Cloud Penetration Testing
Uncover misconfigurations, IAM privilege escalation paths, and exploitable architecture flaws across your AWS, Azure, or GCP environment before an attacker does.
What This Engagement Covers
The Service
Cloud infrastructure evolves at an extraordinary velocity, and security debt accumulates just as quickly: overly permissive IAM roles, exposed storage containers, container escapes, shadow cloud services, and cross-account trust vulnerabilities. Our cloud penetration test evaluates your cloud estate from both outside-in and assumed-breach perspectives, uncovering how an attacker could pivot from a minor misconfiguration to full tenancy control or sensitive database compromise.
What We Test
We assess multi-cloud and single-cloud environments including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). In-scope components include Identity & Access Management (IAM) roles and trust policies, cloud metadata services (IMDSv1/v2), storage buckets (S3, Blob Storage, GCS), serverless functions (Lambda, Cloud Functions), Kubernetes clusters (EKS, AKS, GKE), security group configurations, VPC peering, KMS encryption keys, and CI/CD deployment pipelines.
Components Evaluated in Scope
Our testers systematically inspect the following architectural layers and attack vectors during the assessment.
How We Run It
We combine adversarial tradecraft with deep cloud architecture analysis. Starting from an external or scoped identity posture, we enumerate IAM permissions, evaluate privilege escalation paths, test metadata service isolation, and simulate lateral movement between accounts, subscriptions, and projects. Findings are contextualized with actionable remediation guidance for your cloud engineering team.
Cloud Perimeter & Asset Enumeration
Mapping exposed endpoints, public storage buckets, DNS entries, and cloud services associated with your environment.
IAM & Privilege Escalation Analysis
Analyzing role policies, group memberships, and service account tokens to identify dangerous permission combinations.
Compute & Container Security Testing
Evaluating container breakout paths, host access controls, and Kubernetes RBAC misconfigurations.
Storage & Secrets Security Audit
Testing access restrictions on databases, object stores, and secrets management services.
Metadata Service Exploitation
Probing for Server-Side Request Forgery (SSRF) vulnerabilities to extract temporary credentials from IMDS.
Network & VPC Architecture Review
Validating VPC segmentation, transit gateway routes, peering boundaries, and security group isolation.
CI/CD & Pipeline Integration Review
Assessing GitHub Actions, GitLab CI, or cloud build pipelines for secret leakage and deployment privilege escalation.
Reporting & Engineering Roadmap
Delivering detailed findings with reproduction steps, CVSS scores, and Infrastructure-as-Code (Terraform/CloudFormation) fixes.
What You Receive
Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.
- Executive summary report detailing cloud risk and business exposure
- Technical findings report with CVSS v3.1 ratings and attack paths
- IAM privilege escalation graph and policy review recommendations
- Kubernetes and container security assessment findings
- Infrastructure-as-Code (Terraform / CloudFormation) remediation snippets
- Prioritised engineering roadmap ordered by risk severity
- Free retesting of all critical and high findings within 48 hours
- Letter of Attestation for compliance auditors and stakeholders
What We Usually Find
The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.
Who This Is For
Findings are mapped directly to SOC 2 Type II, ISO 27001, CSA STAR, PCI-DSS v4.0, OSFI B-13, PIPEDA, allowing your team to drop the report into an audit package without manual translation.
Calgary & Toronto Security Specialists
Canadian organizations hosting workloads in Canadian AWS regions (ca-central-1, ca-west-1), Azure Canada Central/East, or GCP Montreal/Toronto must guarantee data residency and protection under PIPEDA and Quebec Law 25. Lorikeet Security Canada ensures your cloud tenant maintains strict data isolation and regulatory compliance.
Common Questions
Yes. Our senior cloud security assessors have deep expertise across AWS, Azure, and GCP, as well as multi-cloud and hybrid environments. We tailor the assessment scope to your specific architecture.
For an assumed-breach cloud penetration test, we request a low-privilege IAM user or role. This enables us to evaluate internal privilege escalation and lateral movement without requiring full root or organization admin access.
No. Major cloud providers (AWS, Microsoft, Google) permit security testing of customer-owned resources without prior authorization for standard services. We follow all provider guidelines and avoid out-of-scope infrastructure attacks.
A configuration review benchmarks settings against CIS benchmarks without active exploitation. A penetration test actively chains misconfigurations together to prove real impact, such as extracting database records or elevating to cloud administrator.
Trusted by Fast-Growing Companies
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Scope It in One Call
Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.