Runbook 01 — Cloud Red Team Methodology
Runbook Information
Section titled “Runbook Information”| Property | Value |
|---|---|
| Runbook Name | Cloud Red Team Methodology |
| Module | Module 08 — Cloud Red Team Operations |
| Runbook Number | Runbook 01 |
| Difficulty | Advanced |
| Estimated Execution Time | Multi-day Engagement |
| Audience | Cloud Red Team Operators, Cloud Penetration Testers, Security Consultants |
| Objective | Provide a repeatable methodology for conducting professional Cloud Red Team engagements from planning through executive reporting and engagement closure. |
Purpose
Section titled “Purpose”Professional Cloud Red Team engagements are not simply penetration tests.
They are structured, objective-driven assessments that safely emulate realistic cloud adversaries to evaluate an organization’s ability to:
- Prevent attacks
- Detect malicious activity
- Investigate incidents
- Contain threats
- Recover from compromise
- Improve cloud security maturity
This runbook provides the standard operating methodology used throughout GoHackersCloud engagements.
Engagement Lifecycle
Section titled “Engagement Lifecycle”Business Objectives
↓
Threat Modelling
↓
Rules of Engagement
↓
Planning
↓
Reconnaissance
↓
Identity Assessment
↓
Privilege Escalation
↓
Lateral Movement
↓
Persistence Assessment
↓
Cloud Communication Validation
↓
Business Impact Validation
↓
Detection Validation
↓
Purple Team Collaboration
↓
Executive Reporting
↓
Remediation
↓
Retesting
↓
Engagement ClosurePhase 01 — Engagement Planning
Section titled “Phase 01 — Engagement Planning”Objective
Section titled “Objective”Understand why the engagement is being performed.
Activities
Section titled “Activities”- Meet executive stakeholders
- Define business objectives
- Understand critical applications
- Identify cloud platforms
- Review previous assessments
- Review compliance requirements
- Establish success criteria
Outputs
Section titled “Outputs”- Business Objectives
- Engagement Charter
- Threat Model
- Stakeholder Register
Phase 02 — Rules of Engagement
Section titled “Phase 02 — Rules of Engagement”Objective
Section titled “Objective”Define clear operational boundaries.
Include
Section titled “Include”- Scope
- Out-of-scope assets
- Approved operators
- Testing windows
- Communication channels
- Emergency contacts
- Stop conditions
- Evidence handling
- Data protection requirements
- Cleanup expectations
Decision Gate
Section titled “Decision Gate”Proceed only after formal written approval.
Phase 03 — Threat Modelling
Section titled “Phase 03 — Threat Modelling”Objective
Section titled “Objective”Select realistic cloud adversary scenarios.
Review
Section titled “Review”- Threat intelligence
- Industry attack trends
- MITRE ATT&CK
- Cloud attack techniques
- Business risks
- High-value assets
Deliverables
Section titled “Deliverables”- Threat Model
- Adversary Profile
- Attack Objectives
Phase 04 — Reconnaissance
Section titled “Phase 04 — Reconnaissance”Objective
Section titled “Objective”Identify publicly accessible cloud assets.
Assess
Section titled “Assess”- Domains
- DNS
- APIs
- Storage
- Identity portals
- Cloud services
- Serverless endpoints
- Kubernetes endpoints
- CI/CD services
Deliverables
Section titled “Deliverables”- External Attack Surface Inventory
- Cloud Footprint Map
- Public Asset Register
Phase 05 — Cloud Identity Assessment
Section titled “Phase 05 — Cloud Identity Assessment”Objective
Section titled “Objective”Understand identity relationships.
Review
Section titled “Review”- AWS IAM
- Microsoft Entra ID
- Google Cloud IAM
- Service Accounts
- Managed Identities
- Service Principals
- Kubernetes Service Accounts
- CI/CD identities
Identify
Section titled “Identify”- Excessive permissions
- Trust relationships
- Role assumptions
- Federation
- Workload identities
Deliverables
Section titled “Deliverables”- Identity Inventory
- Permission Matrix
- Trust Relationship Diagram
Phase 06 — Privilege Escalation Assessment
Section titled “Phase 06 — Privilege Escalation Assessment”Objective
Section titled “Objective”Validate approved privilege escalation paths.
Review
Section titled “Review”- AssumeRole
- PassRole
- Policy modifications
- Managed Identity assignments
- Service Account impersonation
- Kubernetes RBAC
- CI/CD execution roles
Validation
Section titled “Validation”Only approved identities and synthetic resources.
Deliverables
Section titled “Deliverables”- Privilege Escalation Matrix
- Identity Attack Graph
- Technical Findings
Phase 07 — Lateral Movement Assessment
Section titled “Phase 07 — Lateral Movement Assessment”Objective
Section titled “Objective”Validate movement between trusted cloud resources.
Review
Section titled “Review”- Cross-account trust
- Cross-subscription access
- Cross-project access
- Kubernetes namespaces
- Serverless execution identities
- CI/CD trust relationships
Deliverables
Section titled “Deliverables”- Attack Path Diagram
- Segmentation Assessment
- Trust Validation Report
Phase 08 — Persistence Assessment
Section titled “Phase 08 — Persistence Assessment”Objective
Section titled “Objective”Assess approved persistence opportunities.
Review
Section titled “Review”- IAM roles
- Scheduled functions
- Kubernetes CronJobs
- EventBridge
- Azure Automation
- Cloud Scheduler
- CI/CD pipelines
Requirements
Section titled “Requirements”- Temporary
- Approved
- Documented
- Fully reversible
Deliverables
Section titled “Deliverables”- Persistence Assessment
- Cleanup Plan
Phase 09 — Cloud Communication Validation
Section titled “Phase 09 — Cloud Communication Validation”Objective
Section titled “Objective”Validate cloud-native communication paths.
Review
Section titled “Review”- Amazon SQS
- SNS
- EventBridge
- Azure Service Bus
- Event Grid
- Google Pub/Sub
- Cloud Scheduler
Validate
Section titled “Validate”- Logging
- Detection
- Visibility
- Alerting
Deliverables
Section titled “Deliverables”- Communication Assessment
- Detection Summary
Phase 10 — Business Impact Validation
Section titled “Phase 10 — Business Impact Validation”Objective
Section titled “Objective”Safely demonstrate business impact.
Approved Assets
Section titled “Approved Assets”- Synthetic secrets
- Synthetic databases
- Test storage
- Test APIs
- Test applications
Never Use
Section titled “Never Use”- Real customer data
- Production databases
- Employee records
- Financial systems
Deliverables
Section titled “Deliverables”- Business Impact Assessment
- Executive Summary
Phase 11 — Detection Validation
Section titled “Phase 11 — Detection Validation”Objective
Section titled “Objective”Measure defensive capability.
Review
Section titled “Review”- CloudTrail
- Azure Monitor
- Google Cloud Logging
- Kubernetes Audit Logs
- SIEM
- GuardDuty
- Microsoft Sentinel
- Google SCC
Measure
Section titled “Measure”- Logging
- Detection
- Investigation
- Containment
Deliverables
Section titled “Deliverables”- Detection Assessment
- SOC Timeline
- ATT&CK Mapping
Phase 12 — Purple Team Collaboration
Section titled “Phase 12 — Purple Team Collaboration”Objective
Section titled “Objective”Improve security controls.
Participants
Section titled “Participants”- Red Team
- Blue Team
- SOC
- Cloud Security
- DevSecOps
- Incident Response
Activities
Section titled “Activities”- Review attack path
- Validate detections
- Tune alerts
- Improve playbooks
- Retest controls
Deliverables
Section titled “Deliverables”- Purple Team Report
- Detection Improvement Register
Phase 13 — Reporting
Section titled “Phase 13 — Reporting”Executive Report
Section titled “Executive Report”Include:
- Executive Summary
- Business Impact
- Attack Path
- Security Gaps
- Recommendations
- Roadmap
Technical Report
Section titled “Technical Report”Include:
- Scope
- Methodology
- Evidence
- Findings
- ATT&CK Mapping
- Risk Register
- Technical Recommendations
Deliverables
Section titled “Deliverables”- Executive Report
- Technical Report
- Executive Presentation
- Risk Register
Phase 14 — Remediation Planning
Section titled “Phase 14 — Remediation Planning”Prioritize
Section titled “Prioritize”Immediate
Section titled “Immediate”- Remove excessive permissions
- Restrict trust relationships
- Enable missing logging
Short Term
Section titled “Short Term”- Improve IAM
- Improve detection
- Improve segmentation
Long Term
Section titled “Long Term”- Zero Trust
- Continuous validation
- Cloud security governance
Deliverables
Section titled “Deliverables”- Remediation Roadmap
- Ownership Matrix
Phase 15 — Retesting
Section titled “Phase 15 — Retesting”Validate
Section titled “Validate”- Fixed findings
- Improved detections
- Updated IAM
- Segmentation improvements
Deliverables
Section titled “Deliverables”- Retest Report
Phase 16 — Engagement Closure
Section titled “Phase 16 — Engagement Closure”Verify
Section titled “Verify”- Temporary identities removed
- Temporary permissions removed
- Synthetic secrets rotated
- Test resources deleted
- Sessions revoked
- Evidence archived
- Customer sign-off received
Deliverables
Section titled “Deliverables”- Cleanup Verification
- Engagement Closure Report
Standard Deliverables Checklist
Section titled “Standard Deliverables Checklist”Planning
Section titled “Planning”- Engagement Charter
- Business Objectives
- Threat Model
- Rules of Engagement
- Scope Register
Technical
Section titled “Technical”- Reconnaissance Report
- Identity Assessment
- Privilege Escalation Assessment
- Lateral Movement Assessment
- Persistence Assessment
- Cloud Communication Assessment
Detection
Section titled “Detection”- Detection Validation
- Purple Team Report
- ATT&CK Mapping
Reporting
Section titled “Reporting”- Executive Report
- Technical Report
- Executive Presentation
- Risk Register
- Remediation Roadmap
Closure
Section titled “Closure”- Cleanup Verification
- Retest Report
- Engagement Closure Report
Operational Decision Gates
Section titled “Operational Decision Gates”| Phase | Decision |
|---|---|
| Planning | Executive approval received |
| Rules of Engagement | Written authorization complete |
| Reconnaissance | Scope confirmed |
| Identity Assessment | Approved identities only |
| Privilege Escalation | Synthetic resources only |
| Lateral Movement | Trust relationships approved |
| Persistence | Temporary and reversible |
| Business Impact | Synthetic assets only |
| Detection Validation | SOC notified (if required) |
| Reporting | Technical review completed |
| Closure | Cleanup verified |
Engagement Success Criteria
Section titled “Engagement Success Criteria”The engagement is successful when:
- Business objectives are achieved.
- Rules of Engagement are followed.
- Scope is maintained.
- No production disruption occurs.
- No real data is accessed.
- Security controls are evaluated.
- Detection capabilities are measured.
- Business impact is demonstrated using synthetic assets.
- Executive and technical reports are delivered.
- Remediation recommendations are prioritized.
- Cleanup is verified.
- Customer formally accepts the engagement.
Consultant Best Practices
Section titled “Consultant Best Practices”Professional Cloud Red Team consultants should always:
- Obtain written authorization before testing.
- Understand the customer’s business objectives.
- Use the minimum action necessary to validate a finding.
- Stay within the approved scope.
- Use synthetic identities and data whenever possible.
- Preserve evidence throughout the engagement.
- Maintain continuous communication with the engagement manager.
- Document every major activity and decision.
- Recognize security controls that performed well.
- Clearly distinguish confirmed findings from theoretical risks.
- Provide practical, prioritized remediation guidance.
- Verify cleanup before closing the engagement.
- Conduct professional executive and technical debriefings.
Common Pitfalls
Section titled “Common Pitfalls”Avoid the following mistakes:
- Beginning testing before authorization.
- Testing outside the approved scope.
- Using production data for demonstrations.
- Failing to document evidence.
- Ignoring defensive controls that worked.
- Providing overly technical executive reports.
- Omitting remediation ownership.
- Leaving temporary resources deployed after testing.
- Closing the engagement without customer acceptance.
Runbook Summary
Section titled “Runbook Summary”This runbook provides the complete operational methodology for conducting professional Cloud Red Team engagements.
Following this methodology ensures that engagements are:
- Safe
- Repeatable
- Evidence-driven
- Business-focused
- Threat-informed
- Professionally documented
- Executive-ready
- Technically accurate
- Aligned with enterprise consulting best practices
By consistently applying this methodology, Cloud Red Team Operators can deliver high-quality assessments that not only identify security weaknesses but also help organizations improve their overall cloud security posture through measurable, actionable, and repeatable security improvements.