Azure Cloud Security Pentesting Skills

Karl Fosaaen the author of Penetration Testing Azure for Ethical Hacker and is the VP of Research at NetSPI came as a guest to share why the penetration Test of a Web Application hosted on Azure Cloud in 2023 is quite different to just a simple/traditional web app pentesting. Cloud Penetration testing is misunderstood to be just config review in Microsoft Azure Cloud. In this video, we have Karl Fosaaen was kind enough to answer the following questions and methods. Questions: 00:00 Introduction 02:32 A bit about Karl Fosaaen 03:26 How is pentesting in Azure different from AWS? 04:35 Cloud pentesting is not just config review 05:42 Cloud pentesting vs Network pentesting 06:25 Cloud Pentest - Next evolution of Network Pentest? 07:14 Boundaries of cloud pentesting 09:07 Do you need prior approval for Azure Pentest? 09:32 Working with Microsoft Security Research Centre 10:35 Process of pentesting in Azure 11:57 Low hanging fruits to start off with! 13:37 How to persist and escalate? 14:58 Managed Identities in Azure 16:23 Impact of peripheral services to Azure 18:33 Scale of deployments in Azure 21:02 Getting access to permissions for Azure Entra 22:36 Scaling your pentest tools 23:34 TTPs or Matrix you can use 25:30 Getting into Azure Pentesting 26:56 Transitioning from network to azure pentesting 28:37 Connect with Karl Resources: ⁠The NetSPI Blog to learn more about offensive cloud security ⁠ - https://www.netspi.com/blog/technical/ ⁠Mitre - Cloud Attack Matrix⁠ - https://attack.mitre.org/matrices/ent... ⁠ATRM ⁠- https://microsoft.github.io/Azure-Thr... Karl's Book - ⁠Penetration Testing Azure for Ethical Hackers: Develop practical skills to perform pentesting and risk assessment of Microsoft Azure environments ⁠ - https://www.amazon.co.uk/Penetration-... -------------------------------------------------------------------------------- 📱Cloud Security Podcast Social Media📱 _____________________________________ Twitter:   / cloudsecpod   Facebook:   / cloudsecuritypodcast   LinkedIn:   / cloud-security-podcast   Website: https://cloudsecuritypodcast.tv/ #cloudsecurity

Solving Prompt Injection & Shadow AI for AI Malware
▶︎

Solving Prompt Injection & Shadow AI for AI Malware

Compliance in AWS for BEGINNERS - Cloud Security Meetup
▶︎

Compliance in AWS for BEGINNERS - Cloud Security Meetup

Building Reproducible Pipelines in R | Will Landau | Data Science Hangout
▶︎

Building Reproducible Pipelines in R | Will Landau | Data Science Hangout

EDITED EDITION — Getting Started in Pentesting The Cloud–Azure | Beau Bullock | 1-Hour
▶︎

EDITED EDITION — Getting Started in Pentesting The Cloud–Azure | Beau Bullock | 1-Hour

How Claude Mythos Changes Vulnerability Management: From CVSS to Exploitability
▶︎

How Claude Mythos Changes Vulnerability Management: From CVSS to Exploitability

How the Mercatus Center Plays the Long Game
▶︎

How the Mercatus Center Plays the Long Game

ChaosDB: How We Hacked Databases of Thousands of Azure Customers (rev)
▶︎

ChaosDB: How We Hacked Databases of Thousands of Azure Customers (rev)

AZ-900 Microsoft Azure Fundamentals (Full Course 2026) -Become a Cloud Engineer
▶︎

AZ-900 Microsoft Azure Fundamentals (Full Course 2026) -Become a Cloud Engineer

35C3 -  Du kannst alles hacken – du darfst dich nur nicht erwischen lassen.
▶︎

35C3 - Du kannst alles hacken – du darfst dich nur nicht erwischen lassen.

The Zero-Day Clock: How AI Shrank Exploit Times from Months to Hours
▶︎

The Zero-Day Clock: How AI Shrank Exploit Times from Months to Hours

Native Cloud Firewalls Falling Short in a Multicloud World
▶︎

Native Cloud Firewalls Falling Short in a Multicloud World

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

The Invisible Prompt Injection Hack & AI’s "Fire Triangle"
▶︎

The Invisible Prompt Injection Hack & AI’s "Fire Triangle"

Introduction To Azure Penetration Testing by Nikhil Mittal
▶︎

Introduction To Azure Penetration Testing by Nikhil Mittal

Will AI Replace Application Security? Navigating the New SDLC
▶︎

Will AI Replace Application Security? Navigating the New SDLC

How to Hide in Plain Sight: Next-Level Digital Privacy | Ivan Banov at BSidesCache 2025
▶︎

How to Hide in Plain Sight: Next-Level Digital Privacy | Ivan Banov at BSidesCache 2025

Why Legacy DLP Failed & The Rise of the Enterprise Browser
▶︎

Why Legacy DLP Failed & The Rise of the Enterprise Browser

Cybersecurity Architecture: Who Are You? Identity and Access Management
▶︎

Cybersecurity Architecture: Who Are You? Identity and Access Management

Leading in the Age of AI: A Conversation with NVIDIA CEO Jensen Huang | Global Conference 2026
▶︎

Leading in the Age of AI: A Conversation with NVIDIA CEO Jensen Huang | Global Conference 2026

Attacking and Defending Azure with BloodHound | Andy Robbins | WWHF San Diego 2022
▶︎

Attacking and Defending Azure with BloodHound | Andy Robbins | WWHF San Diego 2022