Runbook 01 — Cloud Pentest Preparation Checklist
Runbook Information
Section titled “Runbook Information”| Item | Details |
|---|---|
| Runbook ID | CPS-RB-001 |
| Category | Cloud Penetration Testing |
| Use Case | Pre-Engagement Preparation |
| Audience | Cloud Penetration Testers, Red Teams, Security Consultants |
| Estimated Time | 30–60 Minutes |
| Prerequisites | Signed Rules of Engagement (RoE), Customer Authorization |
Purpose
Section titled “Purpose”This runbook provides a standardized checklist used before every cloud penetration testing engagement.
Its purpose is to ensure that:
- Testing is authorized.
- Scope is clearly defined.
- Required access is available.
- Tools are functioning correctly.
- Risks are minimized.
- Evidence collection is prepared.
- Customer communication channels are established.
Professional cloud penetration testing always begins with preparation—not exploitation.
Enterprise Scenario
Section titled “Enterprise Scenario”CloudNova Technologies has been contracted to perform a cloud penetration test for FinSecure Bank Ltd.
Before any testing begins, every consultant must complete the organization’s Cloud Pentest Preparation Checklist.
Failure to complete these activities may:
- Delay the engagement.
- Increase operational risk.
- Produce inaccurate results.
- Violate customer agreements.
Preparation Workflow
Section titled “Preparation Workflow”Receive Engagement
↓
Review Scope
↓
Review Rules of Engagement
↓
Verify Authorization
↓
Prepare Workstation
↓
Verify Cloud Access
↓
Validate Tools
↓
Review Architecture
↓
Confirm Communication
↓
Begin AssessmentPhase 1 — Engagement Review
Section titled “Phase 1 — Engagement Review”Objective
Section titled “Objective”Understand exactly what the customer has requested.
Review:
- Statement of Work (SoW)
- Rules of Engagement (RoE)
- Assessment Objectives
- Assessment Timeline
- Deliverables
- Success Criteria
Checklist
Section titled “Checklist”- Statement of Work reviewed
- Scope understood
- Objectives confirmed
- Deliverables reviewed
- Timeline verified
Phase 2 — Authorization Review
Section titled “Phase 2 — Authorization Review”Objective
Section titled “Objective”Ensure testing is legally authorized.
Verify:
- Written authorization
- Approved customer contacts
- Testing window
- Emergency contacts
- Escalation process
Never perform testing without documented authorization.
Checklist
Section titled “Checklist”- Authorization letter received
- Customer approval confirmed
- Emergency contacts documented
- Maintenance window confirmed
- Escalation procedure documented
Phase 3 — Scope Validation
Section titled “Phase 3 — Scope Validation”Identify what is:
In Scope
Section titled “In Scope”Examples:
- AWS Accounts
- Azure Subscriptions
- GCP Projects
- Kubernetes Clusters
- APIs
- Storage
- Virtual Machines
- IAM
Out of Scope
Section titled “Out of Scope”Examples:
- Production payment systems
- Third-party services
- Social engineering
- Denial of Service
- Physical security
Checklist
Section titled “Checklist”- In-scope assets documented
- Out-of-scope assets documented
- Target IP ranges verified
- Domains confirmed
- Cloud accounts confirmed
Phase 4 — Verify Cloud Access
Section titled “Phase 4 — Verify Cloud Access”Authenticate to the approved cloud environment.
AWS
aws sts get-caller-identityAzure
az account showGoogle Cloud
gcloud auth listVerify:
- Correct account
- Correct subscription/project
- Correct permissions
Checklist
Section titled “Checklist”- AWS authentication successful
- Azure authentication successful (if applicable)
- GCP authentication successful (if applicable)
- Read-only access verified
- Required assessment permissions available
Phase 5 — Verify Assessment Tools
Section titled “Phase 5 — Verify Assessment Tools”Confirm all required tools are installed and working.
Cloud Tools
Section titled “Cloud Tools”- AWS CLI
- Azure CLI
- Google Cloud CLI
Kubernetes
Section titled “Kubernetes”- kubectl
- Helm
Container Security
Section titled “Container Security”- Docker
- Trivy
- Grype
- Syft
Assessment Tools
Section titled “Assessment Tools”- ScoutSuite
- PMapper
- Checkov
- Terraform
Utilities
Section titled “Utilities”- Git
- jq
- curl
- nmap
- dig
Checklist
Section titled “Checklist”- AWS CLI
- kubectl
- Docker
- Terraform
- ScoutSuite
- Trivy
- Checkov
- Git
- jq
- Nmap
Phase 6 — Validate Lab Environment
Section titled “Phase 6 — Validate Lab Environment”Verify:
- Internet connectivity
- VPN connectivity
- DNS resolution
- Local storage
- Screenshots folder
- Report templates
Example:
ping google.com
aws --version
kubectl version --clientChecklist
Section titled “Checklist”- Internet connectivity
- VPN connected
- DNS working
- Local workspace prepared
- Report template created
Phase 7 — Review Cloud Architecture
Section titled “Phase 7 — Review Cloud Architecture”Study customer documentation.
Review:
- Cloud Accounts
- VPC Architecture
- IAM Design
- Kubernetes Architecture
- Storage
- APIs
- CI/CD
- Monitoring
Understand:
- Business-critical systems
- High-value assets
- Sensitive data
Checklist
Section titled “Checklist”- Architecture diagrams reviewed
- Network topology understood
- IAM model reviewed
- Kubernetes architecture reviewed
- Business-critical assets identified
Phase 8 — Prepare Documentation
Section titled “Phase 8 — Prepare Documentation”Create engagement folders.
Assessment/
├── Notes├── Screenshots├── Evidence├── Reports├── Findings├── Diagrams├── Scripts└── LogsChecklist
Section titled “Checklist”- Notes folder
- Screenshots folder
- Evidence folder
- Findings folder
- Report template ready
Phase 9 — Communication Planning
Section titled “Phase 9 — Communication Planning”Identify:
- Technical Contact
- Project Manager
- Security Team
- Incident Response Team
Agree on:
- Daily status updates
- Critical finding escalation
- Communication channel
- Meeting schedule
Checklist
Section titled “Checklist”- Technical contact documented
- Daily meetings scheduled
- Critical escalation process confirmed
- Communication platform agreed
Phase 10 — Risk Review
Section titled “Phase 10 — Risk Review”Identify potential operational risks.
Examples:
- Production impact
- Shared environments
- Maintenance windows
- API rate limits
- Cloud service quotas
Mitigation:
- Follow Rules of Engagement.
- Avoid unnecessary changes.
- Validate before testing.
Checklist
Section titled “Checklist”- Production risks identified
- Maintenance windows reviewed
- API limits understood
- Cloud quotas reviewed
Phase 11 — Evidence Collection Preparation
Section titled “Phase 11 — Evidence Collection Preparation”Evidence should include:
- Screenshots
- CLI output
- Configuration files
- Cloud resource identifiers
- Logs
- Architecture diagrams
Naming convention:
Evidence/
IAM/
Storage/
Networking/
Kubernetes/
Compute/Checklist
Section titled “Checklist”- Screenshot tool ready
- Evidence folders created
- Naming convention defined
- Time synchronization verified
Phase 12 — Final Readiness Review
Section titled “Phase 12 — Final Readiness Review”Confirm:
- Authorization received
- Scope understood
- Tools operational
- Cloud access working
- Documentation prepared
- Customer notified
If all checks pass:
READY TO BEGINEnterprise Preparation Checklist
Section titled “Enterprise Preparation Checklist”| Item | Status |
|---|---|
| Authorization Verified | ☐ |
| Scope Reviewed | ☐ |
| AWS Authentication Verified | ☐ |
| Tools Tested | ☐ |
| Architecture Reviewed | ☐ |
| Documentation Prepared | ☐ |
| Communication Plan Ready | ☐ |
| Evidence Folder Created | ☐ |
| Risks Reviewed | ☐ |
| Final Approval Received | ☐ |
Common Mistakes
Section titled “Common Mistakes”Avoid:
- Starting without written authorization.
- Testing assets outside the agreed scope.
- Using personal cloud accounts.
- Failing to verify IAM permissions.
- Ignoring maintenance windows.
- Not preparing evidence folders.
- Beginning testing without understanding the architecture.
Best Practices
Section titled “Best Practices”- Review the Rules of Engagement before every engagement.
- Verify cloud access before the assessment starts.
- Keep evidence organized from the beginning.
- Communicate regularly with the customer.
- Document every important action.
- Validate tools before the engagement.
- Treat preparation as part of the penetration test.
Expected Deliverables
Section titled “Expected Deliverables”Upon completing this runbook, you should have:
- Engagement Readiness Checklist
- Verified Cloud Access
- Prepared Assessment Workstation
- Organized Evidence Structure
- Communication Plan
- Architecture Review Notes
- Risk Assessment Notes
- Assessment Workspace
Success Criteria
Section titled “Success Criteria”You have successfully completed this runbook when:
- All checklist items are complete.
- Cloud authentication is verified.
- Assessment tools are operational.
- Documentation structure is prepared.
- Customer communication channels are established.
- The engagement can begin without delays or operational risk.
Next Runbook
Section titled “Next Runbook”Continue with:
➡️ Runbook 02 — Enterprise Cloud Security Assessment