Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of VAPT7 services in this practice area

Config and IAM Attack Paths

Cloud Penetration Testing

Cloud breaches rarely start with a zero-day. They start with an over-permissive role, a public bucket or a forgotten key. We review your configuration and then follow the IAM paths a real attacker would use.

See the engagement path, 6 phasesSee the full VAPT service index

Overview

A cloud VAPT combines a configuration review with real attack-path testing across AWS, Azure, GCP, DigitalOcean and Oracle Cloud. We benchmark your accounts against solid baselines, then go further and show how identity and access management flaws chain into privilege escalation and access to your data. You get both the misconfiguration list and the proof of what an attacker does with the ones that matter.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Cloud engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Rules of Engagement. We agree the accounts, subscriptions and projects in scope, the provider mix, and the read-only and test roles we will use. Activities: Confirm accounts, subscriptions and projects; Agree the provider mix in scope; Provision read-only and test roles; Set testing windows and contacts. Hands over Signed Rules of Engagement. Phase 2, Configuration Review. We assess your accounts against CIS Benchmarks and provider baselines, covering storage, networking, logging and encryption. Activities: Benchmark accounts against CIS baselines; Review storage and network exposure; Check logging and monitoring coverage; Assess encryption at rest and in transit. Hands over Configuration Review Findings. Phase 3, IAM and Identity Analysis. We map roles, policies and trust relationships to find over-permissive access, weak boundaries and risky federation. Activities: Map roles, policies and trust relationships; Find over-permissive and unused access; Assess account and service boundaries; Review federation and identity providers. Hands over IAM Analysis Findings. Phase 4, Manual Exploitation. We follow identity attack paths, escalating privileges and pivoting between services the way an attacker with a foothold would. Activities: Follow identity attack paths from a foothold; Escalate privileges across roles; Pivot between services and accounts; Confirm impact and rule out false positives. Hands over Proven Attack Paths. Phase 5, Post-Exploitation and Impact. We show what the chained paths reach, from data stores to secrets and workloads, and how far a single leaked credential goes. Activities: Show what chained paths reach; Map exposed data stores, secrets and workloads; Trace the blast radius of a leaked credential; Rank findings by real impact. Hands over Impact and Risk Assessment. Phase 6, Reporting and Verified Retest. You get a report with attack paths and prioritised fixes per provider, and we retest once you remediate to confirm closure. Activities: Document attack paths and per-provider fixes; Produce an executive summary; Walk your team through the results; Retest fixes and confirm closure. Hands over Final Report and Verified Retest. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Rules of Engagement

We agree the accounts, subscriptions and projects in scope, the provider mix, and the read-only and test roles we will use.

What Happens In This Phase

  • Confirm accounts, subscriptions and projects
  • Agree the provider mix in scope
  • Provision read-only and test roles
  • Set testing windows and contacts

The Handover

Signed Rules of Engagement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Rules of Engagement

    We agree the accounts, subscriptions and projects in scope, the provider mix, and the read-only and test roles we will use.

    OutputSigned Rules of Engagement

    Activities

    • Confirm accounts, subscriptions and projects
    • Agree the provider mix in scope
    • Provision read-only and test roles
    • Set testing windows and contacts
  2. 02

    Configuration Review

    We assess your accounts against CIS Benchmarks and provider baselines, covering storage, networking, logging and encryption.

    OutputConfiguration Review Findings

    Activities

    • Benchmark accounts against CIS baselines
    • Review storage and network exposure
    • Check logging and monitoring coverage
    • Assess encryption at rest and in transit
  3. 03

    IAM and Identity Analysis

    We map roles, policies and trust relationships to find over-permissive access, weak boundaries and risky federation.

    OutputIAM Analysis Findings

    Activities

    • Map roles, policies and trust relationships
    • Find over-permissive and unused access
    • Assess account and service boundaries
    • Review federation and identity providers
  4. 04

    Manual Exploitation

    We follow identity attack paths, escalating privileges and pivoting between services the way an attacker with a foothold would.

    OutputProven Attack Paths

    Activities

    • Follow identity attack paths from a foothold
    • Escalate privileges across roles
    • Pivot between services and accounts
    • Confirm impact and rule out false positives
  5. 05

    Post-Exploitation and Impact

    We show what the chained paths reach, from data stores to secrets and workloads, and how far a single leaked credential goes.

    OutputImpact and Risk Assessment

    Activities

    • Show what chained paths reach
    • Map exposed data stores, secrets and workloads
    • Trace the blast radius of a leaked credential
    • Rank findings by real impact
  6. 06

    Reporting and Verified Retest

    You get a report with attack paths and prioritised fixes per provider, and we retest once you remediate to confirm closure.

    OutputFinal Report and Verified Retest

    Activities

    • Document attack paths and per-provider fixes
    • Produce an executive summary
    • Walk your team through the results
    • Retest fixes and confirm closure

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Cloud scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: ScoutSuite, Prowler, Pacu, CloudMapper, trivy, kube-hunter, Nuclei, AWS, Azure and GCP CLIs. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: CIS Benchmarks, MITRE ATT&CK for Cloud, OWASP Cloud-Native Application Security Top 10, NIST SP 800-115, PTES, CVSS v4.0.

What We Run

8 tools

  • ScoutSuite
  • Prowler
  • Pacu
  • CloudMapper
  • trivy
  • kube-hunter
  • Nuclei
  • AWS, Azure and GCP CLIs

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

6 standards

  • CISBenchmarks
  • MITRE ATT&CK for Cloud
  • OWASPTop 10Cloud-Native
  • NIST SP 800-115
  • PTES
  • CVSS v4.0
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Findings report with mapped attack paths
  • Configuration review against CIS Benchmarks
  • Executive summary
  • Remediation guidance
  • Verified retest report

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Which cloud providers do you cover?

AWS, Azure, GCP, DigitalOcean and Oracle Cloud. We tailor the review to each provider's services and identity model, since the misconfigurations and attack paths differ between them.

How is this different from a scanner or a CSPM tool?

Those give you a configuration list. We use similar tooling to start, then go further and prove the attack paths, showing how an over-permissive role actually leads to your data.

What access do you need?

Usually a read-only role to assess configuration, plus limited test roles to safely demonstrate privilege escalation. We agree the exact permissions in scoping and stay within them.

Keep Moving Through VAPT

Service 7 of 7 in this practice area