Weaponizing CloudFormation
- Date:
- Tuesday, September 15, 2026
- Time:
- 2pm ET / 7pm BST
In this fully hands-on offensive cloud security workshop, attendees will start with limited IAM permissions and learn to identify and exploit misconfigured CloudFormation execution roles using iam:PassRole, service roles, and Lambda-backed Custom Resources. Participants will weaponize CloudFormation templates to build persistence inside service-scoped IAM paths without needing direct administrative access.
The workshop digs into realistic cloud attack paths, delegated execution abuse, and the risks introduced by over-permissioned automation.