Hybrid Multi-Cloud Red Team Specialist
Attack-path thinking for AWS, Azure, and Active Directory in real hybrid environments
This 3 to 5 day course is built from the structure of the CHMRTS, but with all the focus sharpened around AWS, Azure, and on-premises Active Directory. It also reflects today’s threat reality, where identity abuse, public-facing application exploitation, password spraying, and cloud-to-on-prem pivot paths remain central concerns, and where ATT&CK continues to maintain dedicated cloud and identity-provider coverage for real-world adversary tradecraft.
This course is delivered by an instructor with over 30 years of industry experience and is designed around real industry-demanded content rather than academic abstraction. The result is a practical, operations-minded program that helps learners understand how hybrid attack paths are modeled, exercised, mapped, and reported in modern enterprise environments.
Learning outcomes
- Understand the structure and security characteristics of hybrid environments spanning AWS, Azure, and on-premises Active Directory.
- Identify major trust boundaries, identity dependencies, and attack surfaces across cloud and enterprise environments.
- Analyze how red team operations align to the MITRE ATT&CK Enterprise and Cloud matrices.
- Evaluate common categories of hybrid attack paths involving reconnaissance, initial access, privilege escalation, persistence, credential access, and lateral movement.
- Distinguish platform-specific risks in AWS, Azure, and Active Directory without treating them as isolated silos.
- Plan red team infrastructure, tooling strategy, and operational workflows for hybrid assessments.
- Map technical findings into realistic organizational impact narratives and reporting structures.
- Interpret cloud and identity-centric threat trends that make hybrid red team capability strategically relevant today.
Prerequisites
- Working knowledge of TCP/IP, DNS, authentication, and enterprise networking
- Basic familiarity with AWS and Azure administration concepts
- Foundational understanding of Active Directory, Windows security, and common identity services
- Prior exposure to penetration testing, red teaming, or adversary emulation concepts
- Comfort with command-line tooling (both Windows and Linux), scripting basics, and security assessment workflows
- Familiarity with security logging, IAM concepts, and role-based access control
- General understanding of MITRE ATT&CK terminology is helpful but not required
Detailed training outline
- Course foundations and hybrid threat context
- What defines a hybrid multi-cloud environment
- Why hybrid estates create compound attack surfaces
- Control plane, identity plane, and workload plane relationships
- Trust boundaries across AWS, Azure, and on-premises infrastructure
- Business drivers behind hybrid architecture adoption
- Security consequences of federation, synchronization, and delegated administration
- Current threat relevance
- Identity-led attack patterns
- Public-facing exposure in cloud-connected enterprises
- Password spraying and credential abuse in enterprise ecosystems
- ATT&CK cloud and identity-provider alignment for red team planning
- Hybrid multi-cloud environment overview
- On-premise architecture
- Core enterprise infrastructure components
- Domain services and identity dependencies
- Administrative tiers and trust relationships
- Connectivity models to cloud services
- Multi-cloud architecture
- Shared versus isolated operating models
- Identity centralization versus platform-native identity
- Management plane exposure and operational complexity
- Hybrid multi-cloud architecture
- Integration patterns between cloud and enterprise identity
- Workload placement and connectivity assumptions
- Cross-platform administration and support paths
- Security implications of hybrid join, federation, and sync
- On-premise versus multi-cloud versus hybrid comparison
- Visibility differences
- Attack surface differences
- Detection and response considerations
- Governance and operational maturity challenges
- On-premise architecture
- AWS environment introduction and enumeration
- AWS cloud overview
- Account structure and organizational models
- Shared responsibility implications for red team assessments
- Core services commonly in scope
- Identity and Access Management
- Users, groups, roles, and policies
- Permission boundaries and effective access
- Temporary credentials and role assumption concepts
- Federation and identity integration
- Enterprise identity integration patterns
- External identity providers and trust assumptions
- Session-based access and operational risk
- Cross-account access
- Trust relationships between accounts
- Administrative delegation models
- Role chaining and boundary considerations
- AWS enumeration strategy
- Manual enumeration themes
- Automated asset and identity discovery themes
- Access review and privilege mapping
- Service exposure mapping
- Cross-account relationship analysis
- AWS cloud overview
- Azure environment introduction and enumeration
- Azure cloud overview
- Tenant, subscription, resource group, and management concepts
- Separation of identity and resource management planes
- Azure Active Directory and cloud identity
- Tenant structure and administrative model
- Users, groups, service principals, managed identities, and applications
- Role design and privilege distribution
- Azure Resource Manager
- IaaS, PaaS, and SaaS control boundaries
- Deployment hierarchy and governance constructs
- Resource access versus directory access
- Multi-tenant access
- B2B and external collaboration concepts
- Cross-tenant trust considerations
- Delegated access models
- Roles and RBAC
- Directory roles
- Azure RBAC
- Privileged administration paths
- Scope inheritance and access sprawl
- Microsoft 365 and Office 365 security context
- Collaboration surfaces and identity exposure
- SaaS-to-directory risk relationships
- Azure enumeration strategy
- Manual identity and application review
- Tenant and subscription visibility mapping
- Role and access relationship analysis
- Administrative surface discovery
- Automated assessment themes for Azure environments
- Azure cloud overview
- On-premises Active Directory introduction and enumeration
- On-premise infrastructure overview
- Domain topology
- Administrative boundaries
- Core services and dependency chains
- Active Directory fundamentals
- Forests, domains, trusts, and organizational units
- Kerberos and directory-based authorization concepts
- Identity lifecycle and administrative delegation
- Cross-forest access
- Trust design
- Cross-forest privilege considerations
- Enterprise sprawl and inherited risk
- Authentication and authorization in Active Directory
- Authentication flows
- Privilege assignment
- Service account exposure
- Delegation models
- On-premise to cloud connectivity
- Sync and federation patterns
- Hybrid identity dependencies
- Enterprise application integration
- AD enumeration strategy
- Identity mapping
- Trust mapping
- Privileged group and delegation review
- Infrastructure and endpoint visibility
- Manual and automated enumeration themes
- On-premise infrastructure overview
- Reconnaissance and external profiling in hybrid environments
- Targeted organization profiling
- Business footprint mapping
- Technology stack inference
- Identity and brand surface analysis
- Open-source information gathering across hybrid estates
- Cloud footprint discovery themes
- Internet-facing platform identification
- Documentation and metadata leakage awareness
- Unauthenticated service enumeration
- Tenant and service discovery concepts
- Exposure validation themes
- External identity endpoint visibility
- Password spray risk in enterprise identity ecosystems
- Why spray attacks remain relevant
- Hybrid identity exposure patterns
- Defensive implications for red team simulation
- Leaked credential exposure
- Cloud and enterprise credential risk categories
- Access validation workflow design
- Escalation of business impact through trust relationships
- Targeted organization profiling
- Initial access in hybrid environments
- Public-facing application compromise pathways
- Cloud-hosted and enterprise-hosted exposure categories
- Application-to-identity implications
- Application-to-control-plane impact pathways
- Access through leaked or mismanaged credentials
- Cloud credential categories
- Session and token risk
- Enterprise credential crossover risk
- On-premise spoofing and trust abuse concepts
- Identity trust weaknesses
- Environmental assumptions that enable access
- Phishing and consent-based abuse in Azure-centric ecosystems
- User consent risk
- Enterprise application abuse themes
- SaaS-integrated identity compromise paths
- Public-facing application compromise pathways
- Privilege escalation across cloud and enterprise platforms
- Misuse of serverless and automation components
- Execution context as an escalation surface
- Secrets exposure through automation
- Privileged runtime abuse patterns
- Azure automation misuse
- Automation accounts and privileged workflows
- Runbook and identity context considerations
- Excess IAM permission exploitation
- Over-privileged identities
- Privilege graph analysis
- Control plane escalation pathways
- Active Directory privilege escalation concepts
- Replication-related privilege concerns
- Delegation abuse themes
- Administrative trust collapse
- Misuse of serverless and automation components
- Persistence in hybrid environments
- Cross-account and delegated-access persistence in AWS
- Long-term trust abuse concepts
- Role and access persistence themes
- Azure application and directory persistence
- Enterprise applications as a persistence surface
- Service principal abuse concepts
- Tenant-level persistence considerations
- Active Directory persistence concepts
- Ticketing and trust durability risks
- Backdoor placement categories
- Administrative recovery implications
- Persistence strategy comparison across AWS, Azure, and AD
- Identity-based persistence
- Configuration-based persistence
- Trust-based persistence
- Cross-account and delegated-access persistence in AWS
- Credential access in cloud and hybrid estates
- AWS role and identity abuse themes
- Temporary credential exposure
- Metadata and runtime-derived identity risk
- Chained access possibilities
- Azure Key Vault and secret management risk
- Secret concentration and privilege implications
- Access policy and RBAC exposure
- Automation-driven secret access concerns
- Memory and secret extraction concepts in enterprise environments
- Endpoint and server credential residue
- Service account material exposure
- Identity relay into cloud-connected systems
- AWS role and identity abuse themes
- Lateral movement across hybrid trust boundaries
- Breaking cloud and enterprise segmentation assumptions
- Network boundary misconceptions
- Identity-driven movement versus network-driven movement
- Azure hybrid-joined device compromise concepts
- Device identity as a pivot layer
- Endpoint-to-directory trust implications
- On-premise to cloud lateral movement
- Seamless SSO and hybrid identity exposure
- Federation-linked movement paths
- Administrative workstation and sync-server significance
- Cloud to on-premise lateral movement
- Identity synchronization trust paths
- Administrative credential crossover
- Workload-to-directory adjacency
- Breaking cloud and enterprise segmentation assumptions
- Red team operations overview for hybrid environments
- AWS versus Azure versus Active Directory
- Platform differences in visibility
- Platform differences in privilege models
- Platform differences in operational tradecraft
- Red team infrastructure setup
- Assessment infrastructure planning
- Segregation, logging, and operational hygiene
- Identity-safe and evidence-safe operating practices
- Red team arsenal for hybrid environments
- Cloud assessment tooling categories
- Identity analysis tooling categories
- Automation, scripting, and orchestration considerations
- Evidence management and reporting support tools
- AWS versus Azure versus Active Directory
- MITRE ATT&CK alignment for enterprise and cloud operations
- Unauthenticated enumeration
- Initial access
- Authenticated enumeration
- Privilege escalation
- Persistence
- Credential access
- Discovery
- Lateral movement
- Data exfiltration
- Using ATT&CK to structure planning
- Scoping
- Coverage analysis
- Exercise design
- Reporting and executive mapping
- Full-spectrum hybrid red team exercise design
- Objective-driven operation planning
- Cloud-to-on-premise compromise narrative
- On-premise-to-cloud compromise narrative
- Chaining identity, workload, and control plane findings
- Attack path prioritization based on business impact
- Detection engineering touchpoints for purple team value
- Rules of engagement and safety boundaries
- Evidence collection and deconfliction
- Reporting structure
- Technical findings
- Attack path storyline
- Business risk articulation
- Strategic remediation themes
- Objective-driven operation planning
- Course wrap-up and applied outcomes
- Hybrid attack path review
- Cross-platform risk comparison
- Common failure patterns in real environments
- Translating red team observations into hardening priorities
- Building an internal roadmap for hybrid adversary simulation maturity
Practical, connected learning
My wider training approach brings hands-on implementation and systems thinking together, connecting technology with real operational needs.