
HANDS-ON WORKSHOP | Prevent Remote Code Executions with Private Endpoints: Aviata Chapter 2
Source: YouTube · SANS Cloud Security · published May 29, 2024 · 31:40
This workshop introduces cloud private endpoints as a critical security control while exploring how attackers exploit them through supply chain attacks, based on the SEC 510 PR course curriculum 0:03.
Key Takeaways:
• Private endpoints are highlighted as a crucial security mechanism within cloud environments 0:06.
• The session explains how malicious actors can leverage these endpoints to execute severe and nefarious attacks 0:14.
• A significant focus is placed on understanding how supply chain attacks are utilized in conjunction with private endpoints 0:36.
• The video features a structured agenda that includes a hands-on workshop, a debrief, additional resources, and a Q&A segment 0:42.
This session sets the stage for a deep dive into the dual nature of private endpoints as both a vital defense and a potential attack vector.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
welcome to what should be an awesome action-packed Workshop in this Workshop we're going to be talking about a critical Security Control in the cloud private endpoints and how they can be exploited by attackers to do some of the most nefarious attacks that are out there this content is based on my course SEC 510 PR security controls and mitigations more on that later so we're going to start off by talking about why private endpoints are such an effective security control we're then going to talk about how attackers can leverage them in their attacks how they utilize supply chain attacks in order to accomplish this and then we're going to get into our Workshop 15 minutes before the workshop concludes we are going to do a quick debrief of what we learned and then I'll leave you with some add…