Can you perform pentests in cloud environments (Azure, AWS or GCP)?

Yes. DongIT pentesters work daily with cloud-native architectures on Azure, AWS and GCP. Cloud pentests require specific expertise due to shared responsibility models, provider-specific policies and the way cloud services are intertwined with identity and networking.

What we test in your cloud environment

  • Identity and Access Management (IAM). Overly permissive roles, privilege escalation paths, misconfigured policies, service principals and managed identities.
  • Storage security. Publicly accessible buckets, missing encryption, misconfigured access policies on S3, Blob Storage, GCS.
  • Network segmentation. VNet/VPC configuration, security groups, firewall rules, ExpressRoute/Direct Connect connections.
  • Container security. Kubernetes clusters (AKS, EKS, GKE), container images, RBAC configuration, secrets management.
  • Serverless functions. Azure Functions, AWS Lambda, Google Cloud Functions. Injection vulnerabilities, event-driven attack surfaces.
  • Managed databases. Cosmos DB, DynamoDB, Cloud SQL. Access controls, backup configuration, encryption at rest.
  • Logging and monitoring. Access restrictions on logs, detection gaps in security monitoring.

Preparation for a cloud pentest

For an efficient cloud pentest we need:

  • Read-only console access to the relevant tenant or subscription
  • IAM roles for pentester accounts with temporarily scoped permissions
  • Inventory of resources in scope (IaC configurations such as Terraform, Bicep or CloudFormation are ideal)
  • Confirmation of cloud provider approval where relevant (for example AWS approval for certain test types)

Provider-specific policies

Each cloud provider has specific pentesting policies. AWS allows testing for most services without prior approval, but certain services (such as DNS, RDS) have additional rules. Azure and GCP have their own policies that we respect. We arrange these approvals as part of scoping.

Cloud configuration assessment versus pentest

For faster results, we can also perform a cloud configuration assessment, primarily testing your cloud environment for configuration errors rather than active exploitation. This is more cost-effective for organizations needing a baseline audit and aligns well with ISO 27001 or NIS2 accountability requirements.

Want to discuss a cloud pentest? Contact us for a complimentary scoping conversation, or view our pentest packages.