SecureBlockLog in
All servicesCloud Security

Cloud security assessment for AWS, Azure, and GCP.

IAM privilege escalation paths, public storage exposure, hardcoded secrets, logging gaps, and guardrail coverage — full configuration review across your cloud footprint.

AWS, Azure & GCP coveredIAM graph analysisCIS Benchmark aligned
What we test

Full coverage, tested by hand.

Every assessment is led by an OSCP- or CREST-certified tester — not a scanner with a human proofreading the output.

IAM privilege escalation

Analyse IAM policies, role trust relationships, and permission boundaries to find all paths from low-privilege access to account administrator.

Public storage & data exposure

Enumerate all storage buckets, blob containers, and object stores for public access, misconfigured ACLs, and sensitive data exposure.

Secrets & credential hygiene

Search for credentials hardcoded in instance metadata, Lambda environment variables, CloudFormation templates, and exposed code repositories.

Logging & guardrail coverage

Verify CloudTrail, GuardDuty, Security Hub, and equivalent controls are active, correctly configured, and covering all critical API calls.

Methodology

How we run the engagement.

A structured process that ends with a report you can hand directly to your auditor.

1
Account access

Read-only cross-account role granted. All assessment is read-only API calls — no persistent infrastructure deployed in your environment.

2
Configuration review

Automated and manual review of IAM, networking, storage, compute, and logging configuration against CIS Benchmarks.

3
Privilege escalation mapping

Build an IAM graph to find all privilege escalation paths from every principal to admin-equivalent access.

4
Findings & remediation

Prioritised finding list with console-clickable evidence, Terraform/IaC remediation snippets, and a re-test window.

Sample findings

The kind of issues we find.

Real finding types from past engagements — titles and targets anonymised.

criticalCVSS 9.3SB-C-001
EC2 instance profile allows iam:CreatePolicyVersion — escalation to AdministratorAccess
AWS Account 123456789 — i-0abc1234Day 1
Remediation — Remove iam:CreatePolicyVersion and iam:SetDefaultPolicyVersion from all non-IAM-admin roles. Audit all instance profiles against least privilege.
highCVSS 7.5SB-C-002
S3 bucket with PII exposed publicly via ACL misconfiguration
s3://acme-user-exportsDay 1
Remediation — Enable S3 Block Public Access at account level. Audit all bucket policies and ACLs for unintended public grants.
mediumCVSS 5.5SB-C-003
CloudTrail logging disabled in two non-primary regions
ap-southeast-1, eu-west-2Day 2
Remediation — Enable CloudTrail in all regions with a single multi-region trail. Use AWS Config rule CLOUD_TRAIL_ENABLED for continuous monitoring.
FAQ

Questions about this service.

Still unsure? Ask an engineer in chat — not a sales rep.

A read-only cross-account IAM role (SecurityAudit + additional read-only policies). We provide a CloudFormation template to deploy it in minutes.

Know where you stand before your auditor does.