Beginner Friendly
![]()
Leverage Insecure Storage and Backups for Profit
This beginner-friendly lab shows how backup files on accessible cloud storage can be leveraged to pivot across a cloud environment and into an on-premise Active Directory domain. Starting from AWS keys found on a compromised workstation, you enumerate IAM and S3 bucket policies, download an SSH key backup, recover a Windows EC2 administrator password, and connect over WinRM. From the host you harvest further AWS credentials, download an Active Directory backup, and extract and crack domain NT hashes.
Overview
This beginner-friendly lab shows how backup files on accessible cloud storage can be leveraged to pivot across a cloud environment and into an on-premise Active Directory domain. Starting from AWS keys found on a compromised workstation, you enumerate IAM and S3 bucket policies, download an SSH key backup, recover a Windows EC2 administrator password, and connect over WinRM. From the host you harvest further AWS credentials, download an Active Directory backup, and extract and crack domain NT hashes.
Scenario
Your team recovered AWS credentials from a compromised IT workstation at Huge Logistics. Your mission is to probe their cloud infrastructure, seek out sensitive data, and identify accessible critical resources to gauge the extent of exposure.
Lab prerequisites
- Basic Linux command line knowledge
- AWS CLI installed and configured
- Familiarity with PowerShell and WinRM remoting
Learning outcomes
- Enumerate IAM user policies and S3 bucket policies with the AWS CLI
- Download an exposed SSH key backup from an S3 bucket
- Recover a Windows EC2 administrator password with ec2 get-password-data and the launch key
- Connect to a JEA-restricted host over WinRM using PowerShell on Linux and Windows
- Harvest cleartext AWS credentials from a user profile on the compromised host
- Extract NT hashes from an NTDS.dit backup using Impacket secretsdump
- Crack NT hashes with hashcat mode 1000 and the rockyou.txt wordlist
Real-world context
Exposed backups and machine images on file shares and buckets are a common vector across both on-premise and cloud infrastructure, since backups can hold the same sensitive data as the primary systems. In hybrid environments, compromise of the cloud can lead to compromise of on-premise infrastructure and vice versa.
Cloud Security Training To Protect Your Business
Pwned Labs for Business gives your team access to dedicated business content, including labs and cyber ranges.
We also offer in-person or remote workshops, and our cloud penetration services are helping businesses become more secure!