Cloudanix Joins AWS ISV Accelerate Program

Getting Started With Cloud Pentesting

gcpwn (modeled after Pacu) is a great tool for pentesting covering enumeration and lateral movement. There are many more capabilities coming up soon with support for more Services and APIs.Annual Pen Testing is a good start. But, pentesting should be as close to continuous as possible. It helps organizations stay up to date with their Attack Surface.When starting to pentest, start with IAM. It connects all other services together and the most impactful. For environments, create a seggregated cloud environment for pentesting and tear it down once it’s not used anymore.

In this episode of Scale To Zero Podcast, our guest speaker Scott Weston walks us through the broader landscape of cloud pentesting, including the tool “GCPwn” which is developed by Scott himself.

Whether you’re a seasoned security professional or just starting your journey, this podcast offers valuable insights and practical advice.

Cloud pentesting

You can read the complete transcript of the epiosde here >

Learnings from the podcast

  1. gcpwn (modeled after Pacu) is a great tool for pentesting covering enumeration and lateral movement. There are many more capabilities coming up soon with support for more Services and APIs.
  2. Annual Pen Testing is a good start. But, pentesting should be as close to continuous as possible. It helps organizations stay up to date with their Attack Surface.
  3. When starting to pentest, start with IAM. It connects all other services together and the most impactful. For environments, create a seggregated cloud environment for pentesting and tear it down once it’s not used anymore.

Learning resources recommended by Scott Weston

  1. gcpwn

gcpwn was a tool built by Scott himself when he was learning Google Cloud Platform and leverages the newer GRPC client libraries

You can check gcpwn tool on GitHub >

  1. Scout Suite

Scout Suite is an open source multi-cloud security-auditing tool, which enables security posture assessment of cloud environments.

Check Scout Suite on GitHub >

  1. CloudFoxable

A gamified cloud hacking sandbox from the cloud penetration testing team at BISHOPFOX

Link to CloudFoxable >

  1. PWNedLabs

Experience, real-world, byte sized cloud security labs for training cyber warriors. From beginners to pros, their engaging platform allows security practitioners to secure defenses, ignite career and stay ahead of threats.

Link to CloudFoxable >

  1. Hack The Box

HTB is the leading Cybersecurity Performance Center for advanced frontline teams to aspiring security professionals & students. Start driving peak cyber performance.

Link to Hack The Box >

cta-image

Secure Every Layer of Your Cloud Stack with Cloudanix

Unify your security workflows with Cloudanix — one dashboard for misconfigurations, drift detection, CI/CD, and identity protection.

Get Started

Blog

Read More Posts

Your Trusted Partner in Data Protection with Cutting-Edge Solutions for
Comprehensive Data Security.

Tuesday, Sep 30, 2025

Eliminate Standing Access: Introducing JIT Kubernetes for Azure AKS Security

The Security Mandate: Why Permanent Access Fails Mission-Critical AKS Kubernetes has become the operating system of

Read More

Friday, Aug 08, 2025

User Access Review in Cloud Security: A Foundational Guide to Securing Your Cloud Environment

Introduction: The Unseen Gatekeepers of Cloud Security In the rapidly expanding landscape of cloud computing, organi

Read More

Saturday, Aug 02, 2025

Streamlining Just-in-Time Access: Balancing Security and Developer Workflow Integration

Introduction Just-in-Time (JIT) access is an undisputed cornerstone of modern cloud security. By eliminating standin

Read More