The slide deck is locked
Sign in below to open the deck and the rest of the write-up.
What we covered
A CTF is the fastest way to learn security because it removes the part that usually stops people: permission. The session uses that as the on-ramp, then shows how the same instincts apply to a cloud account someone is actually paying for.
- What a CTF is, and the two formats you will meet: Jeopardy-style challenge boards and attack and defense.
- The categories, with what each one is really testing: web, cryptography, forensics, reverse engineering, binary exploitation, OSINT, and cloud.
- A method for working a challenge: read everything you are given, enumerate before you exploit, and know when you are down a hole worth climbing out of.
- The starter toolkit, and the small number of tools that carry most beginners a long way.
- Cloud security fundamentals: the shared responsibility model, and where the line actually falls between you and the provider.
- Identity as the perimeter: over-permissive roles, long-lived keys, and why least privilege is the control that prevents the most.
- The classic misconfigurations, in the order attackers try them: public storage buckets, exposed metadata endpoints, secrets committed to a repository, and overly open network rules.
- Cloud CTF challenges worked through, so the theory lands as something you have done rather than something you have read.
- Practising legally and safely: the platforms built for it, and the rules of engagement that keep learning on the right side of the line.
- Where to go next, and how to keep momentum after the contest ends.
Members only
Keep reading
The slide deck and the rest of this write-up are free, sign in with Google and they stay unlocked on this device.
No newsletter, no spam. Your email is used to keep you signed in.