Cloud Pentest: How Do You Secure AWS, Azure and Google Cloud?
More and more organisations run their infrastructure fully or partially in the cloud. AWS, Azure and Google Cloud offer plenty of security options — but misconfigurations, poor IAM settings and insecure applications are a daily reality in the cloud too. How does a cloud pentest work, and what exactly gets tested?
What makes a cloud pentest different?
In a traditional pentest, you test servers, networks and applications. In a cloud pentest, specific cloud aspects are added:
- IAM permissions (Identity and Access Management) — overly broad roles, unused service accounts, keys that never rotate
- Misconfigurations — publicly accessible S3 buckets, Azure Blob Storage without authentication, publicly exposed databases
- Serverless vulnerabilities — insecure Lambda functions, Cloud Functions or Azure Functions
- Container and Kubernetes security — unsecured cluster APIs, overly broad pod permissions, secrets in environment variables
- Network configuration — overly open security groups, VPC peering without segmentation
What gets tested per cloud platform?
Amazon Web Services (AWS)
- IAM policies and privilege escalation via misconfigured roles
- S3 bucket permissions (public read/write, ACL misconfigurations)
- EC2 instance metadata service (IMDSv1 abuse)
- Lambda function injection and over-permissive execution roles
- CloudTrail logging: is everything logged and detected?
Microsoft Azure
- Azure AD / Entra ID: guest accounts, conditional access gaps
- Blob Storage and Azure Files: public access, SAS token abuse
- Managed identities and service principal permissions
- Azure Functions and Logic Apps: insecure triggers
- Azure Security Center alerts: are they followed up on?
Google Cloud Platform (GCP)
- Service account keys: long lifespan, broad usage
- GCS bucket permissions
- Compute Engine metadata server
- Cloud Run and Cloud Functions security settings
Are we even allowed to run a cloud pentest?
Yes, provided you own the cloud environment. AWS, Azure and GCP allow pentests on your own environments without prior approval — but there are rules:
- AWS — no pre-notification needed for pentests on your own resources, but DDoS simulations are prohibited
- Azure — no pre-notification needed, but activities may not affect other customers’ services
- GCP — comparable rules; consult the current Cloud Acceptable Use Policy
How does a cloud pentest relate to traditional pentesting?
A cloud pentest doesn’t replace a web application or infrastructure pentest — it’s a complement. Ideally, you combine them: application layer (web application pentest), infrastructure layer (external pentest), and cloud configuration (cloud review). MonkeysICT combines these into a single assessment on request.
FAQ
Do you have cloud-specific certifications?
Our pentesters have experience with AWS and Azure environments and are certified via OSCP, OSWE and OSEP — methodologies that also apply to cloud infrastructure. For in-depth cloud-native assessments (e.g. Kubernetes red teaming), we work together with specialists.
What does a cloud pentest cost?
Depending on scope: a targeted IAM and configuration review starts around €2,000. A full cloud security assessment including the application layer starts around €5,000. Request a quote for your specific situation.
