrastructure deployment can become a powerful vector for privilege escalation and persistence when proper controls are not implemented.