Skip to content
Security incident? Call: +48 732 059 711
Cloud pentest

Cloud is not secure by default

AWS, Azure and GCP — tested for IAM misconfigurations, privilege escalation paths and data exposure. We find what your CSPM tool misses.

Who is it for?

  • SaaS platforms on AWS / Azure / GCP
  • Fintech migrating to cloud
  • Hybrid environments
  • Kubernetes workloads
  • Multi-account / multi-subscription setups
What you get

Outcomes

IAM privilege escalation paths

We map the full privilege graph and find every path that leads to account compromise.

Misconfigurations that matter

Public S3 buckets, overly permissive IAM policies, exposed storage accounts, open security groups.

CIS benchmark gaps

We test against CIS AWS / Azure / GCP benchmarks and flag every gap with business context.

Container & Kubernetes security

EKS/AKS/GKE, pod escape, RBAC abuse, exposed kubelet, insecure images.

Secrets & credentials

Hardcoded keys, exposed environment variables, credentials in git history and Terraform state.

Free retest

One free retest within 30 days — we verify fixes and update the final report.

How we work

Configuration review + attack simulation

  1. 01

    Scoping

    Accounts/subscriptions, services in scope, test credentials (read-only audit + optional test user), exclusions.

  2. 02

    Configuration review

    Automated baseline (CIS benchmarks, Prowler, ScoutSuite) + manual review of risky configurations.

  3. 03

    Attack simulation

    We exploit misconfigurations from the perspective of a compromised identity — privilege escalation, lateral movement, data exfiltration.

  4. 04

    Report & retest

    Executive + technical report in 5 business days. Free retest within 30 days.

FAQ

Frequently asked questions

Do you need production access?
We need read-only audit access (IAM role or equivalent) and optionally a test user for attack simulation.
Which CSPs do you cover?
AWS, Azure, GCP. We also test Kubernetes (EKS/AKS/GKE) and typical SaaS integrations.
Is this a CSPM scan?
No. CSPM is part of the baseline — we go further: manual exploitation, privilege escalation, real attack paths.
How long does it take?
Single account: 7–10 days. Multi-account / multi-cloud: 10–15 days.
Does this satisfy AWS / Azure pentest policy?
Yes. Current AWS and Azure policies allow testing without prior notification for most services.

Scope your cloud pentest

Tell us the CSP and scope — we will come back with a plan, timeline and price within one business day.