Skip to content

Cloud Security Fundamentals

The cloud changes the pentest rules: there’s no physical perimeter or servers to scan, but APIs, identities, and permissions. The central asset is no longer “root on a machine” but a set of credentials with certain permissions (IAM). Understanding the shared responsibility model, how authentication and authorization work, and where the typical flaws are is the basis of the whole Cloud area.

The provider (AWS/Azure/GCP) secures the infrastructure (“security of the cloud”); you secure what you put inside (“security in the cloud”): configuration, IAM, data, code. Almost all cloud breaches are the customer’s fault: public buckets, lax IAM, leaked credentials, misconfigured services. Cloud pentesting focuses there.

On-premise Cloud
--------------------------------------------------
network perimeter identity = perimeter
root on a server IAM credentials with permissions
scan ports enumerate APIs and permissions
service exploit permission abuse / misconfiguration
firewall security groups, IAM policies

Identity is the new perimeter: credentials with excess permissions are the equivalent of an admin password.

  • IAM (Identity and Access Management): users, roles, policies, permissions. The heart of cloud security (see IAM Abuse and Privilege Escalation).
  • Credentials: access keys, tokens, service accounts, managed identities. Their leakage is vector #1.
  • Metadata service: internal endpoint that gives credentials to instances (IMDS) — key in SSRF→cloud (see Metadata Service (IMDS)).
  • Public resources: buckets (S3/Blob/GCS), databases, exposed snapshots (see Buckets and Public Storage).
  • Privilege escalation: chaining permissions to reach admin (see IAM Abuse and Privilege Escalation).
  • Logging: CloudTrail/Activity Log/Audit Logs — what the defender sees.
Concept AWS Azure GCP
------------------------------------------------------------------
Identity IAM User/Role Entra ID / MI IAM / Service Account
Compute EC2 Virtual Machine Compute Engine
Storage S3 Blob Storage Cloud Storage
Serverless Lambda Functions Cloud Functions
Metadata 169.254.169.254 169.254.169.254 metadata.google.internal
Logging CloudTrail Activity Log Cloud Audit Logs
1. Leaked credentials (GitHub, .env, logs) -> direct access (see recon-code)
2. Public resources (buckets, snapshots, DBs) -> data leak (cloud-s3)
3. SSRF -> metadata service -> instance credentials (cloud-metadata)
4. Misconfigured IAM -> privilege escalation (cloud-iam)
5. Misconfigured services (functions, containers, k8s)
6. Secrets in serverless environment/code (cloud-serverless)
# official CLIs
aws / az / gcloud
# multi-cloud auditing and enumeration
ScoutSuite, Prowler (AWS), CloudSploit, Steampipe
# exploitation and escalation
pacu (AWS), ROADtools/AzureHound (Azure), cloudsplaining
# attack mapping
Cartography, PMapper (IAM paths)
  • Least privilege in IAM: no wildcards (*), scoped roles, periodic review.
  • No static credentials: use managed roles/identities, rotation, secrets in managers (Secrets Manager/Key Vault).
  • Block public access by default (buckets, DBs); encryption at rest and in transit.
  • IMDSv2 mandatory (mitigates SSRF→metadata); logging (CloudTrail) enabled and monitored.
  • CSPM (Cloud Security Posture Management) to detect misconfigurations continuously.