Identity escalation
Role assumptions and excessive permissions that expand a controlled foothold.
Controlled attack-path testing across cloud identities, workloads and data access.
Human-led testing.
Manually verified findings.
Role assumptions and excessive permissions that expand a controlled foothold.
Exposed services, secrets, storage permissions and control-plane paths.
Cross-account trust, network paths and separation of sensitive environments.
Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.
A configuration review checks settings against a baseline. A penetration test validates exploitable paths and impact. If you need the inventory of policy gaps first, start with the review.
From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.
Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.
A test and a review are different purchases. Testing attacks the account, while a cloud security review reads the configuration and usually finds more per hour. We compare both options in cloud security review vs penetration test. Applications inside the account are web application penetration testing and API penetration testing. If the driver is a maturity level, the Essential Eight ML2 guide for AWS and Azure is the better starting point.
Share the assets and your reason for testing. We will confirm the approach, fee and schedule.
Last reviewed: