Cloud security

In the Cloud, Configuration Is the Perimeter.

Most cloud incidents come from permissions and configuration, not exotic exploits. Nuclisafe reviews AWS, Azure and GCP environments for identity escalation paths, exposed storage, container weaknesses and misconfigured cloud APIs.

What we test

Testing coverage across the attack surface

Coverage is tailored to your application. The areas below are assessed where applicable to the agreed scope.

Cloud Configuration Review (AWS)Cloud Configuration Review (Azure)Cloud Configuration Review (GCP)IAM Privilege Escalation PathsStorage Bucket ExposureContainer SecurityKubernetes SecurityServerless Function SecurityCloud API MisconfigurationsSecrets Management ReviewLogging & Monitoring CoverageNetwork & Security Group Review

Common weaknesses

Issues we frequently look for

IAM Privilege Escalation

Over-permissive roles and policy chains that let a low-privileged identity reach administrative access.

Public Storage Exposure

Buckets, blobs and snapshots readable or writable without authentication.

Kubernetes Misconfiguration

Privileged containers, weak RBAC, exposed dashboards and unrestricted pod-to-pod traffic.

Hardcoded Secrets

Keys and tokens embedded in images, functions, pipelines and environment configuration.

Serverless Weaknesses

Over-scoped function roles, unvalidated event input and insecure inter-service trust.

Missing Guardrails

Absent logging, alerting and baseline configuration controls that let issues persist unnoticed.

How we test

A manual-first testing approach

  • Read-only configuration review of the in-scope accounts, subscriptions or projects.
  • Identity and permission graph analysis to map realistic privilege escalation paths.
  • Storage, network and cloud API exposure testing from both external and authenticated positions.
  • Container, Kubernetes and serverless review covering images, RBAC, runtime and function permissions.
  • Benchmark comparison with prioritised, cloud-native remediation guidance per finding.

Aligned frameworks

CIS BenchmarksNIST SP 800-53MITRE ATT&CK for Cloud

Assessments are mapped to these industry frameworks and testing methodologies. This does not imply certification by, or partnership with, any of these organisations.

Example tools

ScoutSuiteProwlerPacuTrivykube-hunterCloudSploit

Illustrative only — tooling is selected per engagement and is not a guarantee of full coverage. Manual testing remains central to every assessment.

Deliverables

What you receive

Executive Summary

Business-level view of risk posture, key themes and priorities for leadership and stakeholders.

Technical Report

Detailed findings with affected endpoints, reproduction steps, evidence and references.

Proof of Concept

Validated demonstration of exploitability within the authorized scope, so nothing is theoretical.

Risk Rating

Severity based on impact and likelihood, supporting prioritization and remediation planning.

Remediation Guidance

Specific, actionable fix recommendations written for the developers who will implement them.

Retest Report

Post-fix verification confirming which findings are closed and which need further work.

Ready to start scoping?

Every assessment is scoped according to application complexity, attack surface and testing requirements.