SecureBlockLog inStart a pentest
All servicesCloud Security

Cloud security assessment for AWS, Azure, and GCP.

IAM privilege escalation paths, public storage exposure, hardcoded secrets, logging gaps, and guardrail coverage — full configuration review across your cloud footprint.

See a sample report
AWS, Azure & GCP coveredIAM graph analysisCIS Benchmark aligned
What we test

Full coverage, tested by hand.

Every assessment is led by an OSCP- or CREST-certified tester — not a scanner with a human proofreading the output.

IAM privilege escalation

Analyse IAM policies, role trust relationships, and permission boundaries to find all paths from low-privilege access to account administrator.

Public storage & data exposure

Enumerate all storage buckets, blob containers, and object stores for public access, misconfigured ACLs, and sensitive data exposure.

Secrets & credential hygiene

Search for credentials hardcoded in instance metadata, Lambda environment variables, CloudFormation templates, and exposed code repositories.

Logging & guardrail coverage

Verify CloudTrail, GuardDuty, Security Hub, and equivalent controls are active, correctly configured, and covering all critical API calls.

Methodology

How we run the engagement.

A structured process that ends with a report you can hand directly to your auditor.

1
Account access

Read-only cross-account role granted. All assessment is read-only API calls — no persistent infrastructure deployed in your environment.

2
Configuration review

Automated and manual review of IAM, networking, storage, compute, and logging configuration against CIS Benchmarks.

3
Privilege escalation mapping

Build an IAM graph to find all privilege escalation paths from every principal to admin-equivalent access.

4
Findings & remediation

Prioritised finding list with console-clickable evidence, Terraform/IaC remediation snippets, and a re-test window.

Sample findings

The kind of issues we find.

Real finding types from past engagements — titles and targets anonymised.

criticalCVSS 9.3SB-C-001
EC2 instance profile allows iam:CreatePolicyVersion — escalation to AdministratorAccess
AWS Account 123456789 — i-0abc1234Day 1
Remediation — Remove iam:CreatePolicyVersion and iam:SetDefaultPolicyVersion from all non-IAM-admin roles. Audit all instance profiles against least privilege.
highCVSS 7.5SB-C-002
S3 bucket with PII exposed publicly via ACL misconfiguration
s3://acme-user-exportsDay 1
Remediation — Enable S3 Block Public Access at account level. Audit all bucket policies and ACLs for unintended public grants.
mediumCVSS 5.5SB-C-003
CloudTrail logging disabled in two non-primary regions
ap-southeast-1, eu-west-2Day 2
Remediation — Enable CloudTrail in all regions with a single multi-region trail. Use AWS Config rule CLOUD_TRAIL_ENABLED for continuous monitoring.
Platform

Findings land live — not in a PDF three weeks later.

Every confirmed issue goes into the platform the moment it's documented. Your team tracks status, chats directly with the tester, and exports evidence without waiting for the engagement to close.

Live findings during testingIssues appear as they are confirmed — no batch delivery at the end.
Direct tester chatComment on any finding and the tester who wrote it responds.
Evidence export on demandOne-click SOC 2, ISO 27001, PCI and HIPAA evidence packs.
app.secureblock.com/projects/cloud-security/vulnerabilities
Projects/Acme Corp — AWS Cloud Environment
AC
Acme Corp — AWS Cloud Environment
Start: 12 Jan 2026 · Due: 12 Feb 2026 · Lead tester assigned
In progress
Overview
Vulnerabilities
Scope
Tasks
Reports
Vulnerabilities3
Export evidence
#DateTitleSeverityStatus
0114 JanEC2 instance profile allows iam:CreatePolicyVersion — escalation to AdministratorAccesscriticalOpen
0214 JanS3 bucket with PII exposed publicly via ACL misconfigurationhighRetest requested
0315 JanCloudTrail logging disabled in two non-primary regionsmediumFix verified
FAQ

Questions about this service.

Still unsure? Ask an engineer in chat — not a sales rep.

A read-only cross-account IAM role (SecurityAudit + additional read-only policies). We provide a CloudFormation template to deploy it in minutes.

Know where you stand before your auditor does.