Identity & privilege escalation
IAM users, roles, policies and trust relationships mapped into a graph, then walked for escalation paths — iam:PassRole chains, over-broad assume-role trusts, and wildcard permissions nobody intended to grant.
A benchmark tool tells you which settings differ from a baseline. We tell you which of those actually chain into someone reading your customer database — and which are noise you can safely deprioritise.
Scope
Reviewed with read-only access to the account, and validated from the outside where the rules of engagement allow.
IAM users, roles, policies and trust relationships mapped into a graph, then walked for escalation paths — iam:PassRole chains, over-broad assume-role trusts, and wildcard permissions nobody intended to grant.
Buckets, blobs, snapshots, AMIs and database instances checked for public exposure, over-broad ACLs, and unencrypted data at rest.
Whether an SSRF anywhere in your estate reaches the instance metadata service, and whether IMDSv2 is enforced rather than merely available.
Security groups, NACLs, firewall rules, peering and exposure of management planes — including services listening on the internet that were meant to be internal.
Secrets in environment variables, user-data scripts, container images, CI configuration and source history, plus key rotation and KMS policy review.
Whether CloudTrail, audit logs and flow logs are enabled, retained and actually alerting — tested by performing noisy actions and checking what you saw.
FAQ
A read-only role — SecurityAudit and ViewOnlyAccess on AWS, or the equivalent on GCP and Azure. Anything beyond read-only is agreed explicitly in writing and scoped to a named test window.
No. Benchmarks are a starting point and we run them for coverage, but the value is in the manual work: turning a list of misconfigurations into the specific paths that lead from an internet-facing foothold to your data.
Yes — RBAC review, workload identity, pod security, network policy, and escape paths from a compromised container to the node and then to the cloud account.
Next step
Tell us what you have built. You get a reply within one business day, an NDA, and a free 30-minute scoping call with the person who will do the testing.