Cloud breaches in 2026 rarely occur because an attacker broke modern cryptographic algorithms. They happen because of identity misconfigurations: an overly permissive IAM role, an SSRF vulnerability accessing the legacy Instance Metadata Service (IMDSv1), or a developer who forgot an S3 bucket policy allowed public reads.
Traditional Cloud Security Posture Management (CSPM) tools generate hundreds of alerts for compliance violations, but they lack offensive context. They cannot tell you if an attacker who gains access to a single low-privilege service account can chain permissions to assume an administrator role.
The LoryCloudPentestEngine solves this by simulating authenticated, real-world adversary attack graphs across AWS, Azure, and Google Cloud environments.
Non-Destructive Attack Graphing: Lory connects using read-only cross-account credentials (such as an AWS AssumeRole with External ID). It explores privilege escalation paths mathematically without executing destructive actions or mutating production cloud state.
What Lory's Cloud Engine Evaluates
1. IAM Privilege Escalation Chains
Analyzes dozens of known cloud privilege escalation vectors (e.g., iam:PassRole linked to an EC2 instance, iam:CreatePolicyVersion, or wildcards in assume-role trust relationships) to determine if a lateral pivot can reach administrative privilege.
2. Storage & Database Bucket Exposure
Audits S3 bucket policies, Azure Blob containers, and Google Cloud Storage buckets for public read/write configurations, cross-account access, and missing server-side encryption.
3. Instance Metadata Service (IMDSv1 vs. IMDSv2)
Checks all virtual machine instances to ensure IMDSv1 is disabled and IMDSv2 is strictly enforced with a hop limit of 1, neutralizing SSRF credential exfiltration risks.
4. Network Perimeter & Security Groups
Flags security groups and firewall rules allowing 0.0.0.0/0 access to management ports (SSH, RDP, Kubernetes API server, database engines).
Audit Readiness for SOC 2, ISO 27001 & FedRAMP
Discovered cloud attack paths are mapped directly to compliance frameworks, generating verified evidence packages and remediation blueprints for your engineering team.
Harden Your Cloud Attack Surface with Lory
Uncover hidden privilege escalation paths and cloud misconfigurations. Schedule an autonomous cloud penetration test with Lorikeet Security.