Core Service
FILE · OIU-SVC

Cloud Breaches Are Identity Breaches.

Misconfigured IAM, over-permissive roles, and forgotten service principals are how cloud environments fall. We test AWS, Azure, and GCP the way real attackers move through them: from one assumed role to the next, until the blast radius is the whole account.

Definition Cloud penetration testing is manual adversarial assessment of public cloud environments covering identity and access management abuse, service-level misconfigurations, data-store exposure, and lateral movement across accounts and tenants.

Last reviewed:

File 01 · Definition

What It Is

Identity is where it turns. We start from a foothold credential and follow the role assumptions, trust policies, and service principals that let one identity become another, across IAM abuse, service-level misconfigurations, data-store exposure, and lateral movement between accounts and tenants.

Because a cloud compromise is a chain of role assumptions rather than a single exploit, every privilege-escalation path is reproduced by hand and written up as a step-by-step trace your platform team can follow from the original credential to the data at the end.

Reports map IAM findings to CIS Benchmarks and provider best practices, and to SOC 2, HIPAA, and PCI DSS where regulated data lives in the environment.

The findings that end accounts are rarely zero-days. They are over-privileged roles, exposed access keys, and trust relationships that should not exist, and a CSPM dashboard scores each one in isolation while ignoring how they connect. Turning three medium findings into a cross-account compromise is the manual exercise we run before an attacker does, when the blast radius is your whole environment instead of one bucket.

File 02 · Threat Model

Why Companies Need This

  • 01 You run multi-account or multi-tenant cloud. Cross-account trust paths are the most-exploited and least-tested layer.
  • 02 Your team ships IaC at speed. Terraform and CloudFormation move faster than review cycles. Drift creates exploitable gaps.
  • 03 You hold regulated data in the cloud. SOC 2, HIPAA, PCI examiners expect evidence of cloud-specific manual testing, not generic CSPM exports.
  • 04 You suspect over-permissioning. If no one has audited IAM in twelve months, our engagements almost always find roles holding more than the job requires.

File 03 · Deliverables

What You Get

Unlimited remediation validation included. No time cap, no per-finding charge. How it works

Detailed technical report

CVSS scoring, attack narratives, and proof-of-concept evidence

Executive summary

Findings translated into business risk, not CVSS noise.

Remediation guidance

Prioritized, actionable fixes, not just a list of CVEs

Real-time comms

Dedicated Slack channel for the engagement.

Compliance documentation

Mapped to SOC 2, PCI DSS, HIPAA, ISO 27001, and CMMC

File 04 · Methodology

Our Process

01 MAP

Inventory & Identity Mapping

Account and subscription discovery, IAM role and policy enumeration, trust-relationship mapping across accounts and tenants.

02 TRIAGE

Misconfiguration Triage

Public storage exposure, over-permissive policies, exposed metadata endpoints, weak resource-level controls, secrets in code or environment.

03 ESCAL

Identity Abuse & Privilege Escalation

Role assumption abuse, service-principal hijack, token theft and replay, privilege-escalation paths through chained policy weaknesses.

04 LATERAL

Lateral Movement & Impact

Cross-account pivots, data-store enumeration, demonstration of business impact, blast-radius mapping.

05 VALIDATE

Reporting & Retest

Attack-path narratives, IAM hardening guidance, mapped to CIS Benchmarks and provider best practices. Verification retest included.

File 05 · Intel Brief

Frequently Asked Questions

Q1 Do we need cloud-provider approval first?

AWS, Azure, and GCP each have current rules of engagement. We help confirm coverage and request approval where required before any testing starts.

Q2 Do you test container and Kubernetes workloads?

Yes. Container, EKS/AKS/GKE, and serverless attack surface is part of cloud pentests when in scope. Dedicated Kubernetes engagements are also available.

Q3 How does this differ from a CSPM tool?

CSPM scores configuration. We exploit it. Our deliverable is attack paths and demonstrated impact, not a config-drift dashboard.

Talk to an Operator

Your IAM Is One Over-Permissive Role Away From a Cross-Account Compromise.

30 minutes with the operator who runs the test. Bring your account structure and we will walk the IAM trust paths that worry us most.