Cloud pentesting
AWS, Azure, and Kubernetes.
The NodeZero platform simplifies your cloud security with visibility from various perspectives into your vulnerabilities, identity and access management (IAM) weaknesses, and misconfigurations in Amazon Web Services (AWS), Azure, and Kubernetes.
During internal and external pentests, NodeZero:

AWS
Enumerates cloud resources and assets to find an opening into AWS using attacker techniques like privilege escalation, lateral movement, and exploitable vulnerabilities.

Azure
Utilises a combination of Azure-native attacks and data harvested from the infrastructure to pivot in and out of hybrid cloud environments, demonstrating attack paths that compromise the entirety of perimeter security and Microsoft Azure Entra ID.

Kubernetes
Pivots into Kubernetes environments by exploiting vulnerabilities, weak controls, or common misconfigurations.
Active autonomous probing for cloud weaknesses
NodeZero is deployable both on-premises and in the cloud. During internal and external pentests it exploits content native to the environment it is in, and organically uses the weaknesses it uncovers to pivot between on-premises and the cloud — exactly as an attacker who already has a foothold would.

Find and fix IAM weaknesses
NodeZero runs advanced, vendor-specific testing with a grey-box approach that begins with AWS or Azure Entra ID credentials. By testing from the perspective of what an attacker with a credential can reach, it identifies the weaknesses and misconfigurations that lead to privilege escalation, overexposure of cloud assets, and the paths a malicious insider or external attacker could exploit.
Full tenant compromise — no CVE required
In one engagement, within the first two hours of testing and without using a single CVE, NodeZero exploited on-premises misconfigurations, organically pivoted into Azure, and achieved full tenant compromise by elevating itself to Microsoft Entra ID Global Admin. A compromise at that level renders the integrity and security of every application, asset, and user connected to Entra ID effectively useless. Grey-box IAM testing gives regulated Australian organisations the evidence they need for the cloud access-control risks they are obliged to assess under frameworks such as the Security of Critical Infrastructure (SOCI) Act and APRA CPS 234.

Kubernetes pentesting
Kubernetes has become the mainstay of cloud infrastructure, but its complexity brings significant security risks. Nearly 90% of organisations running containerised workloads faced a Kubernetes security incident in the past year (Red Hat, State of Kubernetes Security 2024), and around 96% are now running or evaluating Kubernetes (CNCF) — yet each distribution (AWS EKS, Google GKE, Azure AKS, or vanilla Kubernetes) introduces unique vulnerabilities an attacker can exploit, so a clean posture on one cannot be assumed to carry across the others. NodeZero autonomously pentests your clusters, continuously identifying exploitable risks like RBAC misconfigurations, container escapes, and secret exposures. It deploys within clusters using Kubernetes Operators and Infrastructure-as-Code (kubectl) for easy setup, and once deployed it tests continuously, with no additional manual effort and without sacrificing visibility into or testing of your other platform assets. Unlike tools that only check static configuration, NodeZero launches real-world attacks against live, running clusters — chaining container-runtime vulnerabilities with weak controls and policies just as an attacker would.
Cross-platform attack chaining
NodeZero shows how vulnerabilities in Kubernetes can be chained together with weaknesses from across an organisation's underlying infrastructure to achieve greater impact, giving security teams a clear view of how attackers could move laterally and escalate privileges.

Continuously find, fix, and verify cloud weaknesses
The NodeZero platform offers advantages to your IT, security, and cloud-focused teams across dynamic cloud environments, whether you run an in-house team or operate as a managed services provider — in Australia and New Zealand, Drochaid delivers NodeZero as the managed-services layer. NodeZero tests hybrid cloud environments concurrently at scale and supports large multi-tenant deployments. It offers proof of every exploit, detailed remediation guidance, and Quick Verify so you can immediately confirm that your fixes are effective.

Use the AWS, Azure, and Kubernetes pentests to:
Validate defence in depth
Identify and fix critical IAM misconfigurations and exploitable vulnerabilities across multiple layers of your defences to strengthen your overall security.
Reduce blast radius
Limit the impact of potential breaches by ensuring that access permissions and security defences are correctly configured.
Combat insider threats and credentialed attacks
Uncover and mitigate vulnerabilities that could be exploited by malicious insiders or attackers equipped with a credential.
Assess your cloud and hybrid environments
Run cloud pentests with NodeZero to find IAM weaknesses, misconfigurations, and exploitable attack paths across AWS, Azure, and Kubernetes.