Marcus Delacroix
Security Engineering Director
Marcus runs red team exercises against cloud control planes for a living. He teaches identity as the real network perimeter, because in practice it is.
Cloud Security When the Network No Longer Protects You
Cloud breaches rarely start with a kernel exploit. They start with an over-scoped role, a forgotten trust policy, or a service account key in a repository. The network perimeter you were trained to defend has been replaced by an identity graph most teams have never drawn.
Marcus Delacroix walks through real attack paths across AWS and GCP — privilege escalation via PassRole, cross-account trust abuse, service account impersonation chains, metadata service pivots — and then shows the policy design that closes each one.
This is a defensive book written from the attacker's side of the table, intended for teams who own their own cloud security posture.
8 chapters · 428 pages total
Security Engineering Director
Marcus runs red team exercises against cloud control planes for a living. He teaches identity as the real network perimeter, because in practice it is.