Testing · Cloud
Cloud & Kubernetes Testing.
Cloud estates attacked the way real operators attack them — chained identity, workload and container weaknesses, not a list of console misconfigurations.
At a glance
- Surface
- Cloud
- Execution
- Manual, senior-led
- Retest
- Included, no charge
- Proposal
- Within one business day
Scope
Configuration review is not a pentest.
We combine configuration analysis with live exploitation to show which misconfiguration actually leads to your data — and which is noise.
AWS, Azure & GCP testing
IAM privilege escalation, role assumption chains, key exposure and cross-account attack paths.
1–2 weeks
Kubernetes & container testing
RBAC abuse, pod escape, supply-chain and registry attacks across managed and self-hosted clusters.
1–2 weeks
Cloud identity attack paths
Entra ID, federation, workload identity and CI/CD credential abuse mapped to real impact.
1 week
Serverless & data platform testing
Functions, queues, object storage and data warehouses tested for exposure and abuse.
3–7 days
CI/CD pipeline attack review
Build systems, runners and secrets tested as the supply-chain target they are.
1 week
Remediation retest
Verification of every fix, with an attestation letter for auditors and customers.
Within 90 days
Method
Configuration, then exploitation.
Nothing starts before the authorisation letter is signed and the blast radius is agreed.
- 01
Scoping
Accounts, subscriptions, clusters, read-only access and provider notification.
- 02
Mapping
Identity graph, trust relationships, exposed services and data stores.
- 03
Exploitation
Privilege escalation, lateral movement across accounts and workload escape.
- 04
Impact
Demonstrated access to crown-jewel data, safely and reversibly.
- 05
Reporting & retest
Attack paths, fixes mapped to IaC, then verification of remediation.
Deliverables
What lands on your desk.
- Cloud identity and trust-relationship attack graph
- Exploited attack paths with reproducible evidence
- Findings mapped to CIS Benchmarks and provider best practice
- Infrastructure-as-code remediation guidance
- Kubernetes RBAC and workload hardening plan
- Prioritised remediation roadmap with effort estimates
- Free retest report and attestation letter
Indicative timeline
Kickoff to closure.
- Week 0
- Scoping, read-only access provisioning, provider notification
- Days 1–3
- Identity and asset mapping across accounts
- Days 3–10
- Exploitation, escalation and cross-account movement
- Days 11–14
- Reporting, walkthrough and executive readout
- Within 90 days
- Free retest and closure letter
Enquire
Start a Cloud & Kubernetes Testing conversation.
Tell us what you need tested. A senior consultant replies within one business day with scoping questions and indicative timelines — no sales funnel.
PRACTICE 03 OF 07
Start here
Know which misconfiguration actually matters.
Share your cloud footprint. We'll come back within one business day with fixed pricing and a named lead operator.
