Set the scope and access
List the approved assets, accounts, regions, identities, and prohibited actions. Private infrastructure needs an approved access path.
Casco tests the public assets, private services, accounts, and identities named in the scope. It checks whether exposed services, credentials, IAM permissions, storage, network rules, or connected applications can be combined to reach data or privileges they should not expose.
Cloud pentesting checks whether a person with the approved starting access can exploit cloud-hosted assets, identities, services, or network paths. Public, private, IAM, and control-plane coverage depend on the access provided. Casco does not perform destructive actions or resource-exhaustion tests.
How Casco tests
Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.
List the approved assets, accounts, regions, identities, and prohibited actions. Private infrastructure needs an approved access path.
Casco records the domains, hosts, services, storage, network paths, identities, permissions, and application connections visible with the approved access.
Casco checks whether exposure, credentials, IAM permissions, network rules, or connected applications can be combined to reach a protected resource.
Each confirmed issue identifies the affected assets, access gained, impact, fix guidance, and reproduction steps within the agreed safety limits.
Pentest deliverables
The report distinguishes exposed assets and configuration issues from paths Casco was able to exploit.
Learn more
See how Casco records source IPs, request IDs, and network activity during a test.
Read the sourceCompare fixed configuration checks with testing that attempts to use the access they expose.
Read the sourceReview Casco's penetration testing accreditation and supervised testing option.
Read the sourceChecks included when applicable
The findings depend on the public assets, private access, identities, and applications in the scope. Casco stays within the agreed safety limits and excludes destructive and resource-exhaustion actions.
Related testing
Frequently asked questions
AI cloud pentesting uses software agents to inspect approved cloud assets, try permitted security tests, and change the next test based on the result. Casco reports the access it was able to gain and the resources affected.
No. A configuration audit compares settings with a policy. A cloud pentest attempts to use exposed services, credentials, permissions, and network rules to reach a protected resource.
Yes. A scope can include cloud infrastructure, web applications, and APIs. Each system and account must be approved for testing.
Yes. The customer must approve the private assets and provide a way for Casco to reach them. The required agent, network route, and credentials depend on the environment.
Yes, when the relevant accounts, identities, permissions, and test credentials are in scope. A test of public assets alone does not include internal IAM or control-plane access.
Casco needs the approved assets and rules of engagement. Public testing may require IP allowlisting and test credentials. Private, IAM, or control-plane testing requires the corresponding access and test identities.
Casco excludes destructive actions and resource-exhaustion testing. Additional restrictions are recorded in the rules of engagement for the assessment.
Customers receive a pentest report and console findings with severity, affected resources, access gained, impact, fix guidance, reproduction steps, and retest status.