Home / Services

Cloud Pentest

Technical diagram of a cloud environment, relating identity and permissions (IAM), workloads and storage within the account

Cloud Pentest

Cloud computing has changed the way companies store data, build applications and deliver services. Platforms such as Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP) offer advanced security capabilities, but protection of the environment depends directly on how those services are configured and managed.

Most security incidents in cloud environments are not caused by provider failures, but by inadequate configuration, excessive permissions, improperly exposed resources and mistakes in how the infrastructure was implemented.

The goal of a Cloud Pentest is to identify vulnerabilities and insecure configurations before they can be exploited by criminals, allowing fixes to be applied proactively and significantly reducing risk for the organisation.

What is assessed in a Cloud Pentest

Depending on the agreed scope, the assessment may include:

  • Identity and access management (IAM);
  • Users, groups, roles and access policies;
  • Excessive permissions and privilege escalation paths;
  • Cloud storage, including buckets and object services;
  • Improper exposure of data and public resources;
  • Virtual machines and Internet-facing services;
  • Virtual networks, subnets, security groups and firewall rules;
  • Access keys, tokens, certificates and stored secrets;
  • APIs and services managed by the provider;
  • Containers and related services, when included in the scope;
  • Configurations that do not follow security best practices;
  • Lateral movement possibilities between resources;
  • Other vulnerabilities present in the cloud environment.

Methodology

The assessment is carried out according to the agreed scope and the permissions made available for the tests.

Most of the analysis is carried out manually by specialists, with automated tools used only to support inventory, reconnaissance and initial checks.

Depending on the authorised scope, we may validate service configuration, identity management, permissions, resource exposure, storage of sensitive information, infrastructure segmentation and controlled exploitation of the vulnerabilities identified.

Tests are executed in a controlled manner, with authorisation from the company, seeking to minimise impact on normal operation of the environment.

Professional Report with Results

At the end of the assessment we deliver a technical report and an executive report containing everything needed to support the remediation of the vulnerabilities identified.

The report includes:

  • All vulnerabilities identified;
  • Severity rating (Critical, High, Medium, Low or Informational);
  • Technical evidence of the exploitation of each vulnerability found;
  • Description of the business impact;
  • Clear remediation recommendations, considering the resources offered by the cloud provider;
  • References to security best practices.

Alongside the technical report we also provide a Penetration Test Attestation Letter, a document that certifies the tests were carried out and can be used as evidence in audits, compliance processes, vendor approval and with clients and business partners.