← All hands-on labs
AWS Security LabsIntermediate~75 minBrowser · no setup3 launches · 7-day window

IAM privilege escalation

Trace and break real IAM escalation chains, then apply least-privilege.

IAMPrivilege EscalationLeast PrivilegePolicy Analysis

What you'll do

  • Work in a real, isolated AWS environment — nothing to install or set up
  • Find and exploit the weakness the way an attacker would
  • Apply the fix and verify it like a defender
  • Map what you did back to real-world controls and frameworks

Skills you'll gain

  • Identifying IAM privilege-escalation paths
  • Policy analysis with SimulatePrincipalPolicy
  • Least-privilege policy design
  • STS & role-assumption controls

Roles this maps to

Cloud Security EngineerPenetration TesterSecurity Consultant

Practical, job-aligned skills you can put on a résumé and demonstrate in interviews — proven against real cloud state, not multiple-choice.

You won't get stuck

Hit Check my work — graded against the live AWS account.

No static checklist. Our auto-grader assumes a role in your lab account and verifies real cloud state — if you only half-fixed it, you'll know. Per-objective ✅ / ⬜, instant.

Ready to launch this lab?

Spin it up in your browser — no setup. Your first lab is free.

24 people viewing now