[ Infrastructure ]
Cloud Penetration Testing
- Typical duration
- 5-10 days
- Starting price
- Scoped
- You provide
- Read-only audit role, plus a low-privilege identity
[ 01 / The engagement ]
Cloud breaches are identity breaches. The interesting question is not whether a bucket is public, it is what a single leaked access key can reach once it is used, which roles it can assume, which functions it can invoke, and how far that chain runs before something stops it. We test configuration and identity together, because separately neither one tells you the blast radius.
[ 02 / Coverage ]
What we test, in practice.
This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.
Methodology
- 01IAM privilege escalation and role assumption chains
- 02Storage, database and snapshot exposure across accounts
- 03Serverless function permissions and event-source abuse
- 04Container and Kubernetes escape, RBAC and admission control
- 05Metadata service access and SSRF-to-credential paths
- 06Cross-account trust, organisation and landing-zone boundaries
- 07Secrets management, key policy and logging coverage
[ 03 / What you get ]
Four things land at the end of every engagement.
Technical report
Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.
Executive summary
Two pages your board can read. Risk in business terms, with the three things that matter most called out.
Letter of attestation
A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.
Free retest
Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.
[ 04 / Questions ]
Before you commit.
For the vast majority of scopes, no, the major providers permit customer-initiated testing of your own resources. We confirm the current policy in writing during scoping and stay inside it.
No. A posture tool lists misconfigurations. We chain them, so you learn which combination actually reaches your data and which ones are noise.
Often scoped together
All services →External Network Penetration Testing
Everything of yours that answers from the internet, including what you forgot.
Internal Network Penetration Testing
We assume the perimeter already failed, and see how far one foothold travels.
Active Directory Security Assessment
The attack paths from any user to Domain Admin, mapped and proven.
Scope a cloud penetration testing.
Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.