~ / methodology / cloud

Cloud (AWS / Azure / GCP)

Assessing cloud identity, storage, and misconfigurations.

Recon

  • Enumerate accounts, regions, and exposed assets
  • Public storage buckets and metadata endpoints

Identity & access

  • Over-permissive roles and policies
  • Privilege escalation paths through IAM
  • Federation and key exposure

Services

  • Storage, functions, containers, and secrets stores
  • Logging and detection gaps

Impact

  • Demonstrate blast radius safely and report with fixes