Offensive Security

Cloud Security Assessment

AWS, Azure, and GCP configuration and identity hardening reviews.

What it is

Cloud breaches are rarely exotic. They are a public storage bucket, an over-permissive role, a key that never rotated, or a metadata service reachable from a web application. We review your AWS, Azure or Google Cloud configuration against how it is actually attacked, then test the findings rather than just listing them.

How we do it

  1. 1

    Configuration baseline

    Automated review against CIS Benchmarks for your platform, as a starting inventory rather than the conclusion.

  2. 2

    Identity and access analysis

    Roles, policies and trust relationships examined for privilege escalation paths — the cloud equivalent of Active Directory attack paths.

  3. 3

    Storage and data exposure

    Buckets, blobs, snapshots, disk images and databases checked for public or over-broad access.

  4. 4

    Network and boundary review

    Security groups, peering, private endpoints and what is genuinely reachable from the internet.

  5. 5

    Workload and metadata testing

    Container and serverless configuration, and whether an application flaw reaches instance metadata and its credentials.

  6. 6

    Logging and detection gaps

    Whether CloudTrail, Defender or Cloud Audit Logs would actually record the attack we just modelled.

What's included

  • AWS, Azure or Google Cloud
  • IAM privilege escalation path analysis
  • Public exposure sweep across storage and compute
  • Container and serverless configuration review
  • Detection coverage gaps identified
  • Findings validated, not just flagged

Who needs it

  • Teams who migrated fast and hardened later
  • Multi-account or multi-subscription estates that have sprawled
  • Businesses needing cloud evidence for SOC 2 or ISO 27001

Deliverables

  • CIS Benchmark scored results with exceptions explained
  • IAM escalation paths with the specific policies at fault
  • Public exposure inventory
  • Infrastructure-as-code fixes where you use it

Compliance relevance

CIS BenchmarksSOC 2ISO 27001GDPRHIPAA

Frequently asked questions

A read-only audit role — SecurityAudit on AWS, Reader plus Security Reader on Azure. Anything beyond read-only is requested separately and only for a specific test you approve.
For configuration review, no. AWS, Azure and Google all permit most penetration testing of your own resources without prior approval now, but a few service categories still require notice and we will tell you if yours is one.
Yes, and cross-cloud identity federation is worth assessing on its own — it is a common and poorly understood escalation path.

Related services

API Security Testing

REST, GraphQL, and gRPC testing for broken auth, BOLA, and data exposure.

Learn More

Compliance Consulting

ISO 27001, SOC 2, PCI DSS, and GDPR readiness and remediation.

Learn More

Penetration Testing

Manual, OSCP-grade testing that emulates real attackers against your assets.

Learn More