Offensive Security · Cloud Pentest
The cloud shifts the attack surface.
AWS / Azure / GCP penetration testing — misconfiguration, IAM abuse and cross-account escalation paths.
Cloud breaches rarely start with a zero-day; they start with a misconfigured IAM role and a leaked key. Solvin's cloud penetration tests combine configuration review with active exploitation of IAM chains, storage exposure, exposed metadata endpoints and cross-account trust — showing what an attacker with a foothold can actually reach.
/ Capabilities
What's in scope.
Configuration review
CIS Cloud Benchmark aligned review across compute, storage, network, IAM, database and observability services.
IAM abuse & escalation
Privilege-escalation path discovery (PMapper / Cloudsplaining) with proof-of-exploit for chains that reach sensitive data.
Lateral movement & cross-account
Assume-role chains, cross-account trust abuse and lateral movement into workloads.
Container & serverless
Kubernetes, ECR / GCR image and Lambda / Cloud Function security testing.
The IAM graph is the attack graph.
We map the effective permissions graph across your accounts and surface escalation paths — including transitive ones through role assumption and service-linked policies.
Cloud provider policies matter.
AWS, Azure and GCP each have pentest policies. We work within them, coordinate notification where required, and never conduct destructive tests without explicit approval.
/ Standards & Tooling
/ References & standards
Every claim on this page is sourced.
These are the public, authoritative sources this page draws from. If a statement isn't backed by one of the standards, tools or policies below, it isn't on the page.
- [1]AWS Customer Support Policy for Penetration Testing— Amazon Web Services
- [2]Microsoft Cloud Penetration Testing Rules of Engagement— Microsoft
- [3]Google Cloud — Customer responsibilities for security testing— Google Cloud
- [4]CIS Benchmarks (AWS, Azure, GCP, Kubernetes)— Center for Internet Security
/ Editorial accuracy checklist
What we confirmed before publishing.
A short list of internal checks every offensive-security page must pass before it goes live. If you spot a gap, email info@solvin.co.in and we'll correct it.
- Every standard, framework and tool named on this page has a citation in the References section below.
- No customer names, logos, case studies or metrics are used unless explicitly authorised in writing.
- No vendor product claims are made beyond what the vendor publishes in official documentation.
- Statistics and percentages are attributed to their source or omitted; illustrative figures are labelled as such.
- Cloud-provider testing policy statements reflect the provider's published rules of engagement at time of writing.
- Content is reviewed annually and after any material change to a referenced standard.
Common questions.
Do we need permission from the cloud provider?
AWS and GCP no longer require pre-approval for most in-scope tests, but denial-of-service and certain intrusive tests still do. Azure has similar rules. We handle notifications where required.
Configuration review or active exploitation?
Both, in one engagement. Configuration review provides breadth; active exploitation validates which findings are actually reachable and impactful.
Ready to scope a cloud penetration testing engagement?
A senior practitioner — not a sales rep — will respond within one business day.
Contact Us