Skip to content

Testing · Cloud

Cloud & Kubernetes Testing.

Cloud estates attacked the way real operators attack them — chained identity, workload and container weaknesses, not a list of console misconfigurations.

At a glance

Surface
Cloud
Execution
Manual, senior-led
Retest
Included, no charge
Proposal
Within one business day

Scope

Configuration review is not a pentest.

We combine configuration analysis with live exploitation to show which misconfiguration actually leads to your data — and which is noise.

AWS, Azure & GCP testing

IAM privilege escalation, role assumption chains, key exposure and cross-account attack paths.

1–2 weeks

Kubernetes & container testing

RBAC abuse, pod escape, supply-chain and registry attacks across managed and self-hosted clusters.

1–2 weeks

Cloud identity attack paths

Entra ID, federation, workload identity and CI/CD credential abuse mapped to real impact.

1 week

Serverless & data platform testing

Functions, queues, object storage and data warehouses tested for exposure and abuse.

3–7 days

CI/CD pipeline attack review

Build systems, runners and secrets tested as the supply-chain target they are.

1 week

Remediation retest

Verification of every fix, with an attestation letter for auditors and customers.

Within 90 days

Method

Configuration, then exploitation.

Nothing starts before the authorisation letter is signed and the blast radius is agreed.

  1. 01

    Scoping

    Accounts, subscriptions, clusters, read-only access and provider notification.

  2. 02

    Mapping

    Identity graph, trust relationships, exposed services and data stores.

  3. 03

    Exploitation

    Privilege escalation, lateral movement across accounts and workload escape.

  4. 04

    Impact

    Demonstrated access to crown-jewel data, safely and reversibly.

  5. 05

    Reporting & retest

    Attack paths, fixes mapped to IaC, then verification of remediation.

Deliverables

What lands on your desk.

  • Cloud identity and trust-relationship attack graph
  • Exploited attack paths with reproducible evidence
  • Findings mapped to CIS Benchmarks and provider best practice
  • Infrastructure-as-code remediation guidance
  • Kubernetes RBAC and workload hardening plan
  • Prioritised remediation roadmap with effort estimates
  • Free retest report and attestation letter

Indicative timeline

Kickoff to closure.

Week 0
Scoping, read-only access provisioning, provider notification
Days 1–3
Identity and asset mapping across accounts
Days 3–10
Exploitation, escalation and cross-account movement
Days 11–14
Reporting, walkthrough and executive readout
Within 90 days
Free retest and closure letter

Enquire

Start a Cloud & Kubernetes Testing conversation.

Tell us what you need tested. A senior consultant replies within one business day with scoping questions and indicative timelines — no sales funnel.

PRACTICE 03 OF 07

0/2000

Start here

Know which misconfiguration actually matters.

Share your cloud footprint. We'll come back within one business day with fixed pricing and a named lead operator.