Skip to main content
Home/Services/Cloud Penetration Testing
AWS, Azure & Google Cloud Security

Cloud Penetration Testing

Uncover misconfigurations, IAM privilege escalation paths, and exploitable architecture flaws across your AWS, Azure, or GCP environment before an attacker does.

SOC 2 Type II ISO 27001 CSA STAR PCI-DSS v4.0 OSFI B-13 PIPEDA
engagement log Cloud Penetration Testing testing
day 01 scope cloud accounts & IAM credentials confirmed agreed
day 01 recon cloud asset discovery & IAM policy mapping complete complete
day 02 finding public S3 bucket containing customer PII identified critical
day 03 finding IAM role escalation via passrole to Lambda execution high
day 03 finding SSRF to IMDSv1 yields temporary cloud admin credentials critical
day 04 triage cloud security findings countersigned by pentester published
day 04 deliver tickets filed in tracker with terraform remediation code 201
after retest cloud retest completed and verified at no extra fee retested
retest included human countersigned report your auditor accepts
1-2 weekstypical duration $7,500fixed scope, from 8deliverables 8methodology stages
Scope

What This Engagement Covers

The Service

Cloud infrastructure evolves at an extraordinary velocity, and security debt accumulates just as quickly: overly permissive IAM roles, exposed storage containers, container escapes, shadow cloud services, and cross-account trust vulnerabilities. Our cloud penetration test evaluates your cloud estate from both outside-in and assumed-breach perspectives, uncovering how an attacker could pivot from a minor misconfiguration to full tenancy control or sensitive database compromise.

What We Test

We assess multi-cloud and single-cloud environments including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). In-scope components include Identity & Access Management (IAM) roles and trust policies, cloud metadata services (IMDSv1/v2), storage buckets (S3, Blob Storage, GCS), serverless functions (Lambda, Cloud Functions), Kubernetes clusters (EKS, AKS, GKE), security group configurations, VPC peering, KMS encryption keys, and CI/CD deployment pipelines.

Targets

Components Evaluated in Scope

Our testers systematically inspect the following architectural layers and attack vectors during the assessment.

AWS tenancies, Azure subscriptions, and GCP projects
IAM policies, role trust relationships, and service accounts
Object storage access controls (S3, Blob, GCS)
Instance metadata service (IMDSv1 vs IMDSv2) exploitation
Container and Kubernetes security (EKS, AKS, GKE, ECS)
Serverless functions, API gateways, and cloud endpoints
VPC architectures, security group rules, and transit gateways
Secrets management (Secrets Manager, Key Vault, Secret Manager)
Cross-account, cross-tenant, and federated trust relationships
CI/CD pipeline permissions and automated build credentials
Method

How We Run It

We combine adversarial tradecraft with deep cloud architecture analysis. Starting from an external or scoped identity posture, we enumerate IAM permissions, evaluate privilege escalation paths, test metadata service isolation, and simulate lateral movement between accounts, subscriptions, and projects. Findings are contextualized with actionable remediation guidance for your cloud engineering team.

01

Cloud Perimeter & Asset Enumeration

Mapping exposed endpoints, public storage buckets, DNS entries, and cloud services associated with your environment.

02

IAM & Privilege Escalation Analysis

Analyzing role policies, group memberships, and service account tokens to identify dangerous permission combinations.

03

Compute & Container Security Testing

Evaluating container breakout paths, host access controls, and Kubernetes RBAC misconfigurations.

04

Storage & Secrets Security Audit

Testing access restrictions on databases, object stores, and secrets management services.

05

Metadata Service Exploitation

Probing for Server-Side Request Forgery (SSRF) vulnerabilities to extract temporary credentials from IMDS.

06

Network & VPC Architecture Review

Validating VPC segmentation, transit gateway routes, peering boundaries, and security group isolation.

07

CI/CD & Pipeline Integration Review

Assessing GitHub Actions, GitLab CI, or cloud build pipelines for secret leakage and deployment privilege escalation.

08

Reporting & Engineering Roadmap

Delivering detailed findings with reproduction steps, CVSS scores, and Infrastructure-as-Code (Terraform/CloudFormation) fixes.

Deliverables

What You Receive

Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.

  • Executive summary report detailing cloud risk and business exposure
  • Technical findings report with CVSS v3.1 ratings and attack paths
  • IAM privilege escalation graph and policy review recommendations
  • Kubernetes and container security assessment findings
  • Infrastructure-as-Code (Terraform / CloudFormation) remediation snippets
  • Prioritised engineering roadmap ordered by risk severity
  • Free retesting of all critical and high findings within 48 hours
  • Letter of Attestation for compliance auditors and stakeholders
Typical Results

What We Usually Find

The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.

Overly Permissive IAM Roles with Wildcard Permissions Publicly Accessible S3 Buckets or Blob Containers IMDSv1 Enabled Allowing SSRF Credential Theft Kubernetes API Server or Kubelet Exposed Externally Hardcoded API Keys in Lambda or Cloud Function Code Unencrypted Sensitive Data in Cloud Storage Insecure Cross-Account AssumeRole Trust Policies Missing CloudTrail / GuardDuty Monitoring Coverage
Fit

Who This Is For

SaaS Organizations Hosting Customer Workloads on AWS, Azure, or GCP
Canadian Enterprises Migrating Legacy Infrastructure to Cloud
Companies Preparing for SOC 2 Type II, ISO 27001, or CSA STAR
FinTech and HealthTech Firms Handling Regulated Canadian Data
Engineering Teams Deploying Kubernetes & Microservices in Production
Organizations Seeking Independent Cloud Architecture Validation
Standards this assessment supports

Findings are mapped directly to SOC 2 Type II, ISO 27001, CSA STAR, PCI-DSS v4.0, OSFI B-13, PIPEDA, allowing your team to drop the report into an audit package without manual translation.

Canadian Operations

Calgary & Toronto Security Specialists

Canadian organizations hosting workloads in Canadian AWS regions (ca-central-1, ca-west-1), Azure Canada Central/East, or GCP Montreal/Toronto must guarantee data residency and protection under PIPEDA and Quebec Law 25. Lorikeet Security Canada ensures your cloud tenant maintains strict data isolation and regulatory compliance.

Calgary OfficeAlberta Operations
Toronto OfficeOntario Operations
FAQ

Common Questions

Do you test across AWS, Microsoft Azure, and Google Cloud Platform? +

Yes. Our senior cloud security assessors have deep expertise across AWS, Azure, and GCP, as well as multi-cloud and hybrid environments. We tailor the assessment scope to your specific architecture.

What credentials or access do we need to provide for a cloud pentest? +

For an assumed-breach cloud penetration test, we request a low-privilege IAM user or role. This enables us to evaluate internal privilege escalation and lateral movement without requiring full root or organization admin access.

Will cloud penetration testing violate AWS or Azure Acceptable Use Policies? +

No. Major cloud providers (AWS, Microsoft, Google) permit security testing of customer-owned resources without prior authorization for standard services. We follow all provider guidelines and avoid out-of-scope infrastructure attacks.

How does this differ from a cloud configuration review? +

A configuration review benchmarks settings against CIS benchmarks without active exploitation. A penetration test actively chains misconfigurations together to prove real impact, such as extracting database records or elevating to cloud administrator.

Client Stories

Trusted by Fast-Growing Companies

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
Next

Scope It in One Call

Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.