CLOUD PENTEST PAST POSTURE
You learn which cloud identities actually reach production data, and the exact role chain each one walks to get there.
…standard, standard cloud light scan that might identify some potential vulnerabilities but not actually qualify whether they're exploitable in the same way that hands on pen tester would…
Every candidate is reproduced before it counts.
platform.
Escalation Chain
Role-assumption paths and over-permissive policies tested with live API calls against your account.
Cross-Account Trust Paths
Every trust path between in-scope accounts, subscriptions, and projects gets attempted, including dev identities reaching production.
Detection Timeline
Timestamps let you match the run to CloudTrail, Azure, or GCP logs and find silent calls.
Downloadable Report
Written into the operation as an output file you download as PDF or Markdown.
Scope
A run covers identity and role assumption paths, over-permissive policies, exposed storage and metadata services, and the reachability of production data from each of them. Scope rules matter more in cloud than anywhere else, because one loose scope statement crosses an account boundary you do not own.
It will not fix the IAM policy
Cracken proves the path is walkable and hands you the chain; rewriting the trust policy is your change process, not ours.
It does not test your cloud provider
Scope is the resources inside your accounts, subscriptions, and projects.
On-premises Active Directory is a separate playbook
The identity infrastructure behind it is not part of this run.
It reaches containerized workloads through the cloud identities and endpoints that expose them
There is no dedicated in-cluster Kubernetes attack path in this plan.
It does not replace AWS Inspector, Wiz, or Orca
Cracken reads their findings as starting context and tests reachability; the inventory coverage stays theirs.
Who this is for
Start testingCloud Security Engineer
Your CSPM ranks thousands of misconfigurations by severity. It cannot tell you which ones chain into a path to production data.
Red Team Lead
You want the role-assumption chain walked across accounts, not another list of over-permissive policies.
CISO
You moved to the cloud for speed. You need evidence that one leaked key costs you what the architecture diagram claims it does.
Questions
Does Cracken need admin credentials in my cloud account?
No. The Cloud Pentest playbook is built to start from whatever it can obtain — a key found in a repository, a token from an instance metadata service, or a low-privilege identity you hand it. Supplying a scoped starting identity shortens the run; it is not a requirement.
Where does Cracken run from? Do I open my cloud to an external scanner?
Cracken runs from a Tentacle — a container you install on a host you control, in or next to the environment under test. The Tentacle executes tools inside a Kali Linux container and streams results back, so traffic originates from your own infrastructure rather than a vendor scanning range. On a self-managed deployment — private cloud, on-premises, or air-gapped — the captured tool output and the model traffic stay inside your boundary, against your own model keys or a self-hosted endpoint. On Cracken Cloud, an operation's uploaded assets and captured tool results are held in Cracken-managed storage.
What happens to the persistence and detection-evasion steps in the plan?
The Cloud Pentest playbook's plan does include persistence — new identities, added keys, backdoored functions — and probing whether audit logging can be tampered with. Those are mutations, so they sit above the default intrusiveness ceiling and queue for approval, and the plan requires every test artifact to be removed afterward.
How does this work alongside Wiz or AWS Inspector if I already run them?
Wiz and AWS Inspector connect to Cracken as read-only data integrations. Cracken imports their cloud findings into the Cybergraph as starting context, then tests whether those findings are actually reachable. The connection reads; it does not write back.
Find out what one leaked key reaches in your cloud.
Scope one account, set the ceiling, and run the playbook.





