SEC588: Cloud Penetration Testing

Programme Code D175
Applications Development
Learning Partner(s)
SANS Institute
6 Days
Format Hybrid
Web Application Penetration Test Cloud Security Application Security Testing Red Team Engineering Quality Engineering
Job Roles
ICT&SS Professional Software Engineer Security Testing Engineer Red Team Engineer Quality Engineer DevOps Engineer Data Security Officer Cybersecurity Engineer


SEC588 will equip you with the latest in cloud-focused penetration testing techniques and teach you how to assess cloud environments. The programme dives into topics like cloud-based microservices, in-memory data stores, serverless functions, Kubernetes meshes, and containers, as well as identifying and testing in cloud-first and cloud-native applications. You will also learn specific tactics for penetration testing in Azure and Amazon Web Services, particularly important given that AWS and Microsoft account for more than half the market. It's one thing to assess and secure a data center, but it takes a specialised skillset to truly assess and report on the risk that an organisation faces if its cloud services are left insecure.

Key Takeaways

At the end of this programme, you will be able to draw from many skill sets that are required to properly assess a cloud environment. If you are a penetration tester, the programme will provide a pathway to understanding how to take your skills into cloud environments. If you are a cloud-security-focused defender or architect, the programme will show you how the attackers are abusing cloud infrastructure to gain a foothold in your environments.

The programme dives into topics of classic cloud Virtual Machines, buckets, and other new issues that appear in cloud-like microservices, in-memory data stores, files in the cloud, serverless functions, Kubernetes meshes, and containers. The programme also covers Azure and AWS penetration testing, which is particularly important given that AWS and Microsoft account for more than half of the market. The goal is not to demonstrate these technologies but rather to teach you how to assess and report on the actual risk that the organization could face if these services are left insecure.

Who Should Attend

  • Please refer to the job roles section.
  • Both attack-focused and defense-focused security practitioners will benefit greatly from SEC588 by gaining a deep understanding of vulnerabilities, insecure configurations, and the associated business risk to their organizations. This programme benefits Penetration Testers, Vulnerability Analysts, Risk Assessment officers, DevOps Engineers, Site Reliability Engineers, and those working in many other areas.


This programme has many labs, so it is critical that you come prepared with the following base level of knowledge:

  1. Familiarity with Linux bash - Not expert level, but a base understanding.
  2. Basic familiarity with Azure and AWS CLI tools - Watching a simple introductory video will suffice.
  3. Base understanding of networking and TCP/IP.
  4. Rudimentary understanding of the Metasploit CLI console.
  5. Understanding how pivots work.

Programme Structure

This programme will cover the following topics in order of day:

  1. Architecture, Discovery, and Recon at Scales
  2. Attacking Identity Systems
  3. Attacking and Abusing Cloud Services
  4. Vulnerabilities in Cloud-Native Applications
  5. Infrastructure Attacks and Red Teaming
  6. Capstone Event


Full Fee

Full programme fee 


8% GST on nett programme fee


Total nett programme fee payable, including GST S$12693.24

With effect from 1 Jan 2023 till 31 Dec 2023

Full Fee

Exam fee (exl. GST)


Total exam fee payable, including 8% GST S$1434.89

With effect from 1 Jan 2023 till 31 Dec 2023


Additional terms and conditions apply for this programme. For more information, visit

Upcoming Classes

Class 1
06 Nov 2023 to 11 Nov 2023 (Full Time)
Duration: 6 days
Time : Day 1: 6.30am to 3pm; Day 2-6: 7am to 3pm

How To Register


Step 1 Apply through your organisation's training request system

Step 2 Your organisation's training request system (or relevant HR staff) confirms your organisation's approval for you to take the programme.

Your organisation will send registration information to the academy.

Organisation HR L&D or equivalent staff can click here for details of the registration submission process.

Step 3 GovTech Digital Academy will inform you whether you have been successful in enrolment.