Skip to content
← Learn

Surface

Cloud infrastructure pentesting

How a cloud environment and identity get tested: IAM, roles, excessive permissions, metadata SSRF and escalation paths. What a real cloud scope includes.

The cloud replaced the perimeter with a permissions problem. There is no more “inside” and “outside”: there are identities with roles, and every role is a door. Cloud pentesting answers a precise question: from a compromised low-privilege identity, what else can an attacker reach?

What gets tested

Identity and permissions. Roles, trust policies, effective permissions (not declared ones: the resulting ones). Escalation paths. Permission combinations that allow assuming higher-privilege roles. SSRF to metadata. A web app that can query the instance metadata endpoint is a direct bridge to credentials. Service configuration. Buckets, queues, serverless functions and their trust policies. Logging and detection. If the simulated attack triggers no alert, that is the first finding.

The deliverable that matters

Not the list of misconfigured buckets: the path. “From a leaked developer credential, two escalations later, the attacker can read the customer database” is a finding. That path gets documented with a reproducible PoC and closed with policy changes, not a generic ticket. For the classic surface feeding the cloud: web and API pentesting. To take it to your accounts: #contacto.

Straight answers

What is a cloud privilege escalation test?

Verifying whether an identity with legitimate permissions can reach permissions it should not have: mismatched role assumptions, open trust policies, wildcards on critical services. Tested with the same techniques an insider would use.

Is a cloud test intrusive?

It can be, which is why it runs under per-environment rules of engagement: which accounts, which regions, which simulated actions are authorized. The human gate applies just like on the network: nothing destructive without a signature.

Does the test need global read access?

Enough read access to map identity and permissions, and nothing more. The principle is the same as the rest of the engagement: minimum scope that answers the risk question.

Time to test your doors?

Tell us what needs validating. We answer with proposed scope, not a brochure.

Talk to Rekon More in Learn