Config and IAM Attack Paths
Cloud Penetration Testing
Cloud breaches rarely start with a zero-day. They start with an over-permissive role, a public bucket or a forgotten key. We review your configuration and then follow the IAM paths a real attacker would use.
See the engagement path, 6 phasesSee the full VAPT service index
Overview
A cloud VAPT combines a configuration review with real attack-path testing across AWS, Azure, GCP, DigitalOcean and Oracle Cloud. We benchmark your accounts against solid baselines, then go further and show how identity and access management flaws chain into privilege escalation and access to your data. You get both the misconfiguration list and the proof of what an attacker does with the ones that matter.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Cloud engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Rules of Engagement. We agree the accounts, subscriptions and projects in scope, the provider mix, and the read-only and test roles we will use. Activities: Confirm accounts, subscriptions and projects; Agree the provider mix in scope; Provision read-only and test roles; Set testing windows and contacts. Hands over Signed Rules of Engagement. Phase 2, Configuration Review. We assess your accounts against CIS Benchmarks and provider baselines, covering storage, networking, logging and encryption. Activities: Benchmark accounts against CIS baselines; Review storage and network exposure; Check logging and monitoring coverage; Assess encryption at rest and in transit. Hands over Configuration Review Findings. Phase 3, IAM and Identity Analysis. We map roles, policies and trust relationships to find over-permissive access, weak boundaries and risky federation. Activities: Map roles, policies and trust relationships; Find over-permissive and unused access; Assess account and service boundaries; Review federation and identity providers. Hands over IAM Analysis Findings. Phase 4, Manual Exploitation. We follow identity attack paths, escalating privileges and pivoting between services the way an attacker with a foothold would. Activities: Follow identity attack paths from a foothold; Escalate privileges across roles; Pivot between services and accounts; Confirm impact and rule out false positives. Hands over Proven Attack Paths. Phase 5, Post-Exploitation and Impact. We show what the chained paths reach, from data stores to secrets and workloads, and how far a single leaked credential goes. Activities: Show what chained paths reach; Map exposed data stores, secrets and workloads; Trace the blast radius of a leaked credential; Rank findings by real impact. Hands over Impact and Risk Assessment. Phase 6, Reporting and Verified Retest. You get a report with attack paths and prioritised fixes per provider, and we retest once you remediate to confirm closure. Activities: Document attack paths and per-provider fixes; Produce an executive summary; Walk your team through the results; Retest fixes and confirm closure. Hands over Final Report and Verified Retest. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Rules of Engagement
We agree the accounts, subscriptions and projects in scope, the provider mix, and the read-only and test roles we will use.
What Happens In This Phase
- Confirm accounts, subscriptions and projects
- Agree the provider mix in scope
- Provision read-only and test roles
- Set testing windows and contacts
The Handover
Signed Rules of Engagement
The next phase starts from this.
Phase 01 Scoping and Rules of Engagement
We agree the accounts, subscriptions and projects in scope, the provider mix, and the read-only and test roles we will use.
What Happens In This Phase
- Confirm accounts, subscriptions and projects
- Agree the provider mix in scope
- Provision read-only and test roles
- Set testing windows and contacts
The Handover
Signed Rules of Engagement
The next phase starts from this.
- 01
Scoping and Rules of Engagement
We agree the accounts, subscriptions and projects in scope, the provider mix, and the read-only and test roles we will use.
OutputSigned Rules of EngagementActivities
- Confirm accounts, subscriptions and projects
- Agree the provider mix in scope
- Provision read-only and test roles
- Set testing windows and contacts
- 02
Configuration Review
We assess your accounts against CIS Benchmarks and provider baselines, covering storage, networking, logging and encryption.
OutputConfiguration Review FindingsActivities
- Benchmark accounts against CIS baselines
- Review storage and network exposure
- Check logging and monitoring coverage
- Assess encryption at rest and in transit
- 03
IAM and Identity Analysis
We map roles, policies and trust relationships to find over-permissive access, weak boundaries and risky federation.
OutputIAM Analysis FindingsActivities
- Map roles, policies and trust relationships
- Find over-permissive and unused access
- Assess account and service boundaries
- Review federation and identity providers
- 04
Manual Exploitation
We follow identity attack paths, escalating privileges and pivoting between services the way an attacker with a foothold would.
OutputProven Attack PathsActivities
- Follow identity attack paths from a foothold
- Escalate privileges across roles
- Pivot between services and accounts
- Confirm impact and rule out false positives
- 05
Post-Exploitation and Impact
We show what the chained paths reach, from data stores to secrets and workloads, and how far a single leaked credential goes.
OutputImpact and Risk AssessmentActivities
- Show what chained paths reach
- Map exposed data stores, secrets and workloads
- Trace the blast radius of a leaked credential
- Rank findings by real impact
- 06
Reporting and Verified Retest
You get a report with attack paths and prioritised fixes per provider, and we retest once you remediate to confirm closure.
OutputFinal Report and Verified RetestActivities
- Document attack paths and per-provider fixes
- Produce an executive summary
- Walk your team through the results
- Retest fixes and confirm closure
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Cloud scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: ScoutSuite, Prowler, Pacu, CloudMapper, trivy, kube-hunter, Nuclei, AWS, Azure and GCP CLIs. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: CIS Benchmarks, MITRE ATT&CK for Cloud, OWASP Cloud-Native Application Security Top 10, NIST SP 800-115, PTES, CVSS v4.0.
What We Run
8 tools
- ScoutSuite
- Pacu
- CloudMapper
- kube-hunter
- AWS, Azure and GCP CLIs
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
6 standards
- CIS
- OWASPCloud-Native
- PTES
Deliverables
What You Receive
- Findings report with mapped attack paths
- Configuration review against CIS Benchmarks
- Executive summary
- Remediation guidance
- Verified retest report
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Which cloud providers do you cover?
AWS, Azure, GCP, DigitalOcean and Oracle Cloud. We tailor the review to each provider's services and identity model, since the misconfigurations and attack paths differ between them.
How is this different from a scanner or a CSPM tool?
Those give you a configuration list. We use similar tooling to start, then go further and prove the attack paths, showing how an over-permissive role actually leads to your data.
What access do you need?
Usually a read-only role to assess configuration, plus limited test roles to safely demonstrate privilege escalation. We agree the exact permissions in scoping and stay within them.
Keep Moving Through VAPT
Service 7 of 7 in this practice area
Practice Area
More in VAPT
- Web ApplicationManual testing of your web apps against the OWASP WSTG
- Mobile ApplicationAndroid and iOS app testing against the OWASP MASVS
- APIREST, GraphQL and SOAP testing against the OWASP API Top 10
- Thick Client ApplicationDesktop app testing across binary, traffic and backend
- Network InfrastructureExternal and internal network testing with lateral movement
- IoT and EmbeddedDevice testing across firmware, hardware and radio