Hands-on AWS security training, from IAM to cloud defense
Our AWS security training programs equip your team with the practical skills needed to identify, prevent, and respond to threats targeting Amazon Web Services. Through hands-on labs in real AWS environments, your engineers will learn to secure IAM configurations, lock down S3 buckets, harden EC2 instances, and implement defense-in-depth strategies used by leading cloud security teams.
Master AWS identity security, least privilege, and access control best practices
Learn to configure and audit AWS IAM policies, roles, and permission boundaries through hands-on labs. Our training covers IAM policy evaluation logic, cross-account role assumption, service control policies, and the principle of least privilege. You will gain practical experience identifying overly permissive policies and implementing secure access patterns used by mature AWS security teams.
Attack and defend S3: bucket enumeration, exposed data, and exfiltration paths
Your team works S3 the way an attacker does: fingerprinting a bucket's region with cURL, signing raw API calls to list buckets and objects, and mapping a public bucket back to its parent AWS account ID. They recover secrets from old object versions, over-shared object ACLs and exposed bucket policies, then pivot through public EBS and RDS snapshots to reach credentials. Every technique is paired with the defense: Block Public Access, snapshot encryption enforced by SCP, Amazon Macie discovery, and CloudTrail data event alerting on enumeration spikes.
Detect threats and investigate incidents using AWS-native security tools
Train your team to configure and use CloudTrail, GuardDuty, Security Hub, and CloudWatch for comprehensive threat detection and incident investigation. Labs cover log analysis techniques, creating custom detection rules, building automated alerting pipelines, and correlating events across multiple AWS accounts. Your engineers will learn to identify indicators of compromise and respond effectively to security incidents in AWS environments.
Secure event-driven architectures, API Gateway, and serverless workloads
Learn to secure Lambda functions, API Gateway endpoints, Step Functions, and event-driven architectures. Our training covers function permission boundaries, environment variable encryption, input validation for event sources, and least-privilege execution roles. Hands-on labs walk your team through securing real serverless applications and identifying common vulnerabilities in event-driven AWS workloads.
Trace attack paths from exposed services through IMDS to lateral movement
Network security is taught here through attack paths, not architecture diagrams. Your team enumerates EC2 security group ingress rules, escalates an SSRF into credential theft against the instance metadata service, and bypasses IMDSv2 using the gopher protocol. From there they move laterally through AWS Systems Manager with ssm:SendCommand, harvesting instance role credentials, EC2 user data and Parameter Store secrets without opening a single inbound port. Defenses covered include enforcing IMDSv2 by declarative policy, disabling IMDS where it is unused, and detection through VPC Flow Logs, GuardDuty and Amazon Detective.
Training built by AWS security practitioners, for AWS security practitioners
Pwned Labs training is created by AWS security practitioners who work in production cloud environments every day. Our instructors hold certifications including AWS Security Specialty, ACRTP, and CPTS, and actively contribute to the cloud security community through research, open-source tooling, and training content used by thousands of professionals worldwide. Every lab is based on real-world scenarios drawn from actual cloud security engagements.
Frequently asked questions
What is AWS security training?
AWS security training teaches practitioners to secure Amazon Web Services environments - identity, storage, network, logging, and workloads - through hands-on labs rather than slides. At Pwned Labs you attack and defend real AWS accounts, so the skills transfer straight to production.
Who is AWS security training for?
Cloud and security engineers, DevOps and platform teams, penetration testers, and SOC analysts who need practical AWS security skills. The fundamentals assume no prior AWS security experience; advanced tracks expect working AWS knowledge.
Is the AWS security training hands-on?
Yes. Every topic runs in a live AWS environment where you enumerate IAM, exploit a misconfiguration, then apply the fix - so you learn by doing. You can try the approach in our hands-on labs.
Which AWS services does the training cover?
IAM and IAM Identity Center, S3 and data protection, VPC and network security, CloudTrail, GuardDuty and Security Hub, Lambda and API Gateway, and ECS and EKS - across both offensive testing and defensive hardening.
Does AWS security training map to certifications?
The material aligns with the AWS Certified Security - Specialty domains and reinforces the practical skills those exams assume. For a structured, cohort-based path, see our cloud security bootcamps.