Cloud Security
Cloud and application security testing across AWS, Azure and GCP, and the misconfigurations that lead to breach.
Field Notes: SSRF to Cloud Takeover
An anonymised web and cloud engagement against a mid-market fintech where a single server-side request forgery flaw reached the cloud metadata endpoint, harvested temporary credentials and opened a path toward full account takeover. Here is how the SSRF cloud metadata attack unfolded, and the layered controls that would have contained it.
The OWASP Top 10 in Practice for Web and API Security
The OWASP Top 10 is the industry reference for web application risk, but the list only matters when you see how the flaws behave in real applications. Here is the OWASP Top 10 in practice for web and API, and how testing catches each one.
Cloud Misconfigurations That Lead to Breach Across AWS, Azure and GCP
Most cloud breaches are not clever exploits. They are misconfigurations: a public bucket, an over-permissive role, a secret left in code. Here are the cloud misconfigurations that lead to breach across AWS, Azure and GCP, and how testing finds them first.
Cloud Security: FAQs
What does StrikeCyber cover under Cloud Security?
This topic collects our research, field notes and guidance on cloud security, written by our operators from real offensive security engagements.
Is StrikeCyber research specific to Australia?
Yes. Our research is grounded in the Australian threat and compliance landscape, including the Essential Eight, SOCI and APRA and local sector risks, while drawing on global attacker tradecraft.
How can I get help with cloud security?
Beyond the research, our operators deliver offensive security engagements across Australia. Scope a free consultation to discuss your environment.
Ready to take the offensive?
StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.
No obligation, no sales pressure. A senior operator replies within one business day.