Infrastructure penetration testing
External and internal penetration testing of networks and Active Directory: from an exposed service or a single workstation to control of the domain.
Infrastructure and cloud
Assessment of AWS, Azure, Google Cloud and Kubernetes environments: identity, network exposure, data stores and paths from a foothold to full control.
Infrastructure and cloud
In the cloud the perimeter is a policy document. A role that can pass another role, a storage bucket readable by any authenticated user, a metadata service reachable from a web application: each looks harmless alone, and together they are a path from the internet to the data.
We review the configuration with read-only access and then test what it means in practice: starting from the position of an outsider, of a compromised workload and of a developer account, we follow the permissions to see how far each of them gets.
01Scope
02Approach
With read-only access we collect the configuration and compare it with the CIS Benchmarks and with the recommendations of the provider.
Permissions are modelled as a graph. We look for the paths that lead from a low-privilege identity to administrative control or to the data.
The paths that matter are walked for real, inside the limits of the rules of engagement, to separate the theoretical from the exploitable.
From inside a container or a function we test what a compromised workload can reach: metadata, neighbouring services, the control plane.
03
04
05Standards
Configuration baselines for cloud platforms, Kubernetes and operating systems.
Center for Internet Security
Catalogue of adversary techniques used to plan operations and to report detection coverage.
The MITRE Corporation
Planning, rules of engagement and conduct of technical testing.
NIST
Severity score and vector of every finding.
FIRST
06Questions
The large providers publish policies that permit testing of your own resources without prior approval, with a list of prohibited actions such as denial of service. We check the current policy of your provider before testing and stay inside it.
For the configuration review, yes. To validate attack paths we need the low-privilege identities the paths start from; they are created for the test and removed after it.
Posture tools list misconfigurations one by one. They rarely show which three of them combine into a path to the data, or which of two hundred warnings actually matters. That is the purpose of this assessment.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.