Cloud security testing and audit
We assess Azure, AWS and GCP estates as an attacker who already has a foothold: enumerating identity, mapping privilege-escalation paths to environment-wide control, and testing whether your own telemetry would catch any of it.
The full attack surface — not just what's visible from the outside.
Identity & privilege escalation
A secure role system
Roles with excessive permissions, unsafe trust policies, and privilege-escalation paths from a low-privilege foothold to full environment control.
Workload & metadata exposure
SSRF and compute identity
SSRF to the instance metadata service (IMDS), credential theft from compute, and over-scoped instance and managed identities.
Public exposure & data
Open resources hidden in configuration
Open object storage, public snapshots and disks, and exposed databases and management planes, against CIS Benchmarks.
Secrets sprawl
Keys in code
Keys and tokens in pipelines, repositories, environment variables and unencrypted state.
Kubernetes
Lateral movement beyond the cluster
RBAC and namespace boundaries, workload identity, pod escape and lateral movement inside the cluster.
Detection & response
Detection is the first step to defence
Whether CloudTrail / Activity Log / Audit and your alerting actually surface the attack you just walked through.
Established industry frameworks — not proprietary checklists.
A configuration baseline used as reference, not as the whole assessment.
Enumerating real escalation and pivot routes across the IAM graph, not isolated misconfiguration flags.
A precise boundary between provider-owned and customer-owned risk.
A structured process from scope to retest — no surprises at delivery.

The questions we hear most often before a contract is signed.
It targets the control plane, identity, configuration and reachability inside the provider account, not packets on a wire. Different failure modes, different tooling, frequently a different skill set.
The provider secures the infrastructure beneath you. Identity, configuration and data are yours, and that boundary is where virtually every significant cloud incident happens.
We scope to least privilege: read-only and audit roles cover most of the assessment. Anything requiring active exploitation is agreed and time-boxed in advance.
Contact us
For any matter, you can reach us using the contact details below or via the contact form.
If you would like to speak with us in person, we invite you to book a meeting using the Microsoft Bookings platform.
Book a meeting in Microsoft Bookings