Scope and access
We agree which tenants and subscriptions are in scope and receive time-boxed read-only access.
A configuration-led review of your cloud tenants — identity, exposure, data and logging — that finds the privilege escalation paths and quiet public exposures a checklist tool reports as green.
Cloud breaches are rarely exploits. They are permissions: a role that can assume another role, a key with no expiry, a storage bucket that was public for one migration and never changed back.
We review your configuration with read access, map how identity actually flows, and show which chains would let a low-privilege principal end up owning the tenant.
Typically one to two weeks, depending on the number of accounts and services.
We agree which tenants and subscriptions are in scope and receive time-boxed read-only access.
We gather identity, network, data and logging configuration across the estate.
We work out which principals can become which other principals, and where that ends.
Where you authorize it, we validate the highest-impact paths rather than only describing them.
Findings are ranked by what they would let an attacker do, with a readout and a retest after remediation.
Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.
A path from a low-privilege role to tenant-wide administration
Access keys years old, still valid, belonging to people who have left
Storage or snapshots readable by anyone who knows the address
Conditional access policies with exclusions that swallow the rule
Logging switched off, short-retention or never delivered anywhere anyone looks
Missing something on this list? Bring it to the call — we scope around what you have.
Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.