Configure the Assessment
Select cloud test categories, safeguards, and rollback behavior.
Open Modules -> Internal Assessment -> Run Assessment. Choose Assessment for an existing cloud inventory or Discovery + Assessment to refresh inventory first.
Target and Agent
Select the discovered AWS account, Azure subscription/resource group, or GCP project and the connected agent on the approved cloud VM. The agent's attached workload identity performs provider operations.
The selected categories and that identity's permissions must both match the approved scope.
Test Categories
Disable every category that is not authorized.
Cloud Identity Privilege Escalation
Roles, policies, identities, federation, and delegation
Cloud Credential Access
Tokens, keys, signed URLs, secrets, and credential stores
Cloud Data Exposure
Storage, databases, backups, messages, logs, and secrets
Cloud Configuration Exposure
Public management, metadata, encryption, and trust boundaries
Cloud Workload Execution
Commands, builds, functions, containers, startup actions, and code updates
Cloud Authentication Bypass
IAM conditions, sessions, tokens, devices, and authentication policy
Cloud Lateral Movement
Federation, hybrid identity, synchronization, and delegated access
Cloud Policy Misconfiguration
Policies, bindings, encryption, event sources, and access settings
Cloud Network Control
Firewalls, security groups, NSGs, DNS, peering, routes, and remote access
Cloud Persistence
Keys, grants, scripts, devices, signed access, and management links
Cloud Defense Evasion
Logging, diagnostics, flow logs, security services, sinks, and locks
Cloud Destructive Impact
Deletion, disablement, quotas, keys, objects, recovery, and disruption
Optional Controls
Validate pre-existing vulnerabilities is for retesting stored findings.
Regional monitoring coverage should remain empty unless an approved unused-region test has prepared monitoring inventory.
Rollback supported changes restores only changes that implement automated rollback. It does not replace the engagement cleanup plan.
RCE safeguards should match the authorization and the desired behavior for already-compromised nodes.
Runtime limits stop remaining work after the configured duration.
Final Review
Before starting, confirm:
provider scope and connected agent;
attached workload identity and temporary permissions;
enabled categories;
retest and regional-monitoring settings;
rollback and RCE safeguards;
runtime and schedule;
cleanup owner and stop conditions.
Use Start run for immediate execution or Schedule run for the configured schedule.
Last updated