Skip to content
AttackVector

Is our cloud configured the way we think it is?

Cloud penetration test

A cloud penetration test assesses your AWS, Azure, or GCP environment from two directions: what an outsider can reach, and what a compromised identity or workload can do once inside. It focuses on identity, configuration, and the attack paths that connect them.

Point in timeTargets: TechnologyTypically 1 to 3 weeks depending on account count and complexity

What you get

  • Over-privileged identities and roles
  • Publicly exposed storage, services, and secrets
  • Attack paths across accounts and subscriptions

Overview

Cloud environments fail differently than data centers. We test identity and access design, storage exposure, network paths, insecure APIs, and the misconfigurations that turn a small mistake into a full account compromise, across AWS, Azure, and GCP.

Scope

What is typically in scope. The final list is agreed with you before testing starts.

  • Cloud accounts, subscriptions, and projects in scope
  • Identity and access management: users, roles, policies, and federation
  • Storage, databases, and secrets management exposure
  • Network design: security groups, peering, private endpoints
  • Compute, containers, and serverless configuration
  • Logging, monitoring, and alerting coverage
  • Infrastructure as code review where available

Methodology

Phases run in this order. Each one produces evidence that feeds the next.

  1. External reconnaissance

    We find what your cloud footprint exposes publicly: buckets, endpoints, and metadata leaked through DNS and certificates.

  2. Configuration review

    Read-only access is used to review identity, network, and storage configuration against provider best practice and attacker techniques.

  3. Assumed breach

    From a low-privilege identity or workload, we attempt privilege escalation and lateral movement across accounts.

  4. Data and control plane impact

    We show what a successful path reaches: sensitive data, deployment pipelines, or the ability to persist.

  5. Reporting

    Findings are prioritized by attack path and paired with provider-specific fixes.

Deliverables

  • Executive summary and cloud risk overview
  • Identity attack path diagrams
  • Findings with evidence, severity, and provider references
  • Exposed resource inventory
  • Logging and detection coverage notes
  • Prioritized remediation roadmap with provider-specific guidance
  • One retest of remediated findings

Sample report excerpt

One finding, in the structure every finding follows. The content is illustrative.

AttackVector · Cloud penetration test · Technical findingsIllustrative excerpt
CriticalFinding 1 of 19

Compute role permits privilege escalation to account administrator

Severity
Critical
Status
Open, retest pending
Affected assets
Listed in appendix A

Impact

Any attacker who compromised a single web server could use its attached role to create new administrative credentials and take over the entire cloud account.

Evidence

From the instance role, a new access key was created for an administrative principal in the test account and used to list all resources.

Screenshot and request/response evidence appear here

Remediation

Apply least privilege to instance and workload roles, remove permissions that allow creating or modifying credentials and policies, and enable alerting on privilege changes.

Verification

Retested after remediation. Result and date are recorded here and reflected in the attestation letter.

Every finding follows this structure.Download the full sample report

Timeline

Typical duration

Typically 1 to 3 weeks depending on account count and complexity

What affects it

Single-account environments finish in about a week. Multi-account organizations and hybrid connectivity add time. Read-only audit credentials should be provisioned before testing starts.

Compliance drivers

Need this for an audit or renewal? This test provides accepted evidence for PCI DSS, HIPAA, SOC 2, ISO 27001.

See the full requirement mapping

Frequently asked questions

How long does a cloud penetration test take?

Typically one to three weeks. Account count, the number of services in use, and hybrid connectivity drive the duration.

Do you need credentials?

Yes, for the configuration review and assumed breach phases we use a read-only audit role plus a low-privilege identity you create for the test. External reconnaissance needs nothing.

Does this cover the applications running in the cloud?

It covers the cloud platform and its configuration. Applications are best tested with a web application test, and we often run both together.

Is a retest included?

Yes. One retest of remediated findings is included.

Which providers do you test?

AWS, Microsoft Azure, and Google Cloud, including hybrid environments that connect back to on-premises networks.

Ready to scope a cloud penetration test?

Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.