Networking

AWS networking decides what is reachable: security groups that are too open, services bound to the internet, VPC peering and endpoints that let a foothold in one network reach another, and the DNS and edge services that front and route traffic. Networking rarely compromises an account on its own, but it is how a reachable foothold turns into reach across the environment, and how a trusted name is captured.

What folds in here#

  • Security groups: internet-exposed management ports and services from over-permissive ingress.
  • VPC: peering, endpoints, and routing to pivot between networks and accounts.
  • Route53: hijacking records and poisoning resolution where you hold zone write access.
  • CloudFront: origin disclosure and cache-behavior abuse to reach protected origins.
  • Dangling-DNS takeover: claiming the orphaned S3, CloudFront, or ELB resource behind a stale record.
  • Global Accelerator: listeners and endpoint groups to front endpoints behind trusted anycast IPs.
  • VPC Lattice: permissive service-network auth policies for cross-VPC and cross-account reach.
  • Direct Connect: virtual interfaces that bridge on-premises networks into the VPC.
  • Network Firewall: rule-group gaps and inspection teardown.
  • WAF: web ACL bypass through encoding, size limits, and origin-direct requests.

Network-layer lateral movement lives here; the identity-based cross-account movement through AssumeRole lives in identity.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more