All Tags

    Penetration Testing

    14 items across 1 section

    Blog Posts14

    AWS Security Cards: Free Offensive Security Reference for 60 AWS Services

    Free, open-source security reference cards covering attack vectors, misconfigurations, enumeration commands, privilege escalation, persistence, detection, and defense for 60 AWS services.

    5 min read · 2026-03-17

    The Verdict, Four Months Later

    Part 16 of 16 in the AWS Security Agent: From Zero to Hero series. Closing the series: the numbers this whole project is built on, the honest verdict distilled to its essentials, what AWS has shipped since my hands-on testing, and an evidence-based look at how AI pentesting stacks up against traditional consultancy today.

    14 min read · 2026-07-29

    The Agent's AWS Footprint

    Part 15 of 16 in the AWS Security Agent: From Zero to Hero series. What AWS Security Agent leaves behind in your own account. CloudTrail events, Secrets Manager entries, and VPC Flow Logs, with the commands to audit and observe every run yourself.

    14 min read · 2026-07-29

    Attacking the Agent Itself

    Part 14 of 16 in the AWS Security Agent: From Zero to Hero series. What AWS itself documents about AWS Security Agent as its own attack surface: the guardrails it publishes, how it limits its own blast radius, and how domain ownership and data handling are enforced. Sourced entirely from AWS's public documentation, not hands-on testing.

    7 min read · 2026-07-29

    We Tried to Trick the Agent

    Part 13 of 16 in the AWS Security Agent: From Zero to Hero series. Adversarial evasion experiments against AWS Security Agent: code obfuscation, prompt injection in design documents and pull requests, fake sanitizers, and misleading comments. Almost every obfuscated vulnerability was still detected (18 of 19), and every injection attempt in these runs was ignored.

    13 min read · 2026-07-29

    What It Catches and What It Misses

    Part 12 of 16 in the AWS Security Agent: From Zero to Hero series. An honest, data-driven account of where AWS Security Agent falls short, with a practical fix for each weakness, plus why results vary from run to run and why a single run undercounts.

    12 min read · 2026-07-29

    How We Measured Detection Rate

    Part 11 of 16 in the AWS Security Agent: From Zero to Hero series. The full measurement methodology behind this series. A purpose-built application with 39 intentional vulnerabilities, a JSON answer key, false-positive controls, and a scoring scheme you can reproduce.

    10 min read · 2026-07-29

    Inside the Engine: What the Logs Reveal

    Part 10 of 16 in the AWS Security Agent: From Zero to Hero series. A data-driven walk through the CloudWatch logs of two real penetration tests: the 14 tools the agent uses, the thousands of reasoning blocks and tool calls, and how the observed behavior maps onto AWS's published multi-agent stages.

    12 min read · 2026-07-29

    Advanced Pentesting: VPC and Cross-Account

    Part 9 of 16 in the AWS Security Agent: From Zero to Hero series. Testing private applications inside a VPC with the agent's ENI model, the network constraints that actually matter, and cross-account shared VPC pentesting via AWS Resource Access Manager added in February 2026.

    8 min read · 2026-07-29

    Pentesting With Credentials

    Part 8 of 16 in the AWS Security Agent: From Zero to Hero series. I ran the same pentest twice against the same application. The only change was providing a username and password. Findings went from 5 to 13, a 160 percent increase, including two critical JWT bypasses and a privilege escalation.

    13 min read · 2026-07-29

    Your First Penetration Test

    Part 7 of 16 in the AWS Security Agent: From Zero to Hero series. Creating an on-demand penetration test in AWS Security Agent and watching each agent component work, from the TLS scanner to the crawler that discovered only 7 of the 48 scored endpoints on its own.

    13 min read · 2026-07-29

    Code Reviews and GitHub

    Part 5 of 16 in the AWS Security Agent: From Zero to Hero series. Connecting GitHub to AWS Security Agent, the analysis-type trap that produces silent reviews, what the agent caught in a deliberately vulnerable Flask app (9 of 10), and the new full-repository review that entered preview on May 12, 2026.

    14 min read · 2026-07-29

    Setting Up From Scratch

    Part 3 of 16 in the AWS Security Agent: From Zero to Hero series. A field-tested walkthrough of setting up AWS Security Agent: choosing an access method, creating an Agent Space, the two IAM roles, the service principal, and domain verification, including the one-click verification gotcha the docs do not warn you about.

    12 min read · 2026-07-29

    The Web Application Security Survival Kit

    Part 2 of 16 in the AWS Security Agent: From Zero to Hero series. A hands-on guide to every vulnerability class AWS Security Agent tests for, with vulnerable code, the exact attacker requests, and why each one is dangerous. Read it early, before the hands-on posts.

    18 min read · 2026-07-29

    Need Help with AWS Security?

    Our AWS security experts can help you implement best practices across all these topics.

    Contact Us