Cloud testing

Cloud penetration testing for AWS, Azure, GCP and Microsoft 365

PentestMe reviews your cloud posture from inside the account, using read-only access you grant and can revoke, and reports the identity, storage and logging misconfiguration that turns one leaked credential into a breach.

Findings come back with the specific console or CLI steps to fix them, not just a control number.

Read-only access, granted on your terms

You connect an account with a role assumption for AWS, a certificate or app registration for Azure and Microsoft 365, or a service account for GCP. The access is read-only, scoped to what the assessment needs, and revocable by you at any time. Nothing is written to your environment, and we tell you exactly which permissions are used and why before you grant them.

What a cloud assessment finds

The misconfiguration that shows up in real cloud breaches, not a generic benchmark dump.

Over-permissive IAM

Roles, users and service accounts holding far more than they use, wildcard policies, and privilege paths that let a minor identity become an administrator.

Public and misconfigured storage

Buckets and containers readable or writable by anyone, including ones discoverable by name rather than linked from anywhere.

Identity and access weakness

Missing or bypassable multi-factor authentication, stale privileged accounts, and conditional access gaps.

Logging and detection gaps

Trails disabled, log retention too short to investigate an incident, and regions where nothing is being recorded at all.

Exposed compute and containers

Instances, functions and Kubernetes control planes reachable from the internet, and container configurations that weaken isolation.

Microsoft 365 and email abuse

Mailbox rules that quietly forward or hide mail, over-shared sites, and the tenant settings behind business email compromise.

Every finding comes with the fix

A cloud report that lists control identifiers is homework, not remediation. PentestMe appends the specific steps to close each finding in the relevant console or CLI, deduplicated so the same misconfiguration is not reported once per tool that noticed it. Where two sources disagree about a setting, we say so rather than reporting both as separate problems.

Assess your cloud free

Connect one account read-only and get a real, validated cloud assessment before you pay anything. No credit card.

Start your free pentest