AWS:
Reconnaissance
AWS recon covering S3, IAM, CloudFront, and asset exposure mapping
AWS Account ID and IAM Discovery
Techniques for enumerating AWS Account IDs and IAM principals using unauthenticated and authenticated methods to map cloud identity attack surface.
AWS Asset Exposure Mapping
Identify and enumerate publicly exposed AWS assets including S3 buckets, EC2 instances, APIs, and misconfigured IAM policies to map an organisation's attack surface.
Route53 and CloudFront Reconnaissance
Enumerate AWS Route53 DNS records and CloudFront distributions to map target infrastructure, identify origins, uncover misconfigurations, and expose hidden endpoints.
S3 Bucket Discovery
Techniques for discovering exposed AWS S3 buckets through permutation, DNS enumeration, and metadata analysis to identify misconfigured storage assets.