Cloud Security Fundamentals
The cloud changes the pentest rules: there’s no physical perimeter or servers to scan, but APIs, identities, and permissions. The central asset is no longer “root on a machine” but a set of credentials with certain permissions (IAM). Understanding the shared responsibility model, how authentication and authorization work, and where the typical flaws are is the basis of the whole Cloud area.
Shared responsibility
Section titled “Shared responsibility”The provider (AWS/Azure/GCP) secures the infrastructure (“security of the cloud”); you secure what you put inside (“security in the cloud”): configuration, IAM, data, code. Almost all cloud breaches are the customer’s fault: public buckets, lax IAM, leaked credentials, misconfigured services. Cloud pentesting focuses there.
The paradigm shift
Section titled “The paradigm shift”On-premise Cloud--------------------------------------------------network perimeter identity = perimeterroot on a server IAM credentials with permissionsscan ports enumerate APIs and permissionsservice exploit permission abuse / misconfigurationfirewall security groups, IAM policiesIdentity is the new perimeter: credentials with excess permissions are the equivalent of an admin password.
Cross-cutting concepts
Section titled “Cross-cutting concepts”- IAM (Identity and Access Management): users, roles, policies, permissions. The heart of cloud security (see IAM Abuse and Privilege Escalation).
- Credentials: access keys, tokens, service accounts, managed identities. Their leakage is vector #1.
- Metadata service: internal endpoint that gives credentials to instances (IMDS) — key in SSRF→cloud (see Metadata Service (IMDS)).
- Public resources: buckets (S3/Blob/GCS), databases, exposed snapshots (see Buckets and Public Storage).
- Privilege escalation: chaining permissions to reach admin (see IAM Abuse and Privilege Escalation).
- Logging: CloudTrail/Activity Log/Audit Logs — what the defender sees.
The providers (equivalences)
Section titled “The providers (equivalences)”Concept AWS Azure GCP------------------------------------------------------------------Identity IAM User/Role Entra ID / MI IAM / Service AccountCompute EC2 Virtual Machine Compute EngineStorage S3 Blob Storage Cloud StorageServerless Lambda Functions Cloud FunctionsMetadata 169.254.169.254 169.254.169.254 metadata.google.internalLogging CloudTrail Activity Log Cloud Audit LogsCloud attack vectors (landscape)
Section titled “Cloud attack vectors (landscape)”1. Leaked credentials (GitHub, .env, logs) -> direct access (see recon-code)2. Public resources (buckets, snapshots, DBs) -> data leak (cloud-s3)3. SSRF -> metadata service -> instance credentials (cloud-metadata)4. Misconfigured IAM -> privilege escalation (cloud-iam)5. Misconfigured services (functions, containers, k8s)6. Secrets in serverless environment/code (cloud-serverless)Cross-cutting tools
Section titled “Cross-cutting tools”# official CLIsaws / az / gcloud# multi-cloud auditing and enumerationScoutSuite, Prowler (AWS), CloudSploit, Steampipe# exploitation and escalationpacu (AWS), ROADtools/AzureHound (Azure), cloudsplaining# attack mappingCartography, PMapper (IAM paths)For the defense
Section titled “For the defense”- Least privilege in IAM: no wildcards (
*), scoped roles, periodic review. - No static credentials: use managed roles/identities, rotation, secrets in managers (Secrets Manager/Key Vault).
- Block public access by default (buckets, DBs); encryption at rest and in transit.
- IMDSv2 mandatory (mitigates SSRF→metadata); logging (CloudTrail) enabled and monitored.
- CSPM (Cloud Security Posture Management) to detect misconfigurations continuously.
Testing checklist
Section titled “Testing checklist”- Understand the shared responsibility model
- Identify the provider and services in use
- Look for leaked credentials (Code Repository OSINT, .env, logs)
- Enumerate IAM and look for escalation (IAM Abuse and Privilege Escalation)
- Exposed public resources (Buckets and Public Storage)
- SSRF toward the metadata service (Metadata Service (IMDS))
- Automated auditing (ScoutSuite/Prowler)
- Map the path to maximum privilege