Service
Cloud offense
Cloud breaks on identity more often than on a port. We look at what a role can assume, what a pipeline publishes and what a bucket or function gives away from an agreed starting point.
What is in
- AWS, Azure and GCP in the slice
- IAM, federation, keys, policies and isolation
- The application in that account, when the path goes through it
- A report that names the account, the role and the chain
What is out
- A CIS benchmark instead of exploitation
- Full admin as a prerequisite
- Permanent change outside the agreement
Who it is for
- A single account with loose IAM
- A landing zone and trust between accounts
- CI/CD that publishes with too much permission
How it runs
From the call to the report
01
Accounts
Which projects are in. The starting point. What production does not touch.
02
Map
Identity first. WAF later, if it still matters.
03
Path
Role, trust, secret, function, storage.
04
Delivery
What to close first. Almost always identity, not a WAF rule.
The map is IAM
An access key from someone who left, a “temporary” role, trust between accounts, metadata reachable from a function. The report needs the chain. A broad policy that does not show what it unlocks prioritizes nothing.
Isolating the test in a dev account and pretending production is safe is another kind of theatre. The slice says how far we go.
Questions on this page
Do you need an admin user?
We need the agreed access. Full admin is almost never required. The starting point is in the scope.
Does this work for a startup with one account?
Yes. A small account with loose IAM is a common target. Size is not the filter.
Next step
Want to book a meeting?
Tell us the company size and what needs to be protected — the system, the environment, what is at stake. From the call, we assess the scenario and build the work within your scope.