Service

Cloud Penetration Testing

AWS, Azure and GCP, tested offensively.

Identity, network and exposed-service testing across your cloud estate, mapped to attacker paths. Standalone, or paired with a web pentest to test the application and the cloud it runs on.

What it is

Testing starts where an attacker starts — a leaked key, a compromised CI runner, an SSRF in the application — and follows the path to your data.

IAM privilege escalation, storage exposure, cross-account trust abuse, VPC and security-group blind spots, instance-metadata abuse, CI/CD paths into production.

Method

  • Assumed-breach start: leaked key, compromised CI runner or SSRF foothold
  • IAM blast-radius mapping — who can become whom, and how
  • Privilege-escalation chains: misconfigured trust, pass-role abuse, sts:AssumeRole
  • Storage exposure across S3, Blob and GCS, public and cross-account
  • Network: VPC peering, security groups, egress paths, exposed services
  • Compute: instance metadata, IMDSv1, AMIs, container and Kubernetes posture
  • CI/CD supply-chain paths into the production environment
  • Detection coverage in CloudTrail, Activity Logs and Audit Logs

What you get

  • Attacker-path narratives
  • IAM blast-radius map for the riskiest principals
  • Reproducible privilege-escalation chains with the exact commands

Ready to scope this engagement?

One email is enough to start. Tell us roughly what you want tested and we'll come back with a scoping call slot inside one business day.