Cloud Penetration Testing
AWS, Azure and GCP, tested offensively.
Identity, network and exposed-service testing across your cloud estate, mapped to attacker paths. Standalone, or paired with a web pentest to test the application and the cloud it runs on.
What it is
Testing starts where an attacker starts — a leaked key, a compromised CI runner, an SSRF in the application — and follows the path to your data.
IAM privilege escalation, storage exposure, cross-account trust abuse, VPC and security-group blind spots, instance-metadata abuse, CI/CD paths into production.
Method
- Assumed-breach start: leaked key, compromised CI runner or SSRF foothold
- IAM blast-radius mapping — who can become whom, and how
- Privilege-escalation chains: misconfigured trust, pass-role abuse,
sts:AssumeRole - Storage exposure across S3, Blob and GCS, public and cross-account
- Network: VPC peering, security groups, egress paths, exposed services
- Compute: instance metadata, IMDSv1, AMIs, container and Kubernetes posture
- CI/CD supply-chain paths into the production environment
- Detection coverage in CloudTrail, Activity Logs and Audit Logs
What you get
- Attacker-path narratives
- IAM blast-radius map for the riskiest principals
- Reproducible privilege-escalation chains with the exact commands
Related services
Web Application Penetration Testing
Web, REST, GraphQL and SOAP. Manual-first, exploit-validated, fix-prioritised.
View service →Network Penetration Testing
Perimeter, internal estate, Active Directory, segmentation.
View service →Vulnerability Assessment
Breadth-first sweep, manual triage, prioritised by exploitability.
View service →Ready to scope this engagement?
One email is enough to start. Tell us roughly what you want tested and we'll come back with a scoping call slot inside one business day.