CCES | Certified Cloud Exploitation Specialist
Find the one permission that unlocks the entire cloud.
CCES teaches you to discover, exploit, and connect weaknesses across AWS, Azure, GCP, containers, and cloud-native pipelines—then explain the full business impact with evidence.
You can reason through the cloud like an attacker.
Cloud compromises rarely depend on one dramatic vulnerability. They happen when identities, permissions, trust relationships, metadata, workloads, and secrets combine into an attack path. CCES trains you to find that path and prove its impact.
Map the Environment
Enumerate identities, policies, services, storage, compute, networks, and trust relationships without losing sight of the objective.
Chain the Weaknesses
Connect overlooked permissions, exposed credentials, and cloud-native features into meaningful privilege and lateral movement.
Explain the Risk
Translate technical access into affected data, operational exposure, persistence, and clear remediation priorities.
Exploit the mistakes companies make in production.
The training moves beyond service definitions and places you inside realistic cloud attack scenarios. You will use consoles, CLIs, policy documents, and offensive tooling to uncover paths that are easy to miss and dangerous to ignore.
AWS Identity Attacks
Abuse IAM policies, PassRole, Lambda permissions, EC2 instance profiles, metadata credentials, and cross-account trust.
Azure & Entra Exploitation
Investigate service principals, OAuth tokens, RBAC gaps, managed identities, storage access, and Key Vault secrets.
GCP Attack Paths
Enumerate IAM and service accounts, abuse workload identity, inspect metadata, and exploit compute, Cloud Run, and storage.
Containers & Kubernetes
Exploit Docker sockets, weak Kubernetes RBAC, service-account tokens, Kubelet and etcd exposure, and pod-to-node paths.
Cloud-Native Pipelines
Trace secrets through repositories, CI/CD systems, Terraform state, serverless functions, API gateways, and deployment workflows.
Posture & Assessment
Use assessment tooling, validate findings manually, map risk to recognized benchmarks, and distinguish exposure from exploitability.
From one exposed secret to account-level impact.
The labs teach a repeatable workflow you can carry into a real cloud assessment—not a list of provider-specific tricks you forget after the exam.
Discover
Map assets, identities, endpoints, public storage, and exposed configuration.
Enumerate
Read policies and trust relationships to identify viable attack paths.
Escalate
Turn limited credentials into stronger roles, identities, or workload access.
Pivot
Move across accounts, subscriptions, projects, containers, and services.
Report
Capture evidence, rate risk, and deliver prioritized remediation guidance.
Real decisions inside controlled environments.
Provider-Specific Foundations
Learn the identity and resource models that make AWS, Azure, and GCP different—from an attacker’s perspective.
Isolated Cloud Scenarios
Work in purpose-built environments where experimentation is safe, evidence is repeatable, and every weakness has context.
Progressive Attack Chains
Move from focused permission abuse into multi-stage compromise involving compute, storage, secrets, and workloads.
Capstone Readiness
Practice full enumeration, exploitation, evidence capture, risk rating, and reporting before the independent final practical.
The Final Multi-Cloud Capstone
Enter a sandboxed enterprise cloud environment with intentional weaknesses across identity, storage, compute, networking, secrets, and container workloads. No checklist tells you which path matters—you must discover, exploit, validate, and document it.
Learn to see the attack path hidden inside the cloud.
Build the methodology, technical confidence, and reporting discipline needed for modern cloud penetration testing.
Start CCES — $400Includes one complimentary exam retake. Additional retakes are $150.