CCES | Certified Cloud Exploitation Specialist

Cloud Offensive Security

Find the one permission that unlocks the entire cloud.

CCES teaches you to discover, exploit, and connect weaknesses across AWS, Azure, GCP, containers, and cloud-native pipelines—then explain the full business impact with evidence.

50+ Hours On-DemandIntermediate → AdvancedLifetime AccessSeven-Day Practical
ATTACK PATH ACTIVEMULTI-CLOUD / 07
Leaked Access KeyInitial foothold discovered
EXPOSED
PassRole → LambdaPrivilege escalation path
HIGH
Workload IdentityContainer-to-cloud pivot
CRITICAL
Attack chain: credential discovery → policy analysis → privilege escalation → secrets access → persistence
What CCES Proves

You can reason through the cloud like an attacker.

Cloud compromises rarely depend on one dramatic vulnerability. They happen when identities, permissions, trust relationships, metadata, workloads, and secrets combine into an attack path. CCES trains you to find that path and prove its impact.

01

Map the Environment

Enumerate identities, policies, services, storage, compute, networks, and trust relationships without losing sight of the objective.

02

Chain the Weaknesses

Connect overlooked permissions, exposed credentials, and cloud-native features into meaningful privilege and lateral movement.

03

Explain the Risk

Translate technical access into affected data, operational exposure, persistence, and clear remediation priorities.

Inside the Multi-Cloud Range

Exploit the mistakes companies make in production.

The training moves beyond service definitions and places you inside realistic cloud attack scenarios. You will use consoles, CLIs, policy documents, and offensive tooling to uncover paths that are easy to miss and dangerous to ignore.

AW

AWS Identity Attacks

Abuse IAM policies, PassRole, Lambda permissions, EC2 instance profiles, metadata credentials, and cross-account trust.

IAMPASSROLEIMDS
AZ

Azure & Entra Exploitation

Investigate service principals, OAuth tokens, RBAC gaps, managed identities, storage access, and Key Vault secrets.

ENTRA IDRBACKEY VAULT
GC

GCP Attack Paths

Enumerate IAM and service accounts, abuse workload identity, inspect metadata, and exploit compute, Cloud Run, and storage.

GCP IAMGCEGCS
K8

Containers & Kubernetes

Exploit Docker sockets, weak Kubernetes RBAC, service-account tokens, Kubelet and etcd exposure, and pod-to-node paths.

DOCKERKUBERNETESETCD
CI

Cloud-Native Pipelines

Trace secrets through repositories, CI/CD systems, Terraform state, serverless functions, API gateways, and deployment workflows.

CI/CDTERRAFORMSECRETS
CS

Posture & Assessment

Use assessment tooling, validate findings manually, map risk to recognized benchmarks, and distinguish exposure from exploitability.

PROWLERCSPMCIS
The Cloud Attack Journey

From one exposed secret to account-level impact.

The labs teach a repeatable workflow you can carry into a real cloud assessment—not a list of provider-specific tricks you forget after the exam.

PHASE 01

Discover

Map assets, identities, endpoints, public storage, and exposed configuration.

PHASE 02

Enumerate

Read policies and trust relationships to identify viable attack paths.

PHASE 03

Escalate

Turn limited credentials into stronger roles, identities, or workload access.

PHASE 04

Pivot

Move across accounts, subscriptions, projects, containers, and services.

PHASE 05

Report

Capture evidence, rate risk, and deliver prioritized remediation guidance.

How the Labs Build Skill

Real decisions inside controlled environments.

01

Provider-Specific Foundations

Learn the identity and resource models that make AWS, Azure, and GCP different—from an attacker’s perspective.

02

Isolated Cloud Scenarios

Work in purpose-built environments where experimentation is safe, evidence is repeatable, and every weakness has context.

03

Progressive Attack Chains

Move from focused permission abuse into multi-stage compromise involving compute, storage, secrets, and workloads.

04

Capstone Readiness

Practice full enumeration, exploitation, evidence capture, risk rating, and reporting before the independent final practical.

Seven-Day Practical Exam

The Final Multi-Cloud Capstone

Enter a sandboxed enterprise cloud environment with intentional weaknesses across identity, storage, compute, networking, secrets, and container workloads. No checklist tells you which path matters—you must discover, exploit, validate, and document it.

Enumerate cloud-hosted assets
Exploit storage exposure
Escalate IAM privileges
Access protected secrets
Compromise workloads
Establish persistence
Capture defensible evidence
Deliver the assessment report
50+ HoursOn-demand training
LifetimeCourse access
7 DaysPractical exam
1 FreeExam retake
$400One-time enrollment
Ready to Think Beyond the Perimeter?

Learn to see the attack path hidden inside the cloud.

Build the methodology, technical confidence, and reporting discipline needed for modern cloud penetration testing.

Start CCES — $400

Includes one complimentary exam retake. Additional retakes are $150.