Skip to content
All systems nominal
Cloud

Cloud security.

The IAM misconfiguration your team hasn't noticed yet: the overpermissioned role that chains from a public endpoint to production data. We walk the chain end to end, and every hop lands as a policy diff you can apply.

Book an engagementAWS · Azure · GCP · attack paths · IAM review
// 01 — What it is

Identity is the perimeter. We test it end to end.

Cloud security failures are usually privilege chains rather than exploits. An overpermissioned role, a misconfigured trust policy, a public-facing Lambda with an exposed secret. We follow those chains to your data and document every link.

We cover AWS, Azure, and GCP: IAM graph analysis, cross-account privilege escalation, service misconfiguration, and data-plane access paths. Every finding comes with a policy diff you can apply.

  • Full IAM privilege graph enumeration and attack-path modelling
  • Cross-account and cross-service lateral movement chains
  • External exposure: public APIs, storage buckets, snapshot sharing
  • Policy diffs included with every IAM finding
  1. External entryExposed API key · public S3 · misconfigured ALBInitial access
  2. IAM enumerationOverpermissioned role → GetCallerIdentity → AssumeRoleDiscovery
  3. Privilege escalationiam:PassRole + lambda:InvokeFunction → admin policyEscalation
  4. Cross-account pivotAssume trusted role → secondary account accessLateral move
  5. Data accessS3 GetObject · RDS snapshot · Secrets Manager readObjective
  • AWSAll regions
  • AZUREMulti-tenant
  • GCPAll services
// 02 — How we run it

Five phases from enumeration to hardening plan.

  1. Environment review

    We map your cloud footprint across accounts, regions and services in scope, then agree on the test boundary in writing.

  2. Enumeration & mapping

    External attack surface, IAM policy graph, service exposure, and cross-account trust relationships. All passive or credentialed, per scope.

  3. Attack path analysis

    We build the privilege chain from external access to your most sensitive data, hopping roles, services, and accounts along the way.

  4. IAM & config review

    Policy-level analysis: overpermissioned roles, wildcard actions, resource-based policies, and trust anchor misconfigurations.

  5. Reporting & remediation

    Attack path diagrams, IAM fix recommendations with policy diffs, risk-ranked misconfiguration inventory, and a prioritised hardening roadmap.

// 03 — What you get

What you close, and the order to close it in.

// next step

Every path to your data, walked and recorded.

Scoping call · attack path report · hardening roadmap.

Schedule a scoping call