Solutions / What we cover

Test access across your cloud environment.

Casco tests the public assets, private services, accounts, and identities named in the scope. It checks whether exposed services, credentials, IAM permissions, storage, network rules, or connected applications can be combined to reach data or privileges they should not expose.

Testing workflowApproved scope only
  1. 01Approved cloud scopeAssets, accounts, identities, and limits
  2. 02Map assets and permissionsServices, networks, and identities
  3. 03Access testsExposure, credentials, IAM, and network rules
  4. 04Report and retestAffected assets, access gained, fix, and retest
Assets, accounts, permissions, and accessApproved scope only

What is cloud pentesting?

Cloud pentesting checks whether a person with the approved starting access can exploit cloud-hosted assets, identities, services, or network paths. Public, private, IAM, and control-plane coverage depend on the access provided. Casco does not perform destructive actions or resource-exhaustion tests.

How Casco tests

How Casco tests cloud infrastructure.

Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.

Test contextStep 01 / 04
Accounts
Assets
Rules
Access
StageScope
Cloud scope recorded
01

Set the scope and access

List the approved assets, accounts, regions, identities, and prohibited actions. Private infrastructure needs an approved access path.

02

Map assets and permissions

Casco records the domains, hosts, services, storage, network paths, identities, permissions, and application connections visible with the approved access.

03

Test combinations that create access

Casco checks whether exposure, credentials, IAM permissions, network rules, or connected applications can be combined to reach a protected resource.

04

Write and retest findings

Each confirmed issue identifies the affected assets, access gained, impact, fix guidance, and reproduction steps within the agreed safety limits.

Pentest deliverables

What the cloud report contains.

The report distinguishes exposed assets and configuration issues from paths Casco was able to exploit.

  • Approved assets, starting access, safety limits, and methodology
  • Prioritized findings with affected cloud resources and impact
  • Reproduction steps for confirmed access paths within the agreed limits
  • Remediation guidance and status for subsequent retesting

Checks included when applicable

What Casco checks for.

The findings depend on the public assets, private access, identities, and applications in the scope. Casco stays within the agreed safety limits and excludes destructive and resource-exhaustion actions.

Exposed administrative services
Cloud storage and data exposure
Weak IAM and privilege paths
Leaked secrets and credentials
Metadata service access
Misconfigured network boundaries

Frequently asked questions

Cloud pentesting questions, answered.

What is AI cloud pentesting?+

AI cloud pentesting uses software agents to inspect approved cloud assets, try permitted security tests, and change the next test based on the result. Casco reports the access it was able to gain and the resources affected.

Is cloud pentesting the same as a configuration audit?+

No. A configuration audit compares settings with a policy. A cloud pentest attempts to use exposed services, credentials, permissions, and network rules to reach a protected resource.

Can cloud and application testing be combined?+

Yes. A scope can include cloud infrastructure, web applications, and APIs. Each system and account must be approved for testing.

Can Casco test private cloud infrastructure?+

Yes. The customer must approve the private assets and provide a way for Casco to reach them. The required agent, network route, and credentials depend on the environment.

Does cloud pentesting include IAM and privilege paths?+

Yes, when the relevant accounts, identities, permissions, and test credentials are in scope. A test of public assets alone does not include internal IAM or control-plane access.

What access does Casco need for cloud pentesting?+

Casco needs the approved assets and rules of engagement. Public testing may require IP allowlisting and test credentials. Private, IAM, or control-plane testing requires the corresponding access and test identities.

What actions are excluded from cloud pentesting?+

Casco excludes destructive actions and resource-exhaustion testing. Additional restrictions are recorded in the rules of engagement for the assessment.

What does Casco deliver after a cloud pentest?+

Customers receive a pentest report and console findings with severity, affected resources, access gained, impact, fix guidance, reproduction steps, and retest status.

Scope a pentest for this system.

Book a demo