Azure Cloud Security Pentesting Skills
Karl Fosaaen the author of Penetration Testing Azure for Ethical Hacker and is the VP of Research at NetSPI came as a guest to share why the penetration Test of a Web Application hosted on Azure Cloud in 2023 is quite different to just a simple/traditional web app pentesting. Cloud Penetration testing is misunderstood to be just config review in Microsoft Azure Cloud. In this video, we have Karl Fosaaen was kind enough to answer the following questions and methods. Questions: 00:00 Introduction 02:32 A bit about Karl Fosaaen 03:26 How is pentesting in Azure different from AWS? 04:35 Cloud pentesting is not just config review 05:42 Cloud pentesting vs Network pentesting 06:25 Cloud Pentest - Next evolution of Network Pentest? 07:14 Boundaries of cloud pentesting 09:07 Do you need prior approval for Azure Pentest? 09:32 Working with Microsoft Security Research Centre 10:35 Process of pentesting in Azure 11:57 Low hanging fruits to start off with! 13:37 How to persist and escalate? 14:58 Managed Identities in Azure 16:23 Impact of peripheral services to Azure 18:33 Scale of deployments in Azure 21:02 Getting access to permissions for Azure Entra 22:36 Scaling your pentest tools 23:34 TTPs or Matrix you can use 25:30 Getting into Azure Pentesting 26:56 Transitioning from network to azure pentesting 28:37 Connect with Karl Resources: The NetSPI Blog to learn more about offensive cloud security - https://www.netspi.com/blog/technical/ Mitre - Cloud Attack Matrix - https://attack.mitre.org/matrices/ent... ATRM - https://microsoft.github.io/Azure-Thr... Karl's Book - Penetration Testing Azure for Ethical Hackers: Develop practical skills to perform pentesting and risk assessment of Microsoft Azure environments - https://www.amazon.co.uk/Penetration-... -------------------------------------------------------------------------------- 📱Cloud Security Podcast Social Media📱 _____________________________________ Twitter: / cloudsecpod Facebook: / cloudsecuritypodcast LinkedIn: / cloud-security-podcast Website: https://cloudsecuritypodcast.tv/ #cloudsecurity

Solving Prompt Injection & Shadow AI for AI Malware

Compliance in AWS for BEGINNERS - Cloud Security Meetup

Building Reproducible Pipelines in R | Will Landau | Data Science Hangout

EDITED EDITION — Getting Started in Pentesting The Cloud–Azure | Beau Bullock | 1-Hour

How Claude Mythos Changes Vulnerability Management: From CVSS to Exploitability

How the Mercatus Center Plays the Long Game

ChaosDB: How We Hacked Databases of Thousands of Azure Customers (rev)

AZ-900 Microsoft Azure Fundamentals (Full Course 2026) -Become a Cloud Engineer

35C3 - Du kannst alles hacken – du darfst dich nur nicht erwischen lassen.

The Zero-Day Clock: How AI Shrank Exploit Times from Months to Hours

Native Cloud Firewalls Falling Short in a Multicloud World

Attacking AI - Jason Haddix - NDC Security 2026

The Invisible Prompt Injection Hack & AI’s "Fire Triangle"

Introduction To Azure Penetration Testing by Nikhil Mittal

Will AI Replace Application Security? Navigating the New SDLC

How to Hide in Plain Sight: Next-Level Digital Privacy | Ivan Banov at BSidesCache 2025

Why Legacy DLP Failed & The Rise of the Enterprise Browser

Cybersecurity Architecture: Who Are You? Identity and Access Management

Leading in the Age of AI: A Conversation with NVIDIA CEO Jensen Huang | Global Conference 2026

