Overview
Kroll’s AWS Cloud Security Assessment and Adversarial Cloud Penetration Testing service gives AWS customers an evidence-based view of cloud risk. The service combines two distinct but complementary models:
- AWS cloud configuration review identifies misconfigurations, control gaps and cloud security weaknesses with read-only access.
- Adversarial cloud penetration testing validates how those weaknesses can be exploited through cloud attack paths, chained exploitation, privilege escalation, lateral movement, persistence and data access. A cloud configuration review tells the customer what is misconfigured. An adversarial cloud penetration test proves what those misconfigurations enable. Kroll performs both.
Buyer problem solved
Cloud teams often receive long lists of findings without a clear view of which issues matter most. A permissive IAM role, exposed service, weak logging configuration or risky trust relationship may appear isolated until issues are chained together. Kroll separates control review from attack-path validation. The configuration review identifies AWS security gaps. The adversarial test validates whether those gaps can be abused to access data, escalate privileges, move laterally, establish persistence or affect critical cloud resources. Findings are prioritized by real-world exploitability and business impact.
Service component 1: AWS cloud configuration review
Kroll uses read-only access to assess AWS configuration and identify remediable security gaps. Review areas may include:
- AWS Organizations, account structure, landing zone design and account separation
- IAM users, roles, policies, trust relationships, privilege boundaries, federated access and MFA
- VPCs, security groups, network ACLs, routing, public services and segmentation
- S3, storage policies, encryption, backup and disaster recovery
- EC2, Lambda, ECS, EKS and serverless configuration
- CloudTrail, CloudWatch, GuardDuty, Security Hub, alerting, log coverage and incident response readiness
- KMS, Secrets Manager, key management and credential handling
Service component 2: Adversarial cloud penetration testing
Kroll simulates realistic threat actor behavior against AWS cloud resources. This validates exploitable weaknesses, tests security controls and assesses business impact using an adversary-centric methodology.
Kroll uses observations from the configuration review to develop exploitation scenarios focused on what an attacker can actually achieve. Activities may include:
- Cloud attack-path planning
- Crown-jewel, AWS resource, identity path and hybrid connectivity analysis
- Authenticated attack simulation using realistic access levels, such as generic employee or IT/cloud administrator
- Identity-driven exploitation, role abuse, privilege escalation and account-to-account pivoting
- Chained exploitation and lateral movement across services, accounts or hybrid connections
- Blast-radius analysis
- Unauthorized data access and safe simulated exfiltration
- Persistence and defense evasion
- Detection and response validation
- MITRE ATT&CK for Cloud mapping across Initial Access, Credential Access, Privilege Escalation, Lateral Movement, Persistence, Defense Evasion, Discovery, Exfiltration and Impact
Customers can use this engagement to:
- Identify AWS configuration weaknesses before they become incidents
- Understand which findings are exploitable
- Validate cloud attack paths across identity, network, storage, compute and managed services
- Assess privilege escalation and lateral movement risk. Determine blast radius and business impact
- Evaluate preventive, detective and corrective controls
- Validate logging, monitoring and detection
- Improve AWS account and landing zone security
- Prioritize short-term, medium-term and long-term remediation
Kroll follows a phased methodology:
- Planning and rules of engagement
- Attack planning and crown-jewel identification
- AWS service and cloud resource enumeration
- Cloud configuration review
- IAM and access path analysis
- Cloud resource evaluation
- Adversarial testing using agreed access levels
- Privilege escalation and lateral movement validation
- Data access and simulated exfiltration
- Persistence and detection validation, where in scope
- Prioritized reporting and remediation planning
Deliverables may include:
- Executive summary
- AWS cloud configuration review report
- Adversarial cloud penetration testing report
- Validated cloud attack-path narrative
- Evidence of privilege escalation or unauthorized access, where identified
- Blast-radius analysis
- IAM and access path findings
- Logging and detection observations
- MITRE ATT&CK for Cloud mapping
- Remediation roadmap
- Debrief presentation, remediation workshop and retest validation report
Highlights
- AWS-focused cloud configuration review across identity, network, storage, compute, logging, monitoring, encryption and incident response readiness.
- Adversarial cloud penetration testing that validates practical attack paths, excessive permissions, exposed services and misconfigurations.
- Executive and technical reporting with prioritized remediation guidance, cloud control improvement recommendations and optional retesting.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Resources
Vendor resources
Support
Vendor support
Kroll provides engagement planning, project management, controlled execution, stakeholder coordination and post-engagement support according to the agreed scope of work. Communication cadence, escalation procedures and safety protocols are defined during scoping.
For queries please contact any of the following Kroll employees:
Rahul Raghavan on rahul.raghavan@kroll.com or +16472096093. Sachin Kumar on sachin.kumar@kroll.com or +918976928403. Feroze Mohideen on feroze.mohideen@kroll.com or +27108254369.