Skip to content

Runbook 01 — Cloud Red Team Methodology

Property Value
Runbook Name Cloud Red Team Methodology
Module Module 08 — Cloud Red Team Operations
Runbook Number Runbook 01
Difficulty Advanced
Estimated Execution Time Multi-day Engagement
Audience Cloud Red Team Operators, Cloud Penetration Testers, Security Consultants
Objective Provide a repeatable methodology for conducting professional Cloud Red Team engagements from planning through executive reporting and engagement closure.

Professional Cloud Red Team engagements are not simply penetration tests.

They are structured, objective-driven assessments that safely emulate realistic cloud adversaries to evaluate an organization’s ability to:

  • Prevent attacks
  • Detect malicious activity
  • Investigate incidents
  • Contain threats
  • Recover from compromise
  • Improve cloud security maturity

This runbook provides the standard operating methodology used throughout GoHackersCloud engagements.


Business Objectives
Threat Modelling
Rules of Engagement
Planning
Reconnaissance
Identity Assessment
Privilege Escalation
Lateral Movement
Persistence Assessment
Cloud Communication Validation
Business Impact Validation
Detection Validation
Purple Team Collaboration
Executive Reporting
Remediation
Retesting
Engagement Closure

Understand why the engagement is being performed.

  • Meet executive stakeholders
  • Define business objectives
  • Understand critical applications
  • Identify cloud platforms
  • Review previous assessments
  • Review compliance requirements
  • Establish success criteria
  • Business Objectives
  • Engagement Charter
  • Threat Model
  • Stakeholder Register

Define clear operational boundaries.

  • Scope
  • Out-of-scope assets
  • Approved operators
  • Testing windows
  • Communication channels
  • Emergency contacts
  • Stop conditions
  • Evidence handling
  • Data protection requirements
  • Cleanup expectations

Proceed only after formal written approval.


Select realistic cloud adversary scenarios.

  • Threat intelligence
  • Industry attack trends
  • MITRE ATT&CK
  • Cloud attack techniques
  • Business risks
  • High-value assets
  • Threat Model
  • Adversary Profile
  • Attack Objectives

Identify publicly accessible cloud assets.

  • Domains
  • DNS
  • APIs
  • Storage
  • Identity portals
  • Cloud services
  • Serverless endpoints
  • Kubernetes endpoints
  • CI/CD services
  • External Attack Surface Inventory
  • Cloud Footprint Map
  • Public Asset Register

Understand identity relationships.

  • AWS IAM
  • Microsoft Entra ID
  • Google Cloud IAM
  • Service Accounts
  • Managed Identities
  • Service Principals
  • Kubernetes Service Accounts
  • CI/CD identities
  • Excessive permissions
  • Trust relationships
  • Role assumptions
  • Federation
  • Workload identities
  • Identity Inventory
  • Permission Matrix
  • Trust Relationship Diagram

Phase 06 — Privilege Escalation Assessment

Section titled “Phase 06 — Privilege Escalation Assessment”

Validate approved privilege escalation paths.

  • AssumeRole
  • PassRole
  • Policy modifications
  • Managed Identity assignments
  • Service Account impersonation
  • Kubernetes RBAC
  • CI/CD execution roles

Only approved identities and synthetic resources.

  • Privilege Escalation Matrix
  • Identity Attack Graph
  • Technical Findings

Validate movement between trusted cloud resources.

  • Cross-account trust
  • Cross-subscription access
  • Cross-project access
  • Kubernetes namespaces
  • Serverless execution identities
  • CI/CD trust relationships
  • Attack Path Diagram
  • Segmentation Assessment
  • Trust Validation Report

Assess approved persistence opportunities.

  • IAM roles
  • Scheduled functions
  • Kubernetes CronJobs
  • EventBridge
  • Azure Automation
  • Cloud Scheduler
  • CI/CD pipelines
  • Temporary
  • Approved
  • Documented
  • Fully reversible
  • Persistence Assessment
  • Cleanup Plan

Phase 09 — Cloud Communication Validation

Section titled “Phase 09 — Cloud Communication Validation”

Validate cloud-native communication paths.

  • Amazon SQS
  • SNS
  • EventBridge
  • Azure Service Bus
  • Event Grid
  • Google Pub/Sub
  • Cloud Scheduler
  • Logging
  • Detection
  • Visibility
  • Alerting
  • Communication Assessment
  • Detection Summary

Safely demonstrate business impact.

  • Synthetic secrets
  • Synthetic databases
  • Test storage
  • Test APIs
  • Test applications
  • Real customer data
  • Production databases
  • Employee records
  • Financial systems
  • Business Impact Assessment
  • Executive Summary

Measure defensive capability.

  • CloudTrail
  • Azure Monitor
  • Google Cloud Logging
  • Kubernetes Audit Logs
  • SIEM
  • GuardDuty
  • Microsoft Sentinel
  • Google SCC
  • Logging
  • Detection
  • Investigation
  • Containment
  • Detection Assessment
  • SOC Timeline
  • ATT&CK Mapping

Improve security controls.

  • Red Team
  • Blue Team
  • SOC
  • Cloud Security
  • DevSecOps
  • Incident Response
  • Review attack path
  • Validate detections
  • Tune alerts
  • Improve playbooks
  • Retest controls
  • Purple Team Report
  • Detection Improvement Register

Include:

  • Executive Summary
  • Business Impact
  • Attack Path
  • Security Gaps
  • Recommendations
  • Roadmap

Include:

  • Scope
  • Methodology
  • Evidence
  • Findings
  • ATT&CK Mapping
  • Risk Register
  • Technical Recommendations

  • Executive Report
  • Technical Report
  • Executive Presentation
  • Risk Register

  • Remove excessive permissions
  • Restrict trust relationships
  • Enable missing logging
  • Improve IAM
  • Improve detection
  • Improve segmentation
  • Zero Trust
  • Continuous validation
  • Cloud security governance
  • Remediation Roadmap
  • Ownership Matrix

  • Fixed findings
  • Improved detections
  • Updated IAM
  • Segmentation improvements
  • Retest Report

  • Temporary identities removed
  • Temporary permissions removed
  • Synthetic secrets rotated
  • Test resources deleted
  • Sessions revoked
  • Evidence archived
  • Customer sign-off received
  • Cleanup Verification
  • Engagement Closure Report

  • Engagement Charter
  • Business Objectives
  • Threat Model
  • Rules of Engagement
  • Scope Register
  • Reconnaissance Report
  • Identity Assessment
  • Privilege Escalation Assessment
  • Lateral Movement Assessment
  • Persistence Assessment
  • Cloud Communication Assessment
  • Detection Validation
  • Purple Team Report
  • ATT&CK Mapping
  • Executive Report
  • Technical Report
  • Executive Presentation
  • Risk Register
  • Remediation Roadmap
  • Cleanup Verification
  • Retest Report
  • Engagement Closure Report

Phase Decision
Planning Executive approval received
Rules of Engagement Written authorization complete
Reconnaissance Scope confirmed
Identity Assessment Approved identities only
Privilege Escalation Synthetic resources only
Lateral Movement Trust relationships approved
Persistence Temporary and reversible
Business Impact Synthetic assets only
Detection Validation SOC notified (if required)
Reporting Technical review completed
Closure Cleanup verified

The engagement is successful when:

  • Business objectives are achieved.
  • Rules of Engagement are followed.
  • Scope is maintained.
  • No production disruption occurs.
  • No real data is accessed.
  • Security controls are evaluated.
  • Detection capabilities are measured.
  • Business impact is demonstrated using synthetic assets.
  • Executive and technical reports are delivered.
  • Remediation recommendations are prioritized.
  • Cleanup is verified.
  • Customer formally accepts the engagement.

Professional Cloud Red Team consultants should always:

  • Obtain written authorization before testing.
  • Understand the customer’s business objectives.
  • Use the minimum action necessary to validate a finding.
  • Stay within the approved scope.
  • Use synthetic identities and data whenever possible.
  • Preserve evidence throughout the engagement.
  • Maintain continuous communication with the engagement manager.
  • Document every major activity and decision.
  • Recognize security controls that performed well.
  • Clearly distinguish confirmed findings from theoretical risks.
  • Provide practical, prioritized remediation guidance.
  • Verify cleanup before closing the engagement.
  • Conduct professional executive and technical debriefings.

Avoid the following mistakes:

  • Beginning testing before authorization.
  • Testing outside the approved scope.
  • Using production data for demonstrations.
  • Failing to document evidence.
  • Ignoring defensive controls that worked.
  • Providing overly technical executive reports.
  • Omitting remediation ownership.
  • Leaving temporary resources deployed after testing.
  • Closing the engagement without customer acceptance.

This runbook provides the complete operational methodology for conducting professional Cloud Red Team engagements.

Following this methodology ensures that engagements are:

  • Safe
  • Repeatable
  • Evidence-driven
  • Business-focused
  • Threat-informed
  • Professionally documented
  • Executive-ready
  • Technically accurate
  • Aligned with enterprise consulting best practices

By consistently applying this methodology, Cloud Red Team Operators can deliver high-quality assessments that not only identify security weaknesses but also help organizations improve their overall cloud security posture through measurable, actionable, and repeatable security improvements.