This year, we are launching a brand new class: Hacking and Securing Cloud Infrastructure (August 1-2) and (August 3-4). The class covers a number of attack scenarios which could allow an attacker to gain a foot hold on to an enterprise's cloud network and then move laterally and vertically to gain further foot hold. A common web application vulnerability hosted on public cloud (such as a SSRF issue) could allow an attacker to query meta-data services and gain vital information. We cover attacks and issues spanning all 3 major cloud providers (AWS, Azure and Google) and also cover the logging, monitoring, securing and hardening aspects.
Another course we're excited to teach virtually is Web Hacking Black Belt - 4 Day and 2 Day Edition. Here we have a collection of some neat, new and ridiculous vulnerabilities affecting web applications and APIs. We have handpicked issues which affected real world applications and have found a mention on the bug bounty platforms. Some of the highlights of the course include topics around SAML, OAUTH, SSO vulnerabilities, practical cryptographic issues, modern de-serialisation issues, advanced XXE, template injection and other topics.
We also have a 2 Day class for beginners called "Basic Infrastructure Hacking" (August 1-2 and August 3-4) that is ideal for people who want to become pentesters or managers who want to understand what goes on behind the scenes. The course begins with laying a foundation for everyone by discussing the basic concepts and gradually builds up to the level where attendees not only use the tools and techniques to hack various components involved in infrastructure hacking, but also walk away with a solid understanding of the concepts on how these tools work and therefore ready to face the real world.