DrochaidHorizon3.ai
NodeZero/Cloud pentesting
Autonomous pentesting

Cloud pentesting

AWS, Azure, and Kubernetes.

The NodeZero platform simplifies your cloud security with visibility from various perspectives into your vulnerabilities, identity and access management (IAM) weaknesses, and misconfigurations in Amazon Web Services (AWS), Azure, and Kubernetes.

83%
of organisations report that one or more of their cloud data breaches were related to access
Expert Insights
What NodeZero tests

During internal and external pentests, NodeZero:

AWS logo

AWS

Enumerates cloud resources and assets to find an opening into AWS using attacker techniques like privilege escalation, lateral movement, and exploitable vulnerabilities.

Azure logo

Azure

Utilises a combination of Azure-native attacks and data harvested from the infrastructure to pivot in and out of hybrid cloud environments, demonstrating attack paths that compromise the entirety of perimeter security and Microsoft Azure Entra ID.

Kubernetes logo

Kubernetes

Pivots into Kubernetes environments by exploiting vulnerabilities, weak controls, or common misconfigurations.

01

Active autonomous probing for cloud weaknesses

NodeZero is deployable both on-premises and in the cloud. During internal and external pentests it exploits content native to the environment it is in, and organically uses the weaknesses it uncovers to pivot between on-premises and the cloud — exactly as an attacker who already has a foothold would.

NodeZero cloud attack path showing privilege escalation into AWS
NodeZero proves a full attack path into AWS — enumerating resources, then escalating and pivoting like an attacker who already has a foothold.
02

Find and fix IAM weaknesses

NodeZero runs advanced, vendor-specific testing with a grey-box approach that begins with AWS or Azure Entra ID credentials. By testing from the perspective of what an attacker with a credential can reach, it identifies the weaknesses and misconfigurations that lead to privilege escalation, overexposure of cloud assets, and the paths a malicious insider or external attacker could exploit.

03

Full tenant compromise — no CVE required

In one engagement, within the first two hours of testing and without using a single CVE, NodeZero exploited on-premises misconfigurations, organically pivoted into Azure, and achieved full tenant compromise by elevating itself to Microsoft Entra ID Global Admin. A compromise at that level renders the integrity and security of every application, asset, and user connected to Entra ID effectively useless. Grey-box IAM testing gives regulated Australian organisations the evidence they need for the cloud access-control risks they are obliged to assess under frameworks such as the Security of Critical Infrastructure (SOCI) Act and APRA CPS 234.

NodeZero attack path: full Entra ID tenant compromise without CVEs
NodeZero attack path: an on-premises foothold pivots into Azure and escalates to full Microsoft Entra ID Global Admin — no CVE required.
04

Kubernetes pentesting

Kubernetes has become the mainstay of cloud infrastructure, but its complexity brings significant security risks. Nearly 90% of organisations running containerised workloads faced a Kubernetes security incident in the past year (Red Hat, State of Kubernetes Security 2024), and around 96% are now running or evaluating Kubernetes (CNCF) — yet each distribution (AWS EKS, Google GKE, Azure AKS, or vanilla Kubernetes) introduces unique vulnerabilities an attacker can exploit, so a clean posture on one cannot be assumed to carry across the others. NodeZero autonomously pentests your clusters, continuously identifying exploitable risks like RBAC misconfigurations, container escapes, and secret exposures. It deploys within clusters using Kubernetes Operators and Infrastructure-as-Code (kubectl) for easy setup, and once deployed it tests continuously, with no additional manual effort and without sacrificing visibility into or testing of your other platform assets. Unlike tools that only check static configuration, NodeZero launches real-world attacks against live, running clusters — chaining container-runtime vulnerabilities with weak controls and policies just as an attacker would.

Kubernetes pentesting with NodeZero
05

Cross-platform attack chaining

NodeZero shows how vulnerabilities in Kubernetes can be chained together with weaknesses from across an organisation's underlying infrastructure to achieve greater impact, giving security teams a clear view of how attackers could move laterally and escalate privileges.

NodeZero attack path chaining an on-premises domain user to AWS administrator
NodeZero chains weaknesses across clouds and the underlying infrastructure into a single, provable attack path.
06

Continuously find, fix, and verify cloud weaknesses

The NodeZero platform offers advantages to your IT, security, and cloud-focused teams across dynamic cloud environments, whether you run an in-house team or operate as a managed services provider — in Australia and New Zealand, Drochaid delivers NodeZero as the managed-services layer. NodeZero tests hybrid cloud environments concurrently at scale and supports large multi-tenant deployments. It offers proof of every exploit, detailed remediation guidance, and Quick Verify so you can immediately confirm that your fixes are effective.

NodeZero Quick Verify confirming a remediated weakness
NodeZero proves each exploit and lets you confirm a fix actually worked with Quick Verify.
Use cases

Use the AWS, Azure, and Kubernetes pentests to:

01

Validate defence in depth

Identify and fix critical IAM misconfigurations and exploitable vulnerabilities across multiple layers of your defences to strengthen your overall security.

02

Reduce blast radius

Limit the impact of potential breaches by ensuring that access permissions and security defences are correctly configured.

03

Combat insider threats and credentialed attacks

Uncover and mitigate vulnerabilities that could be exploited by malicious insiders or attackers equipped with a credential.

Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Assess your cloud and hybrid environments

Run cloud pentests with NodeZero to find IAM weaknesses, misconfigurations, and exploitable attack paths across AWS, Azure, and Kubernetes.