Offensive security

    Cloud Infrastructure Penetration Testing

    Prove which cloud misconfiguration is actually reachable.

    Offensive testing of AWS, Azure and Google Cloud environments: identity paths, privilege escalation and lateral movement.

    Attack path

    Enumerate: Accounts, subscriptions, projects and exposed services.

    Cloud infrastructure penetration testing answers a question a posture tool cannot: which of these findings can an attacker actually chain into access? We test identity and role configuration, exposed services, network segmentation, storage permissions and workload isolation, then attempt real privilege escalation and lateral movement paths inside AWS, Azure or Google Cloud under agreed rules of engagement.

    • Testing is authorised in writing and follows each provider's customer testing policy.
    • Findings are presented as attack paths with the single control that breaks each chain.
    • Complements continuous posture management rather than replacing it.

    How this service connects

    Use Cloud Security to turn test evidence into architecture, hardening and continuous guardrails.

    Broaden the engagement with Penetration Testing when application, network or human attack paths are also in scope.

    Use Vulnerability & Threat Assessment for continuous prioritisation between offensive cloud tests.

    Who should consider this assessment

    • Organisations moving production workloads into AWS, Azure or Google Cloud.
    • Teams operating multi-account, multi-cloud or hybrid environments with complex identity paths.
    • Enterprises using containers, Kubernetes, serverless services or CI/CD pipelines for critical workloads.

    What you receive

    1. 01Documented attack paths across identity, network, workload and storage boundaries.
    2. 02Risk-prioritised technical findings with the control that breaks each demonstrated chain.
    3. 03Executive and engineering views of exposure, impact and recommended remediation order.

    Service packages

    Starter Package

    Who it is for
    Small cloud environments with limited assets and basic configurations.
    Scope
    Up to 10 assets, basic IAM review, common misconfigurations, exposed endpoints and network security.
    Ideal for
    Startups and organisations in the early stages of cloud adoption.

    €1,500 excl. VAT

    Configure with our team

    Standard Package

    Who it is for
    Medium-sized cloud environments with moderate complexity.
    Scope
    Up to 50 assets, IAM policies, VPC and firewall testing, cloud APIs and external integrations.
    Ideal for
    Mid-sized businesses with growing cloud infrastructure.

    €4,500 excl. VAT

    Configure with our team

    Enterprise Package

    Who it is for
    Large-scale, regulated or mission-critical cloud environments.
    Scope
    Unlimited multi-cloud assets, Kubernetes, serverless, CI/CD, cross-account IAM and lateral-movement analysis.
    Ideal for
    Enterprises with advanced configurations and extensive integrations.

    Custom scope

    Configure with our team

    Expertise and delivery standards

    Certified offensive-security expertise

    Our experts hold certifications including OSEE, OSCP, OSWE, OSEP, OSED, OSWP, eWPTx, eMAPT, eCPPT, CRTO and CEH.

    ISO 9001 & ISO 27001

    Evolvice operates certified quality-management and information-security systems under ISO 9001:2015 and ISO 27001:2022.

    13+ years in IT delivery

    More than thirteen years of technology delivery inform scoping, communication, reporting and remediation support.

    Their penetration testing report was not only detailed but actionable. Our developers could immediately start fixing the issues.
    They helped us identify critical vulnerabilities we didn’t know existed. A truly professional and responsive team.
    From the initial scoping call to the final report, everything was handled with precision and professionalism.

    What the engagement covers

    01

    AWS testing

    IAM policy chains, assume-role paths, S3 permissions, metadata service exposure and Lambda privileges.

    02

    Azure testing

    Entra ID roles, managed identities, storage access, subscription boundaries and hybrid join paths.

    03

    Google Cloud testing

    IAM bindings, service-account impersonation, project boundaries and bucket permissions.

    04

    Network & segmentation

    Exposed services, security group and firewall rules, peering and private endpoint paths.

    05

    Container & Kubernetes

    Cluster RBAC, workload isolation, node access and secret exposure.

    06

    Privilege escalation paths

    Chained permissions that end in administrative control, shown step by step.

    Q&A

    How is this different from cloud security posture management?

    Posture management continuously lists misconfigurations. This test proves which of them an attacker can chain into real access, and in what order to fix them.

    Do we need permission from AWS, Azure or Google?

    The major providers permit customer-initiated testing of your own resources within their published policies. We work inside those policies and confirm scope in writing.

    Can you test a multi-cloud or hybrid environment?

    Yes. Cross-account, cross-cloud and hybrid identity paths are usually where the most valuable findings are.

    Will the test affect running workloads?

    Testing runs in defined windows with escalation contacts. Actions that could disrupt availability require explicit written authorisation.

    Let us look at your current security position first.