What problem does it solve?
Cloud security assessments are often unstructured and hard to reproduce. ctest provides a structured 5-phase framework to orchestrate discovery, IAM analysis, service exploitation, and final reporting across AWS, GCP, and Azure, with gate checks and a centralized findings log to ensure consistent results.
Core Features & Use Cases
- Structured 5-phase workflow (Discovery, IAM & Access, Service Exploitation, Container & Orchestration, Reporting) with gated progress.
- Automated artifacts and state management via ctest-output (state.yaml, scope.md, findings-log.md).
- IAM enumeration, metadata/probing, storage/service exploitation, container/RBAC testing, and cross-skill handoffs for holistic cloud security assessments.
- Gate-driven advancement and abandon/pivot heuristics to optimize engagement efficiency.
Quick Start
Use the ctest tool to initialize an engagement and begin Phase 1 discovery.