800+ automated checks

Identity, storage, network and service configuration checks across AWS, Azure, GCP and M365 from one audit engine.

Agentless onboarding

Connect each account with read-only credentials. Nothing to install, nothing to clean up afterwards.

CIS Benchmark coverage

Findings map to CIS Benchmarks for AWS, Azure, GCP and Kubernetes, a baseline your auditors already know.

Exploit-aware prioritisation

CVSS v3.1 scoring, exploit-availability indicators and CISA KEV prioritisation cut through the noise.

Compliance-mapped reporting

Reports map findings to 8 compliance reporting frameworks and export as PDF, CSV and JSON/API.

Re-test on your schedule

Unlimited scans within fair use per asset, with scheduled audits and scan comparison after fixes.

What is cloud penetration testing?

Cloud penetration testing is the assessment of a cloud environment, meaning the accounts and subscriptions, the identities that control them, the storage and network configuration inside them, and the workloads you run on top, to find the weaknesses an attacker could use and then confirm which of those weaknesses are genuinely reachable.

It is a different exercise to traditional network testing. In the cloud the control plane is an API, so the fastest route to your data is usually an over-permissive role or an exposed storage container rather than an unpatched service. Testing has to read the account itself, not just the traffic in front of it.

It also runs under a shared responsibility model. The provider secures the platform; you are responsible for what you build on it. Cloud penetration testing therefore targets your own configuration and your own workloads, never provider infrastructure.

  • Scope. Cloud accounts across AWS, Azure, GCP and Microsoft 365, the identities attached to them, and the applications, APIs and endpoints they expose.
  • Access. Read-only credentials for the account review. Nothing is deployed into your cloud environment and nothing needs uninstalling afterwards.
  • Output. Findings scored with CVSS v3.1, prioritised against CISA KEV, mapped to CIS Benchmarks and 8 compliance reporting frameworks, with evidence attached to anything validated.
  • Cadence. Cloud estates change weekly, so the audit is built to be re-run on a schedule rather than booked once a year.

Posture audit or penetration test?

The two terms get used interchangeably and they are not the same thing. A cloud posture audit is a configuration review: it reads the account through provider APIs and compares what it finds against a baseline such as the CIS Benchmarks. It is read-only, it generates no attack traffic, and it tells you how the environment is set up.

Cloud penetration testing asks the harder question. Of everything the audit flagged, what could an attacker outside your environment actually reach and use? That means probing what the perimeter exposes, testing the applications and APIs you host, and, where authorised, safely validating a finding to show it is real rather than theoretical.

Both matter. An audit without validation buries the one genuinely exploitable issue in a list of hundreds. Validation without an audit misses the misconfiguration that opened the door in the first place. PentestOps runs both, and reports make clear which findings were proven with evidence and which are configuration observations.

LayerWhat PentestOps runsRead-only or active
Cloud accounts (AWS, Azure, GCP, M365)Agentless posture audit against provider baselines and CIS BenchmarksRead-only configuration review through provider APIs
Kubernetes clustersAPI posture review over a read-only kubeconfig, plus node-level CIS Benchmark checks where the runtime permits themRead-only, with a short-lived, auto-cleaned in-cluster job
Internet-facing cloud servicesExternal testing driven by 24+ external recon modulesActive testing, gated by your Rules of Engagement
Web apps and APIs you hostOWASP Top 10 and API Top 10 coverage across REST and GraphQLActive testing, gated by your Rules of Engagement
Confirmed findingsSafe automated exploitation to demonstrate real impactActive, with scope enforcement and a full evidence trail

Why cloud environments need dedicated testing

In the cloud, configuration is the attack surface. A storage bucket opened for a migration, an over-permissive role created during an incident, a network rule widened for a vendor and never wound back: none of these are software vulnerabilities, yet each one can hand an attacker the keys to your environment. Traditional network scanning does not see them.

Cloud estates also change faster than any annual review can track. Teams ship infrastructure as code daily, and a report written in January says little about the account in March. That is why cloud testing works best as a continuous programme rather than a yearly event.

PentestOps treats cloud security as two connected problems: the posture of the accounts themselves, and the exploitability of the workloads you run inside them. The platform addresses both from one place.

What the cloud posture audit covers

The cloud audit runs 800+ automated checks across AWS, Azure, GCP and M365, covering identity and access management, storage exposure, network configuration and provider service settings. Checks map to CIS Benchmarks for AWS, Azure, GCP and Kubernetes, so findings arrive aligned to a baseline your auditors already recognise.

Coverage is agentless. You connect each account with read-only credentials, the platform verifies access, and every subsequent audit runs without deploying anything into your environment.

ProviderPosture focusAvailability
AWSIdentity and access management, storage exposure, network and service configuration against CIS BenchmarksProfessional and Enterprise
AzureIdentity, storage, network and platform service configuration against CIS BenchmarksProfessional and Enterprise
GCPIdentity, storage, network and project configuration against CIS BenchmarksProfessional and Enterprise
Microsoft 365Tenant and identity posture as part of the M365 auditEnterprise

How it works

Cloud engagements follow the same seven-phase methodology as every PentestOps assessment, tuned for provider APIs. The flow from onboarding to verified fix looks like this:

  • Connect an account. Supply read-only credentials for AWS, Azure, GCP or M365. Each cloud account onboards as one asset.
  • Verify scope and authorisation. The platform confirms access and ties every scan to your signed Rules of Engagement.
  • Run the audit. 800+ automated checks assess the account on demand or on a schedule you control.
  • Prioritise what matters. Findings are scored with CVSS v3.1, flagged for known exploit availability and prioritised against CISA KEV.
  • Report and remediate. AI-generated executive summaries, per-finding remediation guidance and compliance-mapped reports in PDF, CSV and JSON/API.
  • Re-test and compare. Re-run the audit after fixes and compare scans to confirm the gap is actually closed.

Posture plus workloads: full-stack cloud testing

A configuration audit tells you how the account is set up. It does not tell you whether the application you host on it can be breached. PentestOps pairs the cloud audit with exploit-validated testing of what you actually run in the cloud:

  • External testing of your public cloud endpoints, driven by 24+ external recon modules that map what the internet can see.
  • Web application and API testing for the apps and services you host, covering OWASP Top 10 and API Top 10 risks.
  • Agentless Kubernetes security testing for managed and self-managed clusters, using a read-only kubeconfig with no agent or DaemonSet to install.
  • Identity posture across Active Directory, Microsoft Entra ID and M365 for Enterprise customers.

Prioritisation, evidence and reporting

Cloud audits can produce long lists. PentestOps is built to shorten them. Findings are correlated against the CVE database, scored with CVSS v3.1, checked for known exploit availability and prioritised against CISA KEV, with false-positive reduction so your team is not chasing noise.

Where safe exploitation is authorised under your Rules of Engagement, scope enforcement automatically stops activity outside authorised assets, and validated findings carry a full evidence trail. Proof, not guesswork.

Reports map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes, and export in multiple formats including PDF, CSV and JSON/API. These mappings describe where findings sit against each framework; they are not a certification of your environment.

Findings are retained for 3 years on Professional and up to 7 years on Enterprise plans, with 365-day audit logs.

Why PentestOps for cloud penetration testing

Plenty of tools watch cloud configuration. PentestOps combines posture auditing with a full penetration testing platform, so the same subscription that reviews your accounts also validates the workloads running inside them.

  • One platform for posture and penetration testing: cloud, external, internal, web, API, identity and Kubernetes coverage in a single programme.
  • Agentless by design: read-only credentials, nothing to deploy, nothing to clean up.
  • Asset-wise pricing: each cloud account is one asset, with unlimited scans within fair use.
  • Self-hosted AI by default: scan data is analysed on infrastructure operated by Extranet Systems, not sent to third-party model providers. External providers are opt-in per tenant.
  • Australian-built and operated. The platform is hosted in Australia and customer data is stored in Australia.
  • Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances.

Frequently Asked Questions

Do I need to install anything in my cloud accounts?

No. The cloud audit is agentless. You supply read-only credentials for each provider, the platform verifies access, and every check runs remotely through provider APIs. Nothing is deployed into your account and nothing needs to be uninstalled afterwards.

Will the audit affect production workloads?

The posture audit reads configuration through provider APIs using read-only credentials, so it does not change resources or generate attack traffic against your workloads. If you add exploit-validated testing of hosted applications, that activity is gated by per-tenant Rules of Engagement with scope enforcement that automatically stops activity outside authorised assets.

Do I need my cloud provider's permission to run a test?

The posture audit is a read-only configuration review of your own account, not an attack on provider infrastructure. Major providers publish customer security-testing policies that allow testing of customer-operated services; review your provider's current policy before scheduling intrusive testing of hosted workloads, and keep all activity inside your signed Rules of Engagement.

How is cloud penetration testing priced?

PentestOps uses asset-wise pricing and each cloud account counts as one asset. Scans against an asset are unlimited within fair use, so you can re-run the audit as often as your change rate demands. See pricing for live plan details.

Which compliance frameworks do cloud findings map to?

Reports map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. The mappings show where findings sit against each framework; they are not a certification of your environment.

How often should we audit our cloud environment?

Match the cadence to your rate of change. Because each cloud account is a single asset with unlimited scans within fair use, most teams schedule regular audits and re-run them after significant changes. Enterprise customers can add continuous monitoring (EASM) so the external perimeter is re-checked between scheduled scans.

Where is our scan data stored?

The platform is hosted in Australia on infrastructure operated by Extranet Systems, and customer data is stored in Australia. Findings are retained for 3 years on Professional and up to 7 years on Enterprise, and audit logs are kept for 365 days.

Can PentestOps audit our Kubernetes clusters too?

Yes. Managed and self-managed clusters, including GKE, EKS, AKS, OpenShift and k3s, are audited agentlessly through a customer-supplied read-only kubeconfig. Each cluster counts as one asset, and there is no agent or DaemonSet to install.

Put your cloud posture to the test

Connect a cloud account with read-only credentials and see what an attacker would find. All paid plans start with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first.