AI-powered
podcast player
Listen to all your favourite podcasts with AI-powered features
Cloud Security Pentest is not just a Cloud configuration review ! Blackhat 2023 & Defcon 31 conversations included Cloud Security Podcast asking traditional and experienced pentesters about their opinion on cloud security pentesting and the divide was between it being a config review or a product pentest. For this episode we have Seth Art from Bishop Fox to clarify the myth.
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Seth Art's Linkedin (Seth Art Linkedin)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Newsletter
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction
(05:17) A bit about Seth Art
(06:44) Network vs Infrastructure Security Pentest
(08:00) Internal vs External Network Security Pentest
(10:26) Assumed vs Objective Based Pentest
(12:51) Is network pentest dead?
(14:04) How to approach network and cloud pentests?
(20:12) Cloud pentest is more than config review
(24:04) Examples of cloud pentest findings
(30:07) Scaling pentests in cloud
(32:25) Traditional skillsets to cloud pentest
(36:58) A bit about cloudfoxable
(39:31) Cloud pentest and Zero Trust
(40:54) Staying ahead of CSP releases
(44:31) Third party shared responsibility
(47:35) 1 fun question
(48:36) Boundary for cloud pentest
(52:21) Last 2 fun questions
These are some of the resources that Seth shared during the episode along with the tools he has created
See you at the next episode!