Getting Started With Cloud Red Team
Getting Started With Cloud Red Team
● CTF Exercise
2
Module - 1 :
Hybrid Multi Cloud
Environment Overview
3
Network Architecture of On-Premise Environment
Internal Network
External Network
Domain
Web server Controller
Mail server
Workstation
4
Network Architecture of Active Directory Forest
Trust relationship
Domain 1 Domain 2
abc.com xyz.com
Tree Tree2
DC 3 DC 4 DC 5
Identity
AD Internal Network (Forest) 5
AWS Multi Accounts Architecture
AWS Organization
AWS
Master Account
6
Azure Cloud Working Model
n Au
atio Azure AD th
ntic en
tic
e at
u th ion
A
Idaas
Azure Resource
O365 / M365
Manager (ARM)
7
Azure Cloud Hierarchy
AAD Tenant
Management Group
Subscription
Resource Group
Resource
Google Cloud Working Model
n Cloud
atio
ntic Identity
e
u th
A
IdaaS
9
GCP Cloud Hierarchy
Organization Company
Shared
Dept X Dept Y Infrastructure
Folders
Team A Team B
Product 1 Product 2
AWS GCP
Azure
On-Premise to Cloud
& Cloud to On-Premise
Network Connectivity
Active Directory
On-Premise Environment
User/
Employee
11
Identity Federation from On-Premise to Cloud
OKTA|Onelogin|AAD
User 2. User
Credential SSO
Authentication
External IdP
[Source Idp]
Internal IdP
Hybrid Multi Cloud Environment Access
Primary
AWS account
AWS SSO User
Azure Subscription
Identity Sync Azure AD User
Primary
User Azure Tenant Azure Subscription
Credentials
15
AWS Cloud Architecture
Cloud Space
Compute
Data Plane
• IAM Username & Password • Long Term Key : Access Key ID & Secret
Web Client AWS CLI SDK/API • Short Term Key : Access Key ID & Secret & Token
• SSO Username & Password
End User
16
Identity and Access Management
IAM :
• AWS Identity and Access Management (IAM) enables you to manage access to AWS services and resources
securely.
• IAM allow you can create and manage AWS users and groups and use permissions to allow and deny their access to
AWS resources.
17
IAM
Policy
19
Module - 3 :
Google Cloud Overview
20
Idaas
tion Cloud
t ica Identity
hen
t
Au
Authentication
Google workspace
Google Cloud Platform
Shared
Dept X Dept Y Infrastructure
Folders
Team A Team B
Product 1 Product 2
Role 1 Role 2
e
rc
ou
Set Of Set Of
es
Permission 2
aR
Permission 1
On
ied
Project
pl
Ap
icy
l
Po
M
IA
Resource
Member 1 Member 2
Member 1
Policy Resources
IAM Role Binding - Organization Level
24
Module - 4 :
Azure Cloud Overview
25
IdAAs
t ion Azure
Au
th
t ica AD
en
h en tic
at
t io
Au n
AAD Tenant
Management
Group
Subscription
Resource
Group
Resource
27
Role Based Access Control (RBAC)
• Azure RBAC is an authorization system built on Azure Resource Manager (ARM) that provides
fine-grained access management of Azure resources.
Service
Identify
Principal (Security Principal) Subscription Subscription Subscription
Mananged
Identify
Resource Group Resource Group Resource Group Resource Group
Role Definition
[Permissions] Resource Resource Resource Resource Resource
Role Assignment on Subscription Level 30
Thank You !
In case of any difficulties or queries, feel free to mail us at
[email protected]
● Follow us on :
LinkedIn: https://www.linkedin.com/company/cyberwarfare/
Twitter: https://twitter.com/cyberwarfarelab
31
© CW Labs UK Pvt. Ltd.