Saturday, 16 May 2020

5 Ways to Intelligent Network Security with Software-Defined Networking

EC-Council Study Materials, EC-Council Guides, EC-Council Learning, EC-Council Certification

Today’s businesses compete in a very challenging landscape of network security. From large corporations to small- and medium-sized enterprises, even many start-ups are adopting cloud services. It not only offers the flexibility of resource utilization, but also reduces operational costs, increases data integrity and security, lowers the risk of data unavailability, and tenfold collaborative productivity.

The migration from on-premise to cloud-based infrastructure has resulted in massive changes in network design and security. To support this digital transformation, organizations need advanced tools and support of automation to improve security. In such a situation, software-defined networking could be the optimal solution.

Software-defined networking – Solving network security challenges


Software-defined networking (SDN) is a network architecture that enables centrally and programmatically efficient network configuration, improving network performance and monitoring. With this arrangement, network security operators can easily manage network consistency without being concerned about the underlying network technology.

SDN impacts organizations positively. With the help of this technology, companies now understand the widening threat landscape and real-world challenges of SDN.

SDN and network security


EC-Council Study Materials, EC-Council Guides, EC-Council Learning, EC-Council Certification

Network defense professionals are looking for innovative ways to protect their organizations from complex security concerns. With SDN, experts have the right opportunity to improve network security. Here’s how:

1. Centralized network control

In a traditional IT environment, network security solutions, such as router and switches, make decisions regarding incoming and outgoing traffic. SDN can centralize the network control, routing the entire traffic using a single controller. It can separate the control plane, forwarding plane, and data plane from each other. This technology gives a clear picture of the network topology and architecture. For network security, SDN can also regulate data packets through a single firewall and improves the data capture ability of IDS and IPS.

2. Simplified configuration

VLAN configuration demands a lot of dedication and sincerity as it offers a highly secured environment for the organizations. The more VLANs a company implements, the more complex it becomes for the professionals managing them.

With the help of SDN, the organizations can automate the VLAN configuration and improve the traceability of these configurations. Along with that, SDN allows dynamic programming and restructuring of network settings, which eventually results in the elimination of DDoS attacks.

3. High-level network policies

The SDN technology offers central management of security policies instead of physically configuring them. This feature enables a network operator to be more flexible and efficient. In addition, organizations are replacing the current management approaches like SNMP/CLI with efficient policy management.

4. Handy Application Programming Interfaces (APIs)

Cloud APIs are crucial for SDN controllers and applications. With easy to use APIs, professionals can conveniently manage network resources, enhance the efficiency of IT resources, and keep the vital tools in easy reach.

Also, take a look at Dhananjaya Naronikar’s coverage on cloud security:


5. Additional qualities

SDN comes with automatic quarantine capabilities, which implies that it can automatically isolate malicious code on a network. Though the quarantine capability may be applicable from a selected point to an infected part on the network.

Source: eccouncil.org

Thursday, 14 May 2020

The role of Cyber Threat Intelligence in patching

EC-Council Study Materials, EC-Council Guides, EC-Council Certification, EC-Council Exam Prep

Vulnerabilities put your business at risk and with thousands of them emerging every year, it becomes impossible to patch them all, and that is where your research is required. Threat intelligence helps identify specific vulnerabilities that are a risk to your organization and provide custom solutions.

Gartner’s research has identified that among all the vulnerabilities identified in the previous decade, only about one-eighth of them were actually exploited in real-world attacks. The vulnerabilities that do not get exploited are often reused and leveraged in a wide range of threats.

Gartner recommends shifting focus from vulnerability management to ranking threats based on their severity. Though both vulnerability management and ranking of threats are important, systems like Common Vulnerabilities and Exposures (CVE) and Common Vulnerability Scoring Systems (CVSSs) does not consider the performance of threats. At the same time, relying solely on the severity of the vulnerabilities won’t help combat threats.

Refocus your goals


The security system to obtain perfection should be completely immune to exploitation. But due to a large number of vulnerabilities, the “patch everything, all the time, everywhere” approach is impossible to achieve. With restricted time and resources, the approach should be the “biggest vulnerabilities first.” When we review the security breaches from the last decade, it is clear that the approach was misguided. Gartner in his research has suggested achieving a balance between what can be fixed, and what difference it makes with available resources and time.

The difference between perceived goals and actual outcomes is due to the negligence of the organization towards fencing against the vulnerabilities. The security teams consider attending the biggest and newer vulnerabilities due to the impression that the attackers target them immediately. Whereas, attackers do not switch to new vulnerabilities if they identify that the existing ones can be exploited multiple times with decreasing costs and less expertise. Gartner observed that the attackers exploit vulnerabilities that are relatively easy and present in widely used software.

To overcome this issue is to gain fundamental right on vulnerability management and patch the vulnerabilities that were exploited earlier, instead of focusing only on the new ones.

Gartner’s report on patching


Gartner, is its research found that nearly 8000 vulnerabilities were disclosed during the past decade, with a marginal rise in their number every year. The new exploited vulnerabilities, due to new software releases, account for only one-eighth of the actual number, whereas the number of threats has increased exponentially. This shows that though the number of breaches has increased in the past decade, new vulnerabilities contribute to only a fraction of them.

Further, zero-day problems form a part of new vulnerabilities that go around 0.4% of all vulnerabilities exploited throughout the decade. Although cyber threat intelligence vendors cannot label them as ‘zero-days’ technically, patching the vulnerabilities of the software is the solution to fix a majority of expected zero-day threats. Through all these years, threat actors have evolved in exploiting vulnerabilities. They are now able to exploit them in 15 days, as against the previous 45 days. Organizations are now left with two options – either patch the systems in 15 days or have a plan to mitigate the damages.

How to fix this flaw


1. Track a metric that identifies the conjunction of existing vulnerabilities and the ones that are been exploited by the threat actors. The highest repeated metric should be patched on priority as a defense against a breach.

2. Protocols like network segmentation, intrusion protection, and privileged identity management are a great help in mitigating threats and preventing vulnerabilities in the absence of their patches. These protocols prioritize vulnerabilities that are being exploited.

3. Identifying and mitigating the threats and patching them requires specialized skills. A Certified Threat Intelligence Analyst (C|TIA). It is a program that gives an individual or organization the ability to run a threat intelligence process and allows ‘evidence-based knowledge’ and ‘actionable advice’ about existing and known threats.

Source: eccouncil.org

Tuesday, 12 May 2020

Is your Cyber Disaster Recovery Plan equipped to handle the latest cyber threats?

EC-Council Study Material, EC-Council Guides, EC-Council Certification, EC-Council Exam Prep

The expansion of the connected ecosystem is contributing to the complexity and growth of cyberattacks. According to Cybersecurity Ventures estimation, the human attack surface will grow to 6 billion by 2021 and the attacks will cost the global economy $6tn by 2021. Those who have experienced high profile cyberattacks have suffered devastating financial loss, reputational damage, and many legal suits. To avoid these consequences, businesses must have cybersecurity in place as a defense from cybercriminals. But despite all the necessary security measures, human errors and technical faults render the security mechanism useless creating the necessity for a disaster recovery plan.

The policies and procedures of a disaster recovery operates during and after the disaster, enabling businesses to recover important assets that they have lost in the crisis. Importantly, the disaster recovery plan shall be in accordance with the threats so that the management can continue to operate business even after an attack.

They’re too big to fail. Are you too small to recover?


Aligning your disaster recovery plan to cyber threats


1. Awareness of threats

Companies should develop a contextual understanding of threats to prevent and handle breaches. Pairing human capital with big data analytics may develop this understanding. With the regulations like GDPR, the key challenge for businesses is to shift the breach time to detection time. Companies can protect against the breaches by considering an approach that recognizes the context and intent of user behavior at an early stage and flags-off potential threats proactively. The understanding of users’ behavior with systems and data also determines the risk factor.

2. Responding to attacks

To respond to attacks profoundly, it is vital for businesses to have tools and processes that can handle and respond to sophisticated cyberattacks. Being one step ahead from the effects of the attacks and the destruction that the cyber attackers may cause, is the only solution from avoiding becoming a victim of them. A better understanding of the data, accessibility, and human error leading to malicious acts, compliance with the GDPR regulations and protects sensitive information in the network. A process should be laid to identify and monitor potential threats on an hourly basis. The identification process embeds checkpoints into the security landscape to build stronger efficiency in analyzing behavior changes that could result in breach possibly. By analyzing the movement of data and behavior of the network, the team can ensure that the threat has been mitigated and they must move to the next step of protecting data, brand, and customers.

3. Continuous planning is significant

Businesses must consider disaster recovery as an evolving plan due to the constantly changing cybersecurity landscape. The security team should not be under an impression that the previous year’s policy /plan can be implemented this year too. The information collected by being vigilant and performing risk assessments regularly, a perfect security plan can be framed. A disaster recovery plan formed based on real observation can only ensure that the landscape is free of vulnerabilities.

4. Approach should evolve

A disaster recovery plan cannot be developed on the basis of traditional approaches. It needs time and effort as it is challenging to create and implement security measures. The traditional risks like an epidemic, terrorism, etc. can be adjoined together as they create the same impact. All cyber incidents are not similar and simple. When the data is encrypted and locked, restoring data from a backup source before ransomware spreads further takes time and involves a significant data loss too.

Source: eccouncil.org

Sunday, 10 May 2020

4 Cybersecurity Lessons Learned the Hard Way


The cybersecurity landscape is dynamic. The threats are constantly evolving and today’s cybersecurity measures may not stand up to pressure tomorrow. However, time and time again we’ve seen companies and organizations slip into complacency or ignore certain processes—such as training or vetting outside tools—and pay in terms of costly cyberattacks.

In this post, we look at four of those cases, discussed below:

1. Atlanta, GA (2018)


On March 22, 2018, the city of Atlanta in Georgia was hit by a SamSam ransomware attack.

The ransomware attack locked municipal workers from accessing their systems. The attackers then demanded US$51,000 in Bitcoin payments in exchange for restoring access.

As a result of the SamSam attack, Atlanta was unable to effectively deliver essential services—such as processing water and sewage bills, issuing business licenses, or scheduling traffic ticket hearings—for over a month following the actual attack.

In general, ransomware attacks occur through phishing attacks aimed at fooling the user into downloading a malicious file (or clicking to a malicious website). The attack then locks the end user out of their system and, typically, the attacker will demand a ransom payment.

However, the SamSam attack does not proliferate through phishing emails, but “by exploiting vulnerabilities or guessing weak passwords in a target’s public-facing systems”.

Though the direct cause of the attack was SamSam, the underlying reason for it was the fact that Atlanta’s IT systems suffered from “between 1,500 and 2,000 security vulnerabilities”. In addition to inherent weaknesses, Atlanta was also ill-equipped to respond to the attack.

The lesson is that not only must you regularly conduct cybersecurity assessments or audits, but to regularly identify and resolve cybersecurity risks. This would involve phasing-out outdated or insecure platforms, such as the 100 servers running on Windows Server 2003 (which Microsoft ended support for in 2015). A solution would have been to expedite the move to the cloud and leverage the provider’s commitment to maintain the latest security standards.

It is a costly practice, but given how the city spent US$2.7 million in emergency contracts a month following the attack (with the total cost slated to reach as much as US$17 million), Atlanta was not spared from the expense either way. Instead, the Atlanta had found itself in the news for all the wrong reasons, which will not help the city or its government from a PR standpoint.

2. British Airways (2018)


In September 2018, British Airways announced that it suffered from a breach that affected as many as 429,000 of its customers and their credit card numbers. The breach, which had gone unnoticed for two weeks, effectively required affected patrons to cancel their credit cards.

RiskIQ, a security vendor, assessed the situation and determined that the breach was a result of attackers injecting malicious code into British Airways’ online payments page. RiskIQ concluded that the attack was specifically aimed at British Airways, making the airline a victim of a targeted and sophisticated attack. It is not clear how much the attack will cost to British Airways.

It appears that the attack exploited third-party code on British Airways’ website. This isn’t an easy issue to deal with considering how many businesses rely on the same third-party code to enable payments, show ads, and other user-centric services.

In fact, the challenge of this security breach was that you or your managed IT services provider(s) might have setup a solid cybersecurity system, but as cyber expert Dr Alan Woodward put it (via the BBC), “You can put the strongest lock you like on the front door, but if the builders have left a ladder up to a window, where do you think the burglars will go?”.

In this respect, the lesson for companies and organizations is to heavily vet and test any and all third-party codes (e.g., tools, scripts, plugins, etc.) they are bringing into their system. Moreover, it would also be good practice to regularly monitor or audit those for irregular activity.

3. eBay (2014)


In May 2014, eBay announced that it had suffered a major data breach affecting upwards of 145 million of its customers. Besides usernames, the breach was thought to have compromised user emails, real names, home addresses, phone numbers, and birthdates. In effect, millions of eBay users were at risk of identity theft or fraud as a result of the breach.

The breach—which had forced eBay to lower its annual sales target by US$200 million and report lower revenue for that year—was likely initiated through a spear-phishing attack.

In spear-phishing attacks, hackers craft sophisticated emails that look as though they are from a trusted source, such as a colleague, manager, vendor, or customer. The goal is to manipulate or fool end users into an action they wouldn’t take if they knew the reality of that email.

For example, a hacker masquerading as a vendor could trick the user into sending money to the hacker in response to a fake invoice. Alternatively, someone posing as a manager could get the user to give password information or click on a malicious link/attachment.

Though technical measures, such as sandboxing affected PCs and filtering traffic from high-risk sources, help, the solution is to train and educate your staff. Your employees should have both the knowledge to recognize phishing attempts and report such issues, not fall for them. In fact, training is relatively a low-cost, quick way of getting high-impact cybersecurity gains.

4. RSA Security (2011)


In 2011, RSA, a multifactor authentication company, reported that it was struck by two spear-phishing attacks. Besides resulting in a cost of US$66 million, the attacks also pulled RSA into the focus of the US government because the company’s SecureID tokens—which were compromised—were in use by Lockheed Martin, a marquee defense vendor.

The spear-phishing attack posed as a company-wide email discussing that year’s recruitment roadmap. An employee not only took that email out of their Junk/Spam folder, but opened the attached Microsoft Excel file, which contained a zero-day exploit of a vulnerability in Adobe’s Flash platform and, in turn, released a variant of the Poison Ivy Trojan.

As with the eBay hack, there were combinations of issues at play, such as the failure of RSA’s threat identification and sandboxing as well as lack of cybersecurity training. In fact, the gap in this case was severe enough that the malicious email was already filtered out, but the employee did not understand why and opted to retrieve and open it anyways.

In each of these four cases, there are two major lessons.

First, the cost of recovering from a cyberattack — be it in fiscal terms or reputation — is higher than the cost of preparing for it in advance.

Second, the root cause for an attack could occur despite solid cybersecurity efforts due to the end user’s lack of knowledge or awareness.

Thus, businesses and organizations must address their cybersecurity issues from every angle — that is, regular auditing, vulnerability scanning, automated response systems (e.g., sandboxing high-risk or unrecognized software), training, and response processes (e.g., disaster recovery).

Final Thoughts

In this post, we looked at four notable cybersecurity attacks. Though the cybersecurity industry has made strides in countering threats, the threats themselves keep evolving. This back-and-
-forth will keep businesses of all sizes on edge, forcing them to invest in understanding these threats and the solutions emerging to stop them.

Source: eccouncil.org

Thursday, 7 May 2020

6 Skills every Ethical Hacker must have to protect an organization

Ethical Hacker, EC-Council Study Materials, EC-Council Guides, EC-Council

On a rare occasion do we see a week go past without news of a massive data breach. There is a hacker attack every 39 seconds and a cybercriminals steal on an average 75 records every second. Both small and big businesses are targeted by cybercriminals, creating a need for skilled ethical hackers to protect their systems. Organizations, government and private, now need ethical hackers more than ever.

Who is an Ethical Hacker?


Ethical hackers identify potential vulnerabilities in the system, application or data before they are been exploited by cybercriminals. To protect businesses, organizations prefer investing in trained ethical hackers. These professionals are trained to use methodologies and technologies similar to those used by a criminal hacker.

6 skills that trained Ethical Hackers possess


Organizations are increasingly adopting technical methods and solutions to store their crucial business data and expanding their market. This has equally led to the expansion of a number of cybercriminals.

1. Identify loopholes

Businesses are highly prone to cyberattacks and therefore, organizations require ethical hackers to protect their systems and IT infrastructure. They identify loopholes and vulnerabilities that can be used by cyber attackers to exploit systems and compromised data. They perform tests that are aimed to protect data from getting leaked.

2. Knowledge of penetration testing

Ethical hackers are equipped with the knowledge of penetration testing or pentesting that will help to identify vulnerabilities in the system. An ethical hacking training consists of different penetration testing methods including, targeted testing, blind testing, internal testing, external testing of network servers or DNS servers.

3. Addresses risk of transitioning to the cloud

Transitioning to the cloud is putting a lot many organization’s data at risk. On one side, business data is vast, and it cannot be stored in-house, creating a need for a cloud network. On another hand, the transition involves security risks and a little negligence exposes the data. The demand for ethical hackers is evolving to overcome the challenges of the cloud transition.

4. Prepares for a real-time attack

In spite of being fortified with security measures, cyberattacks are inevitable. Eventually, a cyber attacker attacks the IT systems or applications by exploiting the smallest of the vulnerabilities present in the IT infrastructure. Cyberattacks are evolving and being prepared to handle them is the only solution when an incident happens. Finding vulnerabilities beforehand by ethical hackers is one of the best ways to prepare against a potential attack.

5. Uses real hacking tools carry out the attack

The organization’s staff may be curious about security processes but not every employee will be aware of the real hacking tools. To ensure better protection at the user end, staff members should be trained by ethical hackers on various tools and methods of identifying threats. An ethical hacker knows the use of real hacking tools and advanced methodologies that protects the organization from potential attacks.

6. Reduces loss in the case of an incident

An ethical hacker can identify vulnerabilities faster and suggest mitigation to prevent any ongoing attack. Mitigating an attack reduces the further loss of data, finance, and reputation of the organization.

Though organizations can easily find black hat hackers, finding an efficient ethical hacker ensures a code of ethics. They are now pragmatic in hiring certified ethical hacker as a security measure.

Source: eccouncil.org

Tuesday, 5 May 2020

Does hands-on learning make you a better Ethical Hacker?

Ethical Hacker, EC-Council Study Materials, EC-Council Guides, EC-Council Exam Prep

Lab-based training is practically oriented as it directly trains you to perform specific tasks. On the other hand, traditional classroom training primarily focuses on theory ignoring practical implementation. Hence, we find a large gap between their grades on paper and their actual performance. The main advantage of hands-on learning, especially for an ethical hacker, is that it allows individuals to transition from the “why” to the “how.” At the same time, engaging physically with different concepts allows students to gain hands-on skills.

Here’s why an ethical hacker needs hands-on learning:


Ethical hacking is a white hat activity where an information security expert attempts to penetrate the network to protect the infrastructure. This is why an ethical hacker performs the test within the scope defined, only after attaining permission from the organization. The goal of an ethical hacker is to identify vulnerabilities and attempt to exploit them to determine the extent of the compromise.

A training program prepares an individual to get the technical skills required to perform the job,hands-on learning is crucial to ensure real-time exposure to a sensitive hacking environment. The first thing to remember is that ethical hacking is a practical process, and thus, the training should be lab-oriented, thereby ensuring that skills required in the real-world are attained.

Practical techniques used by ethical hackers


Ethical hackers use hacking skills and methodologies often used by malicious actors. In brief, here are a few significant hacking techniques used:

◉ Scanning ports to find vulnerabilities. Ethical hackers use various port scanning tools to scan an organization’s network. They identify open ports to study the vulnerabilities associated with each port.

◉ Using tools to sniff and perform network traffic analysis.

◉ Analyzing the process of patch installation to ensure that the system is not affected by the new vulnerabilities.

◉ Evading intrusion detection systems, firewalls, intrusion prevention systems, and honeypots.

◉ Applying social engineering techniques to get information about an organization’s computing environment.

To be ‘job-ready’, one should have hands-on training on various hacking methodologies. This, coupled with both theoretical and practical approaches to learning, ensures that you have the necessary skills to enter the industry. A lab-intrinsic ethical hacking program ensures that you get the right skills. This is crucial to secure the cyberinfrastructure of an organization.

CEH – A constructive hands-on training program in Ethical Hacking


EC-Council’s Certified Ethical Hacker (CEH) is a theoretical and hands-on certification program. It starts with the basics, fields of penetration testing, software installation, and more. The course trains you on everything from analyzing to exploiting the defined scope of IT architecture.

The practical approach of CEH –

◉ CEH is the world’s most comprehensive ethical hacking program with 20 of the most current security domains.

◉ 40% of the program is dedicated to hands-on learning.

◉ In 20 vast modules, the program covers 340 attack technologies that are commonly used by hackers.

◉ The program trains you in the five phases of ethical hacking. This is reconnaissance, gaining access, enumeration, maintaining access, and covering tracks. All these phases of ethical hacking are practiced in the lab too.

◉ It has 140 labs that mimic real-time scenarios.

◉ There are around 2200 hacking tools to allow you to understand and react according to the attacker’s mindset.

◉ EC-Council also provides the iLab range which focuses on the most common tools and techniques used by cybercriminals. Technologies like SQL injection, Cryptography, network scanners, IDS and IPS, and many more.

◉ The labs simulate real-life scenarios using different tools. This includes Kali Linux, dedicated to information security professionals.

CEH is one of the most recognized ethical hacking certifications in the industry. A follow-up to the CEH is another significant ethical hacking certification, the CEH (Practical), which is a 100% hands-on examination.

Key features of CEH Practical


◉ The world’s first ethical hacking industry readiness assessment available live, online, proctored, and verified.

◉ It tests the limits of students while unearthing vulnerabilities.

◉ SMEs from across the world came together to create the CEH Practical exam.

◉ The exam includes 20 real-life scenarios designed to validate the essential skills of being an ethical hacker.

◉ It is not a simulated exam. It asks to prove the application of knowledge acquired to meet real-life instances.

Source: eccouncil.org

Sunday, 3 May 2020

All you need to know about Pentesting in the AWS Cloud

AWS Cloud, EC-Council Study Material, EC-Council Guides, EC-Council Certification

Quite recently, we have experienced many AWS (Amazon Web Services) breaches exposing vulnerabilities, like S3 buckets, compromised AWS environments, and more. To understand the strategies the strategies of specific attacks on AWS Cloud, one must have specific knowledge and a strategic approach. In this article, we will explain the dire need for AWS pentesting among organizations that are seeking to improve their security and reduce the probability of breaches.

What is AWS?



When we talk about AWS pentesting, we must consider the legal regulations of the cloud environment. To put it another way, AWS penetration testing focuses on access management user permissions, identity configuration, user-owned assets, and integration of AWS API into the AWS ecosystem. For example, testing S3 bucket configuration and permission flaws, covering tracks of obfuscating cloud trail logs, targeting and compromising AWS IAM Keys, etc. implies that the client-side components are tested, ignoring the AWS instance.

Why is AWS  penetration testing important?


Many organizations have openly adopted AWS services, but not everyone understands the technical flexibility provided for AWS incorporations. This often in misconfiguration of user permissions and identity management.

The following scenarios explain the significance of penetration testing in AWS environments to ensure security –

◉ Reported failures across security checks of AWS include open-wide security groups’ and excessive permissions.

◉ A false understanding of the ‘shared responsibility model.’ Organizations underestimate their risk exposure.

◉ Incompetency in implementation, operation, and requirements for multi-factor authentication. It is important to consider the effectiveness of social engineering attacks and personal identification information attacks.

◉ Maintaining compliance that impacts the networks and data centers. Specifically, HIPAA, PCI-DSS, FedRAMP, etc. are a few of the  required regulatory compliances that organizations must follow. Per regulatory authorities, pentesting enables recovering and eliminating security gap.

◉ Identify and remediate zero-day vulnerabilities. Addressing zero-day vulnerabilities enables good security posture in the cloud.

Endorsing AWS security implementation in the cloud forms a flexible security plan. Because of the shared responsibility model, AWS explains the need for penetration testing of the applications, operating systems, networks, and instances. Hence, AWS also has a recognized program that permits pentesting. Organizations should partner with businesses that are familiar with the program and create rules governing critical success.

How do AWS Methodologies differ from Traditional Pentesting?


There is a difference between pentesting of traditional security infrastructure and the AWS Cloud. The main difference being systemownership. Amazon owns the core infrastructure of AWS. Therefore, the methodologies used in AWS are different from that of traditional penetration testing. For this reason, the AWS security team involves specific incident response procedures.

5 Vulnerabilities to Test for in AWS


Even though there are numerous  vulnerabilities that are specific to AWS, a few in particular are quite common. Here are the top 5 vulnerabilities to be test for in the AWS landscape:

1. Testing permission flaw along with S3 bucket configuration

2. Implementing web application firewall (WAF)/ Cloudfront misconfiguration bypasses

3. Covering tracks by obfuscating Cloudtail logs

4. Targeting and compromising AWS IAM keys

5. Applying Lambda backdoor functionality and establish access to private clouds

Prior to hiring penetration testers, make sure ensure their understanding of your business deliverables is clear. Also, check to be sure their approach to the risk directly correlates to your business and  ensure  your organization will take appropriate action.

Source: eccouncil.org