All methodologies
Cloud security

Cloud Security Testing Methodology

Configuration and identity assessment across AWS, Azure, GCP, and Kubernetes — benchmarked against CIS and provider best practices, with attack-path analysis for cloud identity.

Phase 1

Connection & Identity

Establish read access

Connect via least-privilege read-only credentials (role assumption / service principal / service account) validated before any assessment runs.

AWS role assumption
Azure service principal
GCP service account
Connection validation
Phase 2

Configuration Posture

Benchmark the estate

Assess the account against CIS benchmarks and provider best practices — IAM, storage exposure, logging, encryption, and network controls.

Prowler
ScoutSuite
kube-bench
Phase 3

Vulnerability & Exposure

Find the gaps

Identify publicly exposed resources, insecure defaults, vulnerable container images, and Kubernetes weaknesses.

Trivy (images)
kube-hunter
Public-exposure checks
Phase 4

Identity Attack Paths

Map privilege escalation

Map how an attacker could escalate privilege or move laterally through cloud identity — the paths a config scan alone misses.

AzureHound / ROADtools
IAM privilege-path analysis
Phase 5

Reporting

Make it actionable

Misconfigurations and exposures prioritised by impact, mapped to CIS and compliance frameworks, with remediation steps.

CIS benchmark mapping
Risk-scored findings
PDF / web / DOCX reports

Standards we map to

Every finding is tagged against the frameworks your compliance team actually uses.

CIS Benchmarks
ISO/IEC 27001:2022
SOC 2 (CC)
NIST SP 800-115

A note on authorization

Every active test requires either attested ownership of the target during signup or an explicit written authorization on file. We log every test request against this authorization so there's never any ambiguity about scope — we are bound by the same Computer Misuse legislation our customers are.

Explore other methodologies

Ready to run a Cloud assessment?

Run your first scan in minutes. No credit card required for the free tier.