SVC—06 · ASSESSMENT

Cloud penetration testing

We review configuration against the provider's rules and perform only the exploitation authorized in the rules of engagement.

Start scoping
NIST SP 800-115PTESMITRE ATT&CK 19.1Provider testing policies

TEST BOUNDARY

What sits inside the boundary

Accounts, subscriptions, projects, regions and services
IAM paths, workloads, storage, secrets and Kubernetes clusters
CI/CD, SaaS integrations and hybrid boundaries

ACCESS MODES

Knowledge level is scoped

Configuration review
Grey-box exploitation
Assumed breach

DELIVERY—LEDGER

Deliverables you can inspect.

OUTPUT

Privilege and trust-path analysis

Configuration and exploitation evidence kept separate

Remediation plan aligned to provider constraints

EFFORT—DRIVER

Accounts, services and regions

IAM and Kubernetes complexity

Hybrid links and provider restrictions

EXPLICIT—LIMIT

Testing must follow each provider's authorization policy

Client-owned and third-party assets are distinguished explicitly

POINT—IN—TIME

Precision includes what we do not claim.

A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.

Method and limitations

SCOPE—NEXT

Define the boundary before the fee.

Build a scope draft