CPENT Module 12 Cloud Penetration Testing
CPENT Module 12 Cloud Penetration Testing
Penetration Tester:
Organization:
Date: Location:
Target Organization
URL
Successfully Identified the Type of Cloud Service Under Test? Yes No
Identified Cloud 1.
Services to be Tested
2.
3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Systems/Instances and 1.
Applications that Need to
2.
be Tested
3.
4.
5.
Results Analysis:
Target Organization
URL
Successfully Identified the Tools for Penetration Testing? Yes No
List of Cloud Services 1.
to be Tested
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Is Cloud Reconnaissance Successful? Yes No
Information Gathered
List of Publicly Accessible 1.
Resources
2.
3.
4.
5.
Security Groups 1.
2.
3.
4.
5.
Subnets 1.
2.
3.
4.
Permissions 1.
2.
3.
4.
5.
Hardware Details 1.
2.
3.
4.
5.
Software Details 1.
2.
3.
4.
5.
Network Information 1.
2.
3.
4.
5.
Databases in Use 1.
2.
3.
4.
5.
Operating Systems in 1.
Use (include Version)
2.
3.
4.
5.
Security Flaws/ 1.
Vulnerabilities Identified
2.
3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Impact of Lock-In on 1.
Business Services
2.
3.
4.
5.
Determined Provisions
to Switch Over to Other
CSPs
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Information Gathered by 1.
Checking SLA Document
2.
and Track Record of the
CSP 3.
4.
5.
6.
Roles and 1.
Responsibilities of the
2.
CSP and Subscribers in
Managing Cloud 3.
Resources
4.
5.
Hidden Dependency to 1.
Resources Outside Cloud
2.
3.
4.
5.
Issues Related to 1.
Transparency on the
2.
Usage of Technologies
and Data Storage 3.
4.
5.
Source Escrow 1.
Agreement
2.
3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Is the Service Compliant with International Standards for Data Yes No
Protection Belonging to the Different Industries Served by the Client?
CSP is Regularly Audited and Certified for Compliance Issues? Yes No
Regulations CSP Complies
With
Do the Regulations Meet the Requirements of the Client? Yes No
If Responsibilities of the CSP and Subscribers in Maintaining Compliance Yes No
is Well Defined?
SLA Provides Transparency on Compliance Issues? Yes No
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Right employee(s) with the proper knowledge is appointed to work with Yes No
cloud-based technologies?
Security, authentication, 1.
and authorization processes
2.
employees follow
3.
4.
5.
Right employee(s) with the proper knowledge is appointed to look for Yes No
cloud security?
Tools used by cloud security 1.
employees
2.
3.
4.
5.
Right set of policies and procedures are implemented to ensure cloud Yes No
security?
Policies implemented for 1.
Cloud Security
2.
3.
4.
5.
Security Assessment 1.
Processes Employed by the
2.
Company
3.
4.
5.
6.
7.
8.
9.
10.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Does CSP provides isolation of resources in the cloud? Yes No
Methods Used to Check 1.
Cloud Resource Isolation
2.
3.
4.
5.
6.
7.
8.
9.
10.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Test 1.10: Check Whether Anti-Malware Applications are Installed and Updated on Every
Device
Target Organization
URL
Cloud Service Tested
Components of the Cloud 1.
Infrastructure
2.
3.
4.
5.
6.
7.
8.
9.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Test 1.11: Check Whether Firewalls are Installed at Every Network Entry Point
Target Organization
URL
Cloud Service Tested
Firewalls Installed at Every Network Entry Point? Yes No
Effectiveness of
Firewalls in
Preventing
Transmission of
Malicious Traffic
Information 1.
Gathered from
2.
Firewall
Implementation 3.
Policy
4.
5.
Information 1.
Gathered from
2.
Firewall Logs and
Network 3.
Configuration
4.
5.
Authorized Persons 1.
having Access to
2.
Firewall
Configuration and 3.
Settings
4.
5.
Alert Mechanism 1.
Used in Firewalls
2.
3.
4.
5.
Unused Ports, 1.
Protocols, and
2.
Services
3.
4.
5.
Does the Firewall Block Unused Ports, Protocols, and Services? Yes No
Identified 1.
Vulnerabilities 2.
3.
4.
5.
6.
7.
8.
9.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Test 1.12: Check that Strong Authentication is Deployed for Every Remote User
Target Organization
URL
Cloud Service Tested
Did the cloud Service Deploy Strong Authentication for Every Remote Yes No
User?
Does the Company have a Strong Password and Authentication Policy? Yes No
OTP Used to Validate the Passwords? Yes No
Identified Vulnerabilities 1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Test 1.13: Check the SSL Certificates for Cloud Services in the URL
Target Organization
URL
Cloud Service Tested
Cloud Services Enabled for SSL Encryption? Yes No
VPN and Secure Email Services Used for Communication? Yes No
Security and Privacy 1.
Policies of the Cloud
2.
Services
3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Test 1.14: Check whether Files Stored on Cloud Servers are Encrypted
Target Organization
URL
Cloud Service Tested
Is the Data Stored on Cloud Servers is Encrypted? Yes No
Encryption Algorithms 1.
Used
2.
3.
4.
5.
Cloud Service Providers or Service Users Hold the Algorithmic Keys for Yes No
the Encryption?
Employees having 1.
Access to Encryption
2.
Algorithms and Their
Keys 3.
4.
5.
Identified 1.
Vulnerabilities
2.
3.
4.
5.
6.
7.
8.
9.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Data Retention Policies of
Service Provider
Does the data retention policies meet the company’s needs and comply Yes No
with internal corporate policy?
Does the CSP perform regular backups and recovery tests? Yes No
Do the Policies Bound by the Law of the Land to Disclose the Data to Yes No
Third Parties?
Duration of Data Retention in
the Cloud
Procedures to Completely 1.
Erase the Data from the
2.
Cloud
3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Test 1.16: Check that all Users Follow Safe Internet Practices
Target Organization
URL
Cloud Service Tested
Does the Company have a Documented Computer and Internet Usage Yes No
Policy?
Computer and Internet
Usage Policy Details
Checked the Logs and Determined whether any Employee has violated Yes No
the Policies?
If Yes, Details of Violation
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Techniques Used for 1.
Assessing Cloud
2.
Vulnerabilities
3.
4.
5.
Cloud Components 1.
Assessed for
2.
Vulnerabilities
3.
4.
5.
Identified 1.
Vulnerabilities
2.
3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Password Grabbing 1.
Techniques Used
2.
3.
4.
5.
Credentials Obtained 1.
2.
3.
4.
5.
Other Cyberattacks 1.
Performed
2.
3.
4.
5.
Sensitive Information 1.
Collected
2.
3.
4.
5.
6.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Host is updated with the latest patches and regular updates? Yes No
Password used for VM OS is complex? Yes No
Any unnecessary services/programs running on the VM OS? Yes No
Host is individually firewalled? Yes No
VM host is physically secured? Yes No
File integrity checks are implemented? Yes No
Are virtual machines secured? Yes No
Identified Vulnerabilities 1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Test 1.20: Check Audit and Evidence-Gathering Features in the Cloud Service
Target Organization
URL
Cloud Service Tested
Does the CSP includes provisions for performing audit and gathering Yes No
evidence in case of a security incident?
Cloud Service Provider Offers Features for Cloning of Virtual Machines? Yes No
Storage Capacity Provided to
support Multiple Clones
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
AWS Shared Model
Used
Responsibility Between
AWS and the Customer
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
List of Services which 1.
are Permitted
2.
3.
4.
5.
List of Activities 1.
which are Prohibited
2.
3.
4.
5.
Policies Regarding 1.
the use of Security
2.
Assessment Tools
3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Identified S3 Bucket Successfully? Yes No
Method used Manual Method Automated Method
List the Techniques 1.
Used to Identify S3
2.
Buckets
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Test 2.7: Attempt to Obtain Access to the set of EC2 Instance/Role Permissions
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Is it Possible to Update the Login Profile with Regular User Accounts? Yes No
Updated Username
Updated Password
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Commands Used
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Azure Shared Model
Used
Responsibilities
Between Azure and
the Customer
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Scope 1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
Rules of Engagement 1.
to Perform Penetration
2.
Testing on the
Microsoft Cloud 3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Assessed Azure Environment Successfully? Yes No
Vulnerabilities Recommendations Secure Score Impact Resource
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Assigned Role of Users Checked Successfully? Yes No
Access Control (IAM)
Name Type Role Scope
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
Identified 1.
Misconfigurations
2.
3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Is Access to the Azure AD Portal is Restricted? Yes No
Access to Azure administrative portal is Restricted? Yes No
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Test 3.6: Check whether Multi-Factor Authentication (MFA) is Enabled for Every User
Target Organization
URL
Cloud Service Tested
Multi-Factor Authentication (MFA) is Enabled for Every User? Yes No
Display Name Username Multi-Factor Auth Status
1.
2.
3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
WAF is installed on Microsoft Azure? Yes No
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Data is Encrypted at Rest? Yes No
Storage Account Encryption Status
1. Enabled Disabled
2. Enabled Disabled
3. Enabled Disabled
4. Enabled Disabled
5. Enabled Disabled
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
SQL Databases are Encrypted? Yes No
Database Instance Data Encryption Status
1. On Off
2. On Off
3. On Off
4. On Off
5. On Off
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Checked Data Retention Time Successfully? Yes No
Data Retention Time
Storage Capacity
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Test 3.11: Check whether Network Security Groups Diagnostic logs are turned On
Target Organization
URL
Cloud Service Tested
NSG Diagnostic Logs Checked Successfully? Yes No
Network Security Group NSG Diagnostic logs
1. ON OFF
2. ON OFF
3. ON OFF
4. ON OFF
5. ON OFF
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Region Network Watcher Status
1. Enabled Disabled
2. Enabled Disabled
3. Enabled Disabled
4. Enabled Disabled
5. Enabled Disabled
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Virtual Machine JIT VM Access Status
1. Enabled Disabled
2. Enabled Disabled
3. Enabled Disabled
4. Enabled Disabled
5. Enabled Disabled
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Google Cloud Shared
Model Used
Responsibilities
Between Google and
the Customer
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Scope 1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
Rules of Engagement 1.
to Perform Penetration
2.
Testing on the Google
Cloud 3.
4.
5.
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Status of Security Health
Enabled Disabled
Analytics
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Status of Cloud Web
Enabled Disabled
Security Scanner
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Status of Cloud Anomaly
Enabled Disabled
Detection
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Status of Container Threat
Enabled Disabled
Detection
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis:
Target Organization
URL
Cloud Service Tested
Status of Event Threat
Enabled Disabled
Detection
Tools/Services Used 1.
2.
3.
4.
5.
Results Analysis: