Cloud security

Cloud posture and privileges (IAM/PAM)

Cloud posture and privileges — complements offensive cloud pentest.

Cloud security

Cloud posture and privileges — complements offensive cloud pentest.

Cloud posture review

Cloud account posture assessment: configuration, exposure, and best-practice alignment.

  • AWS / Azure / GCP
  • CIS benchmarks
  • Public exposure

Read-only review on agreed accounts

runbook · cloud-posture

fortress@engagement:~$ posture_review --accounts 3 --read-only
cis_failures: 12 · public_buckets: 0
report: risk_prioritized_by_account
complements offensive cloud pentest

Secuencia ilustrativa bajo alcance acordado

Coverage
Accounts and subscriptions in scope; IAM, storage, networks, and exposed services.
Typical deliverables
Risk-prioritized report with provider control references and suggested remediation.
Assumptions / modality
Read-only or audit roles; complements offensive cloud pentest.

IAM/PAM assessment

Review of identities, privileges, and privileged access in hybrid environments.

  • Least privilege
  • PAM
  • Federation

Identity inventory + privilege analysis

runbook · iam-pam

fortress@engagement:~$ iam_review --inventory roles,groups
overprivileged: 5 · orphaned: 2
plan: phased_least_privilege
document review · no prod changes

Secuencia ilustrativa bajo alcance acordado

Coverage
Roles, groups, policies, service accounts, and agreed privileged access flows.
Typical deliverables
Over-privilege map, orphaned accounts, and phased hardening plan.
Assumptions / modality
Document review and queries; no production changes.

Need offensive pentest across AWS, Azure, or GCP? View cloud pentest