Andrei
I'm a security engineer, pentester, and researcher who came to the field from a background in medicine. I've been hacking the web since 2019 and hold OSCP and OSWE
Happy to contribute to the community and exchange knowledge - come say hi, let's chat and stay in touch
Session
Your bug bounty / pentest scope is a list of ASN and domains. Your attack surface isn't.
Modern cloud architectures expand beyond those horizons - Lambda function URLs, API Gateway endpoints, S3 buckets, CloudFront distributions, container registries, and CI artifacts deploy outside the visible domain space, weakly monitored and missing from official scope.
So: whoarethey? This talk provides the answers to that key question - how to map a target company's cloud-heavy infrastructure with a pure black-box approach, beyond standard methods. Alongside a brief recap of the regular recon (acquisitions, subdomain enumeration) for completeness, the focus will be on cloud-asset recon. You will learn how to find all the APIs of any given cloud and almost all the cloud domains with user workloads or content - and how to attribute them to a specific company.
For hunters and pentesters tired of running the same methods against the same scope with the same results and wondering where the bugs went.