Is our cloud configured the way we think it is?
Cloud penetration test
A cloud penetration test assesses your AWS, Azure, or GCP environment from two directions: what an outsider can reach, and what a compromised identity or workload can do once inside. It focuses on identity, configuration, and the attack paths that connect them.
What you get
- Over-privileged identities and roles
- Publicly exposed storage, services, and secrets
- Attack paths across accounts and subscriptions
Overview
Cloud environments fail differently than data centers. We test identity and access design, storage exposure, network paths, insecure APIs, and the misconfigurations that turn a small mistake into a full account compromise, across AWS, Azure, and GCP.
Scope
What is typically in scope. The final list is agreed with you before testing starts.
- Cloud accounts, subscriptions, and projects in scope
- Identity and access management: users, roles, policies, and federation
- Storage, databases, and secrets management exposure
- Network design: security groups, peering, private endpoints
- Compute, containers, and serverless configuration
- Logging, monitoring, and alerting coverage
- Infrastructure as code review where available
Methodology
Phases run in this order. Each one produces evidence that feeds the next.
External reconnaissance
We find what your cloud footprint exposes publicly: buckets, endpoints, and metadata leaked through DNS and certificates.
Configuration review
Read-only access is used to review identity, network, and storage configuration against provider best practice and attacker techniques.
Assumed breach
From a low-privilege identity or workload, we attempt privilege escalation and lateral movement across accounts.
Data and control plane impact
We show what a successful path reaches: sensitive data, deployment pipelines, or the ability to persist.
Reporting
Findings are prioritized by attack path and paired with provider-specific fixes.
Deliverables
- Executive summary and cloud risk overview
- Identity attack path diagrams
- Findings with evidence, severity, and provider references
- Exposed resource inventory
- Logging and detection coverage notes
- Prioritized remediation roadmap with provider-specific guidance
- One retest of remediated findings
Sample report excerpt
One finding, in the structure every finding follows. The content is illustrative.
Compute role permits privilege escalation to account administrator
- Severity
- Critical
- Status
- Open, retest pending
- Affected assets
- Listed in appendix A
Impact
Any attacker who compromised a single web server could use its attached role to create new administrative credentials and take over the entire cloud account.
Evidence
From the instance role, a new access key was created for an administrative principal in the test account and used to list all resources.
Remediation
Apply least privilege to instance and workload roles, remove permissions that allow creating or modifying credentials and policies, and enable alerting on privilege changes.
Verification
Retested after remediation. Result and date are recorded here and reflected in the attestation letter.
Timeline
Typical duration
Typically 1 to 3 weeks depending on account count and complexity
What affects it
Single-account environments finish in about a week. Multi-account organizations and hybrid connectivity add time. Read-only audit credentials should be provisioned before testing starts.
Compliance drivers
Need this for an audit or renewal? This test provides accepted evidence for PCI DSS, HIPAA, SOC 2, ISO 27001.
See the full requirement mappingFrequently asked questions
How long does a cloud penetration test take?
Typically one to three weeks. Account count, the number of services in use, and hybrid connectivity drive the duration.
Do you need credentials?
Yes, for the configuration review and assumed breach phases we use a read-only audit role plus a low-privilege identity you create for the test. External reconnaissance needs nothing.
Does this cover the applications running in the cloud?
It covers the cloud platform and its configuration. Applications are best tested with a web application test, and we often run both together.
Is a retest included?
Yes. One retest of remediated findings is included.
Which providers do you test?
AWS, Microsoft Azure, and Google Cloud, including hybrid environments that connect back to on-premises networks.
Related
Often paired with
External penetration test
Can an outsider get in?
Your internet-facing perimeter, tested from the outside in.
Learn moreInternal penetration test
What damage can an insider do?
Assume the perimeter has failed. Find out what happens next.
Learn moreWeb application test
Can this application be turned against its users?
Deep, manual testing of one application and its APIs.
Learn moreReady to scope a cloud penetration test?
Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.