For the complete documentation index, see llms.txt. This page is also available as Markdown.

Configure the Assessment

Select cloud test categories, safeguards, and rollback behavior.

Open Modules -> Internal Assessment -> Run Assessment. Choose Assessment for an existing cloud inventory or Discovery + Assessment to refresh inventory first.

Target and Agent

Select the discovered AWS account, Azure subscription/resource group, or GCP project and the connected agent on the approved cloud VM. The agent's attached workload identity performs provider operations.

The selected categories and that identity's permissions must both match the approved scope.

Test Categories

Disable every category that is not authorized.

Category
Typical coverage

Cloud Identity Privilege Escalation

Roles, policies, identities, federation, and delegation

Cloud Credential Access

Tokens, keys, signed URLs, secrets, and credential stores

Cloud Data Exposure

Storage, databases, backups, messages, logs, and secrets

Cloud Configuration Exposure

Public management, metadata, encryption, and trust boundaries

Cloud Workload Execution

Commands, builds, functions, containers, startup actions, and code updates

Cloud Authentication Bypass

IAM conditions, sessions, tokens, devices, and authentication policy

Cloud Lateral Movement

Federation, hybrid identity, synchronization, and delegated access

Cloud Policy Misconfiguration

Policies, bindings, encryption, event sources, and access settings

Cloud Network Control

Firewalls, security groups, NSGs, DNS, peering, routes, and remote access

Cloud Persistence

Keys, grants, scripts, devices, signed access, and management links

Cloud Defense Evasion

Logging, diagnostics, flow logs, security services, sinks, and locks

Cloud Destructive Impact

Deletion, disablement, quotas, keys, objects, recovery, and disruption

Optional Controls

  • Validate pre-existing vulnerabilities is for retesting stored findings.

  • Regional monitoring coverage should remain empty unless an approved unused-region test has prepared monitoring inventory.

  • Rollback supported changes restores only changes that implement automated rollback. It does not replace the engagement cleanup plan.

  • RCE safeguards should match the authorization and the desired behavior for already-compromised nodes.

  • Runtime limits stop remaining work after the configured duration.

Advanced Settings

Final Review

Before starting, confirm:

  • provider scope and connected agent;

  • attached workload identity and temporary permissions;

  • enabled categories;

  • retest and regional-monitoring settings;

  • rollback and RCE safeguards;

  • runtime and schedule;

  • cleanup owner and stop conditions.

Use Start run for immediate execution or Schedule run for the configured schedule.

Last updated