This document is the master's thesis of Réka Szabó titled "Penetration testing of aws-based environments". The thesis investigates how penetration testing techniques can be applied specifically to AWS environments. It outlines a general penetration testing methodology for AWS, integrating existing tools into the process. A major focus is on authenticated penetration tests, where credentials are provided to allow testing for internal misconfigurations. The thesis contains chapters on AWS services, common AWS security issues, penetration testing methodology, and describes conducting both non-authenticated and authenticated penetration tests of AWS environments.