0% found this document useful (0 votes)
33 views86 pages

CPENT Module 12 Cloud Penetration Testing

Uploaded by

Oleg Pelsch
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
33 views86 pages

CPENT Module 12 Cloud Penetration Testing

Uploaded by

Oleg Pelsch
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

EC-Council Certified Penetration Testing Professional

Certified Penetration Testing Professional

Methodology: Cloud Penetration Testing

Penetration Tester:
Organization:
Date: Location:

Confidential 1 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1: Cloud Penetration Testing

Test 1.1: Identify the Type of Cloud to be Tested

Target Organization
URL
Successfully Identified the Type of Cloud Service Under Test? Yes No
Identified Cloud 1.
Services to be Tested
2.
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 2 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.2: Identify What is to be Tested in the Cloud Environment

Target Organization
URL
Systems/Instances and 1.
Applications that Need to
2.
be Tested
3.
4.
5.

Successfully Identified the Systems/Instances and Applications to be Yes No


Tested?
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 3 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.3: Identify Tools for Penetration Testing

Target Organization
URL
Successfully Identified the Tools for Penetration Testing? Yes No
List of Cloud Services 1.
to be Tested
2.
3.
4.
5.

Tools used for Pen 1.


Testing the Cloud
2.
Services
3.
4.
5.

Results Analysis:

Confidential 4 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.4: Perform Cloud Reconnaissance

Target Organization
URL
Cloud Service Tested
Is Cloud Reconnaissance Successful? Yes No
Information Gathered
List of Publicly Accessible 1.
Resources
2.
3.
4.
5.

Security Groups 1.
2.
3.
4.
5.

Routing Tables, Network 1.


ACL
2.
3.
4.
5.

Subnets 1.
2.
3.
4.

Confidential 5 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Permissions 1.
2.
3.
4.
5.

Identity and Access 1.


Management (IAM)
2.
Policies
3.
4.
5.

Hardware Details 1.
2.
3.
4.
5.

Software Details 1.
2.
3.
4.
5.

Network Information 1.
2.
3.
4.
5.

Confidential 6 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Databases in Use 1.
2.
3.
4.
5.

Operating Systems in 1.
Use (include Version)
2.
3.
4.
5.

Security Flaws/ 1.
Vulnerabilities Identified
2.
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 7 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 8 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.5: Check for Lock-in Problems

Target Organization
URL
Cloud Service Tested
Impact of Lock-In on 1.
Business Services
2.
3.
4.
5.

Service Level Agreement


(SLA) between
Subscriber and Cloud
Service

Determined Provisions
to Switch Over to Other
CSPs

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 9 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 10 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.6: Check for Governance Issues

Target Organization
URL
Cloud Service Tested
Information Gathered by 1.
Checking SLA Document
2.
and Track Record of the
CSP 3.
4.
5.
6.

Roles and 1.
Responsibilities of the
2.
CSP and Subscribers in
Managing Cloud 3.
Resources
4.
5.

Any Discrepancy in SLA 1.


Clauses, Specify
2.
3.
4.
5.

Visibility of the CSP’s 1.


Audit, Certification, and
2.
Vulnerability Assessment
Processes 3.
4.
5.

Confidential 11 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Hidden Dependency to 1.
Resources Outside Cloud
2.
3.
4.
5.

Issues Related to 1.
Transparency on the
2.
Usage of Technologies
and Data Storage 3.
4.
5.

Source Escrow 1.
Agreement
2.
3.
4.
5.

Cloud Asset Ownership 1.


2.
3.
4.
5.

Any Other Issues, Specify 1.


2.
3.
4.
5.

Confidential 12 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 13 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.7: Check for Compliance Issues

Target Organization
URL
Cloud Service Tested
Is the Service Compliant with International Standards for Data Yes No
Protection Belonging to the Different Industries Served by the Client?
CSP is Regularly Audited and Certified for Compliance Issues? Yes No
Regulations CSP Complies
With
Do the Regulations Meet the Requirements of the Client? Yes No
If Responsibilities of the CSP and Subscribers in Maintaining Compliance Yes No
is Well Defined?
SLA Provides Transparency on Compliance Issues? Yes No
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 14 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.8: Check for Right Implementation of Security Management

Target Organization
URL
Cloud Service Tested
Right employee(s) with the proper knowledge is appointed to work with Yes No
cloud-based technologies?
Security, authentication, 1.
and authorization processes
2.
employees follow
3.
4.
5.

Right employee(s) with the proper knowledge is appointed to look for Yes No
cloud security?
Tools used by cloud security 1.
employees
2.
3.
4.
5.

Right set of policies and procedures are implemented to ensure cloud Yes No
security?
Policies implemented for 1.
Cloud Security
2.
3.
4.
5.

Proper security and business-continuity-process models are Yes No


implemented?

Confidential 15 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Security Assessment 1.
Processes Employed by the
2.
Company
3.
4.
5.
6.
7.
8.
9.
10.

Proper processes for handling security incidents are implemented? Yes No


Backup and disaster 1.
recovery mechanisms in use
2.
3.
4.
5.

Idle resources in reserve to 1.


support business continuity
2.
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 16 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 17 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.9: Check Cloud for Resource Isolation

Target Organization
URL
Cloud Service Tested
Does CSP provides isolation of resources in the cloud? Yes No
Methods Used to Check 1.
Cloud Resource Isolation
2.
3.
4.
5.
6.
7.
8.
9.
10.

CSP’s Client Feedback and 1.


Expert Reviews
2.
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 18 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 19 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.10: Check Whether Anti-Malware Applications are Installed and Updated on Every
Device

Target Organization
URL
Cloud Service Tested
Components of the Cloud 1.
Infrastructure
2.
3.
4.
5.
6.
7.
8.
9.

Do the Components of Cloud Infrastructure Protected Using Appropriate Yes No


Security Controls?
Anti-Malware Solutions 1.
Installed on Cloud
2.
Components
3.
4.
5.

Impact of Data Breaches 1.


on Business
2.
3.
4.
5.

Confidential 20 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 21 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.11: Check Whether Firewalls are Installed at Every Network Entry Point

Target Organization
URL
Cloud Service Tested
Firewalls Installed at Every Network Entry Point? Yes No
Effectiveness of
Firewalls in
Preventing
Transmission of
Malicious Traffic

Information 1.
Gathered from
2.
Firewall
Implementation 3.
Policy
4.
5.

Information 1.
Gathered from
2.
Firewall Logs and
Network 3.
Configuration
4.
5.

Authorized Persons 1.
having Access to
2.
Firewall
Configuration and 3.
Settings
4.
5.

Confidential 22 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Alert Mechanism 1.
Used in Firewalls
2.
3.
4.
5.

Unused Ports, 1.
Protocols, and
2.
Services
3.
4.
5.

Does the Firewall Block Unused Ports, Protocols, and Services? Yes No
Identified 1.
Vulnerabilities 2.
3.
4.
5.

6.
7.
8.
9.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 23 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 24 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.12: Check that Strong Authentication is Deployed for Every Remote User

Target Organization
URL
Cloud Service Tested
Did the cloud Service Deploy Strong Authentication for Every Remote Yes No
User?
Does the Company have a Strong Password and Authentication Policy? Yes No
OTP Used to Validate the Passwords? Yes No
Identified Vulnerabilities 1.
2.
3.
4.
5.
6.
7.
8.
9.
10.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 25 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 26 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.13: Check the SSL Certificates for Cloud Services in the URL

Target Organization
URL
Cloud Service Tested
Cloud Services Enabled for SSL Encryption? Yes No
VPN and Secure Email Services Used for Communication? Yes No
Security and Privacy 1.
Policies of the Cloud
2.
Services
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 27 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.14: Check whether Files Stored on Cloud Servers are Encrypted

Target Organization
URL
Cloud Service Tested
Is the Data Stored on Cloud Servers is Encrypted? Yes No
Encryption Algorithms 1.
Used
2.
3.
4.
5.

Cloud Service Providers or Service Users Hold the Algorithmic Keys for Yes No
the Encryption?
Employees having 1.
Access to Encryption
2.
Algorithms and Their
Keys 3.
4.
5.

Identified 1.
Vulnerabilities
2.
3.
4.
5.
6.
7.
8.
9.

Confidential 28 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 29 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.15: Check the Data Retention Policy of Service Providers

Target Organization
URL
Cloud Service Tested
Data Retention Policies of
Service Provider

Does the data retention policies meet the company’s needs and comply Yes No
with internal corporate policy?
Does the CSP perform regular backups and recovery tests? Yes No
Do the Policies Bound by the Law of the Land to Disclose the Data to Yes No
Third Parties?
Duration of Data Retention in
the Cloud
Procedures to Completely 1.
Erase the Data from the
2.
Cloud
3.
4.
5.

Data Retention in case 1.


another company acquires
2.
the service provider
3.
4.
5.

Confidential 30 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 31 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.16: Check that all Users Follow Safe Internet Practices

Target Organization
URL
Cloud Service Tested
Does the Company have a Documented Computer and Internet Usage Yes No
Policy?
Computer and Internet
Usage Policy Details

Checked the Logs and Determined whether any Employee has violated Yes No
the Policies?
If Yes, Details of Violation

Does the Policy Cover the Implementation of Security Solutions? Yes No


Security Solutions 1.
Deployed
2.
3.
4.
5.

Alert Mechanism Used in


Case of Breach of the
Policy

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 32 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 33 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.17: Perform a Detailed Vulnerability Assessment

Target Organization
URL
Cloud Service Tested
Techniques Used for 1.
Assessing Cloud
2.
Vulnerabilities
3.
4.
5.

Cloud Components 1.
Assessed for
2.
Vulnerabilities
3.
4.
5.

Identified 1.
Vulnerabilities
2.
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 34 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 35 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.18: Try to Gain Passwords to Hijack the Cloud Service

Target Organization
URL
Cloud Service Tested
Password Grabbing 1.
Techniques Used
2.
3.
4.
5.

Credentials Obtained 1.
2.
3.
4.
5.

Other Cyberattacks 1.
Performed
2.
3.
4.
5.

Sensitive Information 1.
Collected
2.
3.
4.
5.
6.

Confidential 36 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 37 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.19: Test for Virtualization Management (VM) Security

Target Organization
URL
Cloud Service Tested
Host is updated with the latest patches and regular updates? Yes No
Password used for VM OS is complex? Yes No
Any unnecessary services/programs running on the VM OS? Yes No
Host is individually firewalled? Yes No
VM host is physically secured? Yes No
File integrity checks are implemented? Yes No
Are virtual machines secured? Yes No
Identified Vulnerabilities 1.
2.
3.
4.
5.
6.
7.
8.
9.
10.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 38 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 39 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 1.20: Check Audit and Evidence-Gathering Features in the Cloud Service

Target Organization
URL
Cloud Service Tested
Does the CSP includes provisions for performing audit and gathering Yes No
evidence in case of a security incident?
Cloud Service Provider Offers Features for Cloning of Virtual Machines? Yes No
Storage Capacity Provided to
support Multiple Clones

Type of provisions CSP is 1.


providing in case of a
2.
cyberattack
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 40 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2: AWS Specific Penetration Testing

Test 2.1: Understand AWS Shared Responsibility Model

Target Organization
URL
Cloud Service Tested
AWS Shared Model
Used

Responsibility Between
AWS and the Customer

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 41 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.2: Understand AWS Penetration Testing Policy and Procedures

Target Organization
URL
Cloud Service Tested
List of Services which 1.
are Permitted
2.
3.
4.
5.

List of Activities 1.
which are Prohibited
2.
3.
4.
5.

Policies Regarding 1.
the use of Security
2.
Assessment Tools
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 42 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 43 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.3: Attempt to Identify S3 Buckets

Target Organization
URL
Cloud Service Tested
Identified S3 Bucket Successfully? Yes No
Method used Manual Method Automated Method
List the Techniques 1.
Used to Identify S3
2.
Buckets
3.
4.
5.

Domain IP Address Region Organization


1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
Tools/Services Used 1.
2.
3.
4.
5.

Confidential 44 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 45 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.4: Check for S3 Bucket Permissions

Target Organization
URL
Cloud Service Tested
Commands Used

Identified S3 Bucket Permissions Successfully? Yes No


List of Identified Permissions
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 46 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 47 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.5: Attempt to Create New Policy Version

Target Organization
URL
Cloud Service Tested
Commands Used

New Policy Version Created Successfully? Yes No


Policy Created

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 48 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.6: Attempt to Set an Existing Policy Version as Default

Target Organization
URL
Cloud Service Tested
Commands Used

Is Setting an Existing Policy Version as Default Successful? Yes No


Risk Associated with
the Permission-Levels of
Inactive Policy Versions

Selected IAM Policy

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 49 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.7: Attempt to Obtain Access to the set of EC2 Instance/Role Permissions

Target Organization
URL
Cloud Service Tested
Commands Used

Obtained Access to the Set of EC2 Instance/Role Permissions of an AWS Yes No


Account Successfully?
Permissions used to Create a
1.
New EC2 Instance
2.
3.
4.
5.

List of EC2 Metadata


1.
2.
3.
4.
5.

Retrieved AWS Keys


1.
2.
3.
4.
5.

Confidential 50 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 51 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.8: Attempt to Create a New User Access Key

Target Organization
URL
Cloud Service Tested
Commands Used

Created a New User Access Key Successfully? Yes No


New User Access key ID

New User Secret key

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 52 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 53 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.9: Attempt to Create a New Login Profile

Target Organization
URL
Cloud Service Tested
Commands Used

Created a New Login Profile Successfully? Yes No


Password for an IAM
User

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 54 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.10: Attempt to Update an Existing Login Profile

Target Organization
URL
Cloud Service Tested
Commands Used

Is it Possible to Update the Login Profile with Regular User Accounts? Yes No
Updated Username

Updated Password

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 55 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.11: Attempt to Attach a Policy to a User

Target Organization
URL
Cloud Service Tested
Commands Used

Attached a Policy to a User Successfully? Yes No


Privileges Escalated Successfully? Yes No
Attached Policy

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 56 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.12: Attempt to Attach a Policy to a Group

Target Organization
URL
Cloud Service Tested
Commands Used

Attached a Policy to a Group Successfully? Yes No


Privileges Escalated Successfully? Yes No
Attached Policy

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 57 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.13: Attempt to Attach a Policy to a Role

Target Organization
URL
Cloud Service Tested
Commands Used

Attached a Policy to a Role Successfully? Yes No


Privileges Escalated Successfully? Yes No
Attached Policy

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 58 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.14: Attempt to Create/Update an Inline Policy for a User

Target Organization
URL
Cloud Service Tested
Commands Used

Created/Updated an Inline Policy for a User Role Successfully? Yes No


Created/Updated Inline
Policy

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 59 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.15: Attempt to Create/Update an Inline Policy for a Group

Target Organization
URL
Cloud Service Tested
Commands Used

Created/Updated an Inline Policy for a Group Successfully? Yes No


Created/Updated Inline
Policy

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 60 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.16: Attempt to Create/Update an Inline Policy for a Role

Target Organization
URL
Cloud Service Tested
Commands Used

Created/Updated an Inline Policy for a Role Successfully? Yes No


Created/Updated Inline
Policy

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 61 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.17: Attempt to Add a User to a Group

Target Organization
URL
Cloud Service Tested
Commands Used

Added a User to a Group Successfully? Yes No


Privileges Escalated Successfully? Yes No
Group Name

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 62 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 2.18: Attempt to Update AssumeRolePolicyDocument of a Role

Target Organization
URL
Cloud Service Tested
Commands Used

Updated AssumeRolePolicyDocument of a Role Successfully? Yes No


Privileges Escalated Successfully? Yes No
Role Name

Policy Document File

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 63 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3: Azure Specific Penetration Testing

Test 3.1: Understand Azure’s Shared Responsibility Model

Target Organization
URL
Cloud Service Tested
Azure Shared Model
Used

Responsibilities
Between Azure and
the Customer

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 64 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.2: Understand Azure Penetration Testing Policy and Procedures

Target Organization
URL
Cloud Service Tested
Scope 1.
2.
3.
4.
5.
6.
7.
8.
9.
10.

Rules of Engagement 1.
to Perform Penetration
2.
Testing on the
Microsoft Cloud 3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 65 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 66 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.3: Assess Azure Environment with Azure Security Center

Target Organization
URL
Cloud Service Tested
Assessed Azure Environment Successfully? Yes No
Vulnerabilities Recommendations Secure Score Impact Resource
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 67 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.4: Check Assigned Role of Users

Target Organization
URL
Cloud Service Tested
Assigned Role of Users Checked Successfully? Yes No
Access Control (IAM)
Name Type Role Scope
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
Identified 1.
Misconfigurations
2.
3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 68 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 69 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.5: Check whether access to the Azure AD Portal is Restricted

Target Organization
URL
Cloud Service Tested
Is Access to the Azure AD Portal is Restricted? Yes No
Access to Azure administrative portal is Restricted? Yes No
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 70 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.6: Check whether Multi-Factor Authentication (MFA) is Enabled for Every User

Target Organization
URL
Cloud Service Tested
Multi-Factor Authentication (MFA) is Enabled for Every User? Yes No
Display Name Username Multi-Factor Auth Status
1.
2.
3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 71 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.7: Check whether WAF is installed on Microsoft Azure

Target Organization
URL
Cloud Service Tested
WAF is installed on Microsoft Azure? Yes No
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 72 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.8: Check whether Data is Encrypted at Rest

Target Organization
URL
Cloud Service Tested
Data is Encrypted at Rest? Yes No
Storage Account Encryption Status
1. Enabled Disabled
2. Enabled Disabled
3. Enabled Disabled
4. Enabled Disabled
5. Enabled Disabled
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 73 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.9: Check whether Azure SQL Databases are Encrypted

Target Organization
URL
Cloud Service Tested
SQL Databases are Encrypted? Yes No
Database Instance Data Encryption Status
1. On Off
2. On Off
3. On Off
4. On Off
5. On Off
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 74 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.10: Check the Data Retention Time in Microsoft Azure

Target Organization
URL
Cloud Service Tested
Checked Data Retention Time Successfully? Yes No
Data Retention Time

Storage Capacity

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 75 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.11: Check whether Network Security Groups Diagnostic logs are turned On

Target Organization
URL
Cloud Service Tested
NSG Diagnostic Logs Checked Successfully? Yes No
Network Security Group NSG Diagnostic logs
1. ON OFF
2. ON OFF
3. ON OFF
4. ON OFF
5. ON OFF
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 76 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.12: Check whether Azure Network Watcher is Enabled

Target Organization
URL
Cloud Service Tested
Region Network Watcher Status
1. Enabled Disabled
2. Enabled Disabled
3. Enabled Disabled
4. Enabled Disabled
5. Enabled Disabled
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 77 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 3.13: Check whether JIT VM Access is Enabled

Target Organization
URL
Cloud Service Tested
Virtual Machine JIT VM Access Status
1. Enabled Disabled
2. Enabled Disabled
3. Enabled Disabled
4. Enabled Disabled
5. Enabled Disabled
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 78 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 4: Google Cloud Platform Specific Penetration Testing

Test 4.1: Understand Google Cloud Shared Responsibility Model

Target Organization
URL
Cloud Service Tested
Google Cloud Shared
Model Used

Responsibilities
Between Google and
the Customer

Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 79 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 4.2: Google Cloud’s Provision for Penetration Testing

Target Organization
URL
Cloud Service Tested
Scope 1.
2.
3.
4.
5.
6.
7.
8.
9.
10.

Rules of Engagement 1.
to Perform Penetration
2.
Testing on the Google
Cloud 3.
4.
5.

Tools/Services Used 1.
2.
3.
4.
5.

Confidential 80 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Results Analysis:

Confidential 81 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 4.3: Check whether Security Health Analytics is Enabled

Target Organization
URL
Cloud Service Tested
Status of Security Health
Enabled Disabled
Analytics
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 82 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 4.4: Check whether Cloud Web Security Scanner is Enabled

Target Organization
URL
Cloud Service Tested
Status of Cloud Web
Enabled Disabled
Security Scanner
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 83 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 4.5: Check whether Cloud Anomaly Detection is Enabled

Target Organization
URL
Cloud Service Tested
Status of Cloud Anomaly
Enabled Disabled
Detection
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 84 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 4.6: Check whether Container Threat Detection is Enabled

Target Organization
URL
Cloud Service Tested
Status of Container Threat
Enabled Disabled
Detection
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 85 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.
EC-Council Certified Penetration Testing Professional

Test 4.7: Check whether Event Threat Detection is Enabled

Target Organization
URL
Cloud Service Tested
Status of Event Threat
Enabled Disabled
Detection
Tools/Services Used 1.
2.
3.
4.
5.

Results Analysis:

Confidential 86 CPENT Template Copyright © by EC-Council


All Rights Reserved. Reproduction is Strictly Prohibited.

You might also like