{"product_id":"aws-cloud-pentest-extended","title":"AWS Cloud Pentest - Extended","description":"\u003cp\u003e\u003cstrong\u003eFixed price. Fixed scope. No sales call.\u003c\/strong\u003e A deeper AWS security review and penetration test for organisations with multiple accounts, container or serverless workloads, and a need to know what an attacker could do with a compromised low-privileged identity.\u003c\/p\u003e\n\u003ch3\u003eScope included\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUp to 3 AWS accounts, up to 2 regions\u003c\/li\u003e\n\u003cli\u003eRead-only audit role (via our CloudFormation template) plus one low-privileged test role you provide\u003c\/li\u003e\n\u003cli\u003eEstimated effort: 7 tester-days\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eWhat we test\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEverything in Baseline, across all in-scope accounts, plus:\u003c\/li\u003e\n\u003cli\u003ePrivilege-escalation paths starting from a low-privileged role (assumed breach)\u003c\/li\u003e\n\u003cli\u003eContainers and serverless: EKS\/ECS configuration, Lambda permissions and secrets in environment variables\u003c\/li\u003e\n\u003cli\u003eCross-account access between the in-scope accounts\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eDeliverables\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePDF report with executive summary and technical findings (CVSS-scored, with remediation advice)\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e1 free retest within 45 days\u003c\/strong\u003e of the final report: we verify your fixes and issue an updated report\u003c\/li\u003e\n\u003cli\u003eLetter of attestation you can share with auditors and customers\u003c\/li\u003e\n\u003cli\u003eCritical findings reported to you immediately, not at the end of the test\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eNot included\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAWS Organizations with more than 3 accounts (email us for a fixed price)\u003c\/li\u003e\n\u003cli\u003eAzure and Google Cloud; application-level testing of workloads running on AWS (see Web Application Pentest)\u003c\/li\u003e\n\u003cli\u003eSocial engineering \/ phishing, denial-of-service\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cem\u003eTesting follows the AWS penetration testing policy: no prior approval from AWS is required for the permitted services.\u003c\/em\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cem\u003eIf we discover during kick-off that your environment is larger than this tier, you can upgrade for the price difference or get a full refund, your choice.\u003c\/em\u003e\u003c\/p\u003e","brand":"fasttrack pentest","offers":[{"title":"Default Title","offer_id":64744587264377,"sku":"FT-AWS-T2","price":8095.0,"currency_code":"EUR","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1039\/6100\/2361\/files\/ft4-aws-2.svg?v=1790784178","url":"https:\/\/fasttrackpentest.com\/products\/aws-cloud-pentest-extended","provider":"fasttrack pentest","version":"1.0","type":"link"}