Offensive Security · Cloud Pentest

The cloud shifts the attack surface.

AWS / Azure / GCP penetration testing — misconfiguration, IAM abuse and cross-account escalation paths.

Cloud breaches rarely start with a zero-day; they start with a misconfigured IAM role and a leaked key. Solvin's cloud penetration tests combine configuration review with active exploitation of IAM chains, storage exposure, exposed metadata endpoints and cross-account trust — showing what an attacker with a foothold can actually reach.

AWS · Azure · GCP
Full coverage
CIS
Benchmark aligned
IAM
Escalation paths

/ Capabilities

What's in scope.

Configuration review

CIS Cloud Benchmark aligned review across compute, storage, network, IAM, database and observability services.

IAM abuse & escalation

Privilege-escalation path discovery (PMapper / Cloudsplaining) with proof-of-exploit for chains that reach sensitive data.

Lateral movement & cross-account

Assume-role chains, cross-account trust abuse and lateral movement into workloads.

Container & serverless

Kubernetes, ECR / GCR image and Lambda / Cloud Function security testing.

The IAM graph is the attack graph.

We map the effective permissions graph across your accounts and surface escalation paths — including transitive ones through role assumption and service-linked policies.

Cloud provider policies matter.

AWS, Azure and GCP each have pentest policies. We work within them, coordinate notification where required, and never conduct destructive tests without explicit approval.

/ Standards & Tooling

CIS Cloud BenchmarksAWS / Azure / GCP native APIsPacu / ScoutSuite / ProwlerPMapper / Cloudsplainingkube-hunter / kube-bench

/ References & standards

Every claim on this page is sourced.

These are the public, authoritative sources this page draws from. If a statement isn't backed by one of the standards, tools or policies below, it isn't on the page.

  1. [1]AWS Customer Support Policy for Penetration TestingAmazon Web Services
  2. [2]Microsoft Cloud Penetration Testing Rules of EngagementMicrosoft
  3. [3]Google Cloud — Customer responsibilities for security testingGoogle Cloud
  4. [4]CIS Benchmarks (AWS, Azure, GCP, Kubernetes)Center for Internet Security

/ Editorial accuracy checklist

What we confirmed before publishing.

A short list of internal checks every offensive-security page must pass before it goes live. If you spot a gap, email info@solvin.co.in and we'll correct it.

  • Every standard, framework and tool named on this page has a citation in the References section below.
  • No customer names, logos, case studies or metrics are used unless explicitly authorised in writing.
  • No vendor product claims are made beyond what the vendor publishes in official documentation.
  • Statistics and percentages are attributed to their source or omitted; illustrative figures are labelled as such.
  • Cloud-provider testing policy statements reflect the provider's published rules of engagement at time of writing.
  • Content is reviewed annually and after any material change to a referenced standard.

Common questions.

Do we need permission from the cloud provider?

AWS and GCP no longer require pre-approval for most in-scope tests, but denial-of-service and certain intrusive tests still do. Azure has similar rules. We handle notifications where required.

Configuration review or active exploitation?

Both, in one engagement. Configuration review provides breadth; active exploitation validates which findings are actually reachable and impactful.

Ready to scope a cloud penetration testing engagement?

A senior practitioner — not a sales rep — will respond within one business day.

Contact Us