Pwned Labs Amazon Cloud Attack & Defense Bootcamp - Professional Edition
ACRTP stands for Amazon Cloud Red Team Professional.
Hands-on AWS attack and defense training focused on real-world identity and infrastructure attack paths.
Ideal for: Penetration testers, security consultants, cloud red teamers, purple teamers, cloud security engineers validating AWS controls, and practitioners aspiring to these roles.
Designed for modern identity-driven AWS environments, teaching operators to execute the tradecraft and evaluate agentic-assisted workflows end-to-end.
Already registered? Access here
Pwned Labs Amazon Cloud Attack & Defense Bootcamp - Professional Edition Overview
AWS is the current market leader in public cloud!
This on-demand bootcamp and structured learning path teaches practical techniques for attacking and defending AWS environments. You will work through identity-driven attack paths across AWS and CI/CD using techniques observed in active intrusions.
After completing the bootcamp and associated learning path, you will validate your skills in a fully hands-on, unproctored exam that requires completing an end-to-end exploitation chain.
The exam environment is dynamic, with scenarios changing regularly to reflect real-world AWS intrusions and ensure certification credibility.
Prerequisites and key learning outcomes
You should be comfortable using the Windows or Linux command line. Prior AWS experience is helpful but not required.
The ACRTP is the AWS-focused track among the Pwned Labs cloud pentesting certifications.
After completing the bootcamp and passing the exam, you will demonstrate proficiency in:
- Understand core AWS services and identity concepts
- Simulate compromise of developer and cloud workloads
- Perform AWS security audits and remediate misconfigurations
- Leverage AWS services for initial access and lateral movement
- Use phishing techniques for initial access
- Abuse compromised credentials for privilege escalation
- Abuse Amazon Bedrock and integrated data stores
- Execute hands-on purple team attack and defense scenarios
- Exploit misconfigured IAM roles and trust relationships
- Detect threats using GuardDuty, CloudTrail, Athena, and Splunk
- Attack and defend a broad range of AWS IaaS and PaaS services, including EC2, Lambda, IAM, CI/CD, storage, and application services
What you get
You get ongoing access to the full AWS security curriculum, organized into four pillars that align to the four sessions. Each pillar includes its own learning path so you can hit the ground running before the session starts.
- Lifetime access to the latest session recordings, updated slides and command guides, bootcamp labs, and all future course updates
- 45 days of Academy lab access for the learning paths tied to each session, starting from when you redeem your voucher rather than from purchase, with no deadline to claim and extendable with subscription
- Direct preparation for the PLACRTP certification exam
- More information on the bootcamp, learning paths, and the PLACRTP exam is available on the PLACRTP FAQ page.
Focus on trending techniques and tradecraft
The Pwned Labs Amazon Cloud Attack & Defense Bootcamp, Professional Edition covers attacker tradecraft observed in real AWS cloud breaches, including activity attributed to groups such as AMBERSQUID and SCARLETEEL. Labs simulate realistic enterprise environments with active users and services.
You will learn how to:
- Identify and replicate tradecraft from recent cloud incidents
- Execute attacks using multiple approaches and tools
- Evict attackers and rotate credentials across AWS services
Course syllabus
The Pwned Labs Amazon Cloud Attack & Defense Bootcamp (ACRTP) is a hands-on, on-demand AWS red team course. Across four sessions you work identity and infrastructure attack paths through IAM, EC2, S3, and CI/CD using tradecraft observed in real intrusions, then defend each one, before validating your skills in a 24-hour, fully hands-on exam.
Session 1: Getting initial access to AWS
- AWS and IAM overview, and the AWS CLI hands-on
- AWS service endpoints and techniques to discover AWS account IDs
- Identifying public AWS resources and AMBERSQUID tradecraft
- Harvesting secrets from code repositories
- Enumerating IAM principals and performing password spray attacks
Session 2: Exploiting overprivileged IAM and trust policies
- Examining IAM policies and enumeration, and responding to compromised access keys
- Performing and detecting IAM brute-force enumeration
- Exploiting dangerous IAM permissions to account takeover
- Exploiting GitHub Actions OIDC for AWS access
- Visualizing IAM attack paths
Session 3: Attacking and defending AWS resources
- Identifying deployed resources across regions with CloudFox and aws_list_all
- Increasing access through Amazon S3, and attacking and defending EC2 and IMDSv2
- Attacking and defending Elastic Beanstalk and AWS Systems Manager (SSM)
- Attacking and defending Amazon Bedrock, including knowledge-base data poisoning
- SCARLETEEL tradecraft: hacking Jupyter notebooks
Session 4: Purple and blue teaming in AWS
- Assessing AWS security with Prowler and exploiting cross-service role trust
- Responding to security incidents with Amazon Inspector
- Increasing access through defensive infrastructure and Amazon Macie
- Setting traps with honey tokens and detection-avoidance techniques
- Detection with GuardDuty, CloudTrail, Athena, and Splunk, plus exam prep and a capstone CTF
Related concepts in our Security A-Z glossary: GitHub Actions OIDC, AWS privilege escalation, AWS IAM PassRole, cloud IAM privilege escalation, and cloud incident response.
Meet the team
Our instructors are on hand in Discord to help whenever you need it..
Tyler Petty brings over a decade of cybersecurity experience across technical and leadership roles and works as a cloud security engineer.
Driven by a passion for helping others, he has created hands-on labs in cloud security and DevSecOps, along with a course on using Infrastructure as Code to build secure infrastructure on AWS.
He is actively involved in the cloud security community, contributing hands-on educational content and open-source resources focused on AWS security, DevSecOps, and real-world defensive and offensive techniques.
Ian Austin is a security researcher and educator with a career spanning over 20 years in technical, security and leadership roles for global enterprises.
Ian was Head of Content at Hack The Box, a leading online platform for cybersecurity training and assessment. He also participated in the Green Team of Locked Shields, a NATO cyber defense exercise, contributing to the design and execution of realistic scenarios.
He is the founder of Pwned Labs, providing gamified and immersive cloud security labs for red and blue teams.
How it works
Start immediately with on-demand access. Work through the learning path and labs at your own pace. Your purchase includes 45 days of lab access and two ACRTP exam attempts. The 45 days begins when you redeem your voucher rather than at purchase, and there is no deadline to claim it. Lab access is extendable with subscription. Support is available via Discord.
What security teams say
“I’ve attended two training sessions delivered by Pwned Labs: one focused on Microsoft cloud environments and the other on AWS. Both delivered highly relevant content in a clear, approachable manner, paired with an excellent hands-on lab environment that was immediately applicable to real-world Red Team Operations, Purple Team exercises, and Cloud Penetration Tests.”
Caleb Havens, Red Team Operator & Social Engineer, NetSPI
“Although my background was mainly web and network penetration testing, the ACRTP and MCRTP bootcamps gave me a solid foundation in AWS and Azure offensive security. I’m now able to take part in cloud penetration testing engagements and have more informed security discussions with my team.”
Steven Mai, Senior Penetration Tester, Centene
Ask your employer to fund ACRTP
Need employer funding approval? Use our ready-made employer funding request to outline the value of the Pwned Labs Amazon Cloud Attack & Defense Bootcamp - Professional Edition and the ACRTP certification.
Prefer to self-fund? You can enroll immediately.
Frequently asked questions
What is the ACRTP bootcamp?
The Pwned Labs Amazon Cloud Attack & Defense Bootcamp (ACRTP) is a hands-on, on-demand course covering AWS attack and defense. It teaches identity and infrastructure attack paths across IAM, EC2, S3, and CI/CD, then certifies you through the Amazon Cloud Red Team Professional exam.
What does ACRTP stand for?
ACRTP stands for Amazon Cloud Red Team Professional. It is the hands-on certification earned by completing the bootcamp and passing the exam.
Do I need AWS experience to take the ACRTP?
No. You should be comfortable with the Windows or Linux command line. Familiarity with AWS is helpful but not required, and all the material you need to pass the exam is provided in the bootcamp and its structured learning paths.
How long is the ACRTP exam and is it proctored?
Once started you have 24 hours to complete an end-to-end exploitation chain from a provided entry point to capture the flag. The exam is fully hands-on, unproctored, and does not require a pentest report.
What tools and techniques does the ACRTP cover?
The bootcamp covers IAM enumeration and privilege escalation, GitHub Actions OIDC abuse, IMDSv2 and EC2 attacks, S3, Elastic Beanstalk, SSM and Amazon Bedrock, plus defensive tooling including Prowler, Amazon Inspector, Macie, GuardDuty, CloudTrail, and Athena.
Does the ACRTP certificate expire?
No. Once awarded, the ACRTP certificate does not expire or require renewal. Your registration includes two exam attempts, and exam attempts do not expire.
Which real-world threat actors does the ACRTP model?
Labs draw on tradecraft observed in real AWS intrusions, including activity attributed to AMBERSQUID (cryptojacking across AWS services) and SCARLETEEL (cloud credential theft and container compromise).

