The provider secures the hardware. Everything you configured on top of it is your problem.
You start by finding out which zone you're actually standing in. IaaS, PaaS, SaaS — the line between what AWS secures and what you secure moves depending on the service model, and most breaches happen because someone assumed the provider had it covered. Nugget doesn't hand you that line as a diagram to memorize; it puts a specific resource in front of you — a misconfigured S3 bucket, an over-permissioned Lambda role — and asks whose zone it's in.
From there the sessions follow where the actual damage happens: identity. You'll work through why a 'read-only' role can still exfiltrate an entire customer database, why SSO doesn't cover the service accounts and CI/CD runners quietly holding standing permissions nobody audited, and what it would take to shrink that blast radius to a 15-minute window instead of a permanent grant. The Snowflake breach comes up here — not as a cautionary tale you skim, but as a pattern you reconstruct: valid credentials, no MFA, no anomaly detection. No exploit code required.
Nugget sketches the kill chain on the whiteboard first — credential theft, GetCallerIdentity, enumeration, escalation — then works you across each link with questions, so you're reasoning about where the chain breaks rather than watching someone else find it.
Start exploring Cloud Security tonight — a 30-day trial, cancel anytime.
Start your 30-day trial