Official Website link
Date: August 10–11, 2026 | 2 Day Training
Time: 8:30 AM – 5:30 PM
Location: Las Vegas Convention Center W208
Level: Intermediate to Advanced
Format: 2 Day Hands-on Training
Instructors: Anant Shrivastava (Founder, Cyfinoid Research), Riyaz Walikar
Course Overview
A completely hands-on, scenario-driven, multi-cloud offensive training where students learn how attackers discover, pivot, and gain control across legacy cloud environments like AWS, Azure, GCP, and Aliyun and modern developer platforms like Railway and Vercel — using real-world exploit chains instead of provider-specific theory.
Participants deploy vulnerable but realistic targets into their own cloud accounts using provided Terraform projects, then execute guided attack scenarios including OSINT-driven cloud reconnaissance, storage and artifact exposure, SSRF against metadata services, credential harvesting, IAM privilege escalation, serverless abuse, managed database access, container and Kubernetes pivots, and cross-platform compromise through developer platforms and CI/CD integrations.
Each attack scenario mirrors techniques used by real adversaries and is paired with concise defensive guidance so participants leave with practical attack playbooks and actionable hardening strategies.
Topics Covered
Day 1
- Module 0: Orientation and Setup
- Module 1: Multi Cloud Adversary Mindset
- Module 2: Recon to First Foothold
- Module 3: SSRF and Metadata Abuse
- Module 4: Serverless and Data Tier Attacks
- Module 5: Containers and Kubernetes
Day 2
- Module 6: Deep Cloud Native Abuse
- Module 7: Azure Kill Chains
- Module 8: AI and Over Privileged Integrations
- Module 9: Developer Platforms with Multi Cloud Support
- Module 10: Defenses That Actually Work
- Capstone and Exam Preparation