AWS networking decides what is reachable: security groups that are too open, services bound to the internet, VPC peering and endpoints that let a foothold in one network reach another, and the DNS and edge services that front and route traffic. Networking rarely compromises an account on its own, but it is how a reachable foothold turns into reach across the environment, and how a trusted name is captured.
What folds in here#
- Security groups: internet-exposed management ports and services from over-permissive ingress.
- VPC: peering, endpoints, and routing to pivot between networks and accounts.
- Route53: hijacking records and poisoning resolution where you hold zone write access.
- CloudFront: origin disclosure and cache-behavior abuse to reach protected origins.
- Dangling-DNS takeover: claiming the orphaned S3, CloudFront, or ELB resource behind a stale record.
- Global Accelerator: listeners and endpoint groups to front endpoints behind trusted anycast IPs.
- VPC Lattice: permissive service-network auth policies for cross-VPC and cross-account reach.
- Direct Connect: virtual interfaces that bridge on-premises networks into the VPC.
- Network Firewall: rule-group gaps and inspection teardown.
- WAF: web ACL bypass through encoding, size limits, and origin-direct requests.
Network-layer lateral movement lives here; the identity-based cross-account movement through AssumeRole lives in identity.