{"product_id":"aws-cloud-pentest-baseline","title":"AWS Cloud Pentest - Baseline","description":"\u003cp\u003e\u003cstrong\u003eFixed price. Fixed scope. No sales call.\u003c\/strong\u003e A manual security review and penetration test of one AWS account: the right fit for SaaS companies that run on AWS and need evidence for SOC 2, ISO 27001 or a customer security review.\u003c\/p\u003e\n\u003ch3\u003eScope included\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e1 AWS account, 1 region\u003c\/li\u003e\n\u003cli\u003eRead-only access via an audit role you create with our CloudFormation template (no write permissions needed)\u003c\/li\u003e\n\u003cli\u003eEstimated effort: 5 tester-days\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eWhat we test\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration review against the CIS AWS Foundations Benchmark\u003c\/li\u003e\n\u003cli\u003eIAM: overly permissive policies, unused or exposed access keys, missing MFA, risky trust relationships\u003c\/li\u003e\n\u003cli\u003ePublicly exposed resources: S3 buckets, snapshots, security groups, load balancers, API Gateway\u003c\/li\u003e\n\u003cli\u003eLogging and encryption: CloudTrail, S3 and EBS encryption, key management\u003c\/li\u003e\n\u003cli\u003eManual validation of every finding, so you get real risks rather than a raw tool export\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eDeliverables\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePDF report with executive summary and technical findings (CVSS-scored, with remediation advice)\u003c\/li\u003e\n\u003cli\u003eLetter of attestation you can share with auditors and customers\u003c\/li\u003e\n\u003cli\u003eCritical findings reported to you immediately, not at the end of the test\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eNot included\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRetest of findings: add a \u003ca href=\"\/products\/retest-fix-verification\"\u003eSeparate Retest ($1,499)\u003c\/a\u003e, or choose Extended where a free retest is included\u003c\/li\u003e\n\u003cli\u003ePrivilege-escalation testing from a low-privileged role (see Extended)\u003c\/li\u003e\n\u003cli\u003eAzure and Google Cloud; application-level testing of workloads running on AWS (see Web Application Pentest)\u003c\/li\u003e\n\u003cli\u003eSocial engineering \/ phishing, denial-of-service\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cem\u003eTesting follows the AWS penetration testing policy: no prior approval from AWS is required for the permitted services.\u003c\/em\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cem\u003eIf we discover during kick-off that your environment is larger than this tier, you can upgrade for the price difference or get a full refund, your choice.\u003c\/em\u003e\u003c\/p\u003e","brand":"fasttrack pentest","offers":[{"title":"Default Title","offer_id":64744580448633,"sku":"FT-AWS-T1","price":6095.0,"currency_code":"EUR","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1039\/6100\/2361\/files\/ft4-aws-1.svg?v=1790784178","url":"https:\/\/fasttrackpentest.com\/products\/aws-cloud-pentest-baseline","provider":"fasttrack pentest","version":"1.0","type":"link"}