#tag

Cloud Security

6 matching posts.

All tags
PentestSep 9, 202616 min read

The Vendor Was Out of Scope. The Trust Boundary Was Not.

A third-party platform may be excluded from testing while the customer-controlled trust decisions around it remain assessable: identity claims, callbacks, webhooks, custom domains, delivery paths, and data flows.

#pentest#external-pentest#methodology#identity-security#cloud-security
PentestAug 29, 202614 min read

The External Perimeter Is a Graph. The Port List Is Only One View.

Modern external pentesting starts by proving how domains, companies, certificates, identity systems, cloud services, and third parties relate. Active scanning then verifies the small part of that graph that is both relevant and authorized.

#pentest#external-pentest#methodology#cloud-security#identity-security
PentestJul 9, 202618 min read

The Model Is Not the Target. The Pipeline Is.

A field methodology for using MITRE ATLAS without turning an AI assessment into matrix theatre: map the production system, follow authority into tools and data, test reachable attack paths, and label the evidence only after impact is proven.

#methodology#pentest#attack-paths#cloud-security#ai-security
Cloud SecurityApr 16, 20268 min read

The Pipeline Has No Secret. It Still Has a Cloud Identity.

Replacing static deployment keys with OIDC removes a credential from the repository. It does not decide which workflow deserves the resulting cloud role — that decision lives in the trust policy, and one wildcard can turn an organisation into a deployment API.

#cloud-security#identity-security#access-control#attack-paths
Web SecurityJan 29, 20269 min read

The Request Stayed Server-Side. The Credential Did Not.

SSRF severity is not the URL an application can fetch. It is the trust the outbound request inherits — network position, redirect behavior, DNS resolution, and access to metadata or control-plane identities. Test the route as a chain, not a blacklist.

#web-security#cloud-security#access-control#attack-paths
Cloud SecurityAug 14, 20259 min read

Cloud IAM Privilege Escalation: Every Permission Is Individually Fine. The Chain Is Not.

CSPM and least-privilege tools grade each IAM policy on its own, and on its own nearly every policy passes. Cloud privilege escalation is a path across roles, accounts, and trust — and a scanner that cannot see the path cannot flag the risk.

#cloud-security#identity-security#privilege-escalation#attack-paths