Case Study - Configuration Security Testing (Defaults Are Vulnerabilities)
S3 “private” with public policy. K8s dashboard without auth. 300+ defaults waiting to be headlines.
Server
Cloud IAM
Container
API GW
vs Baseline
Client Context
Bank migrating to AWS — 120 accounts, EKS, RDS, API gateway, 400+ EC2/VMs, IaC half-adopted. OJK cloud guideline + ISO 27001 A.8 review.
Challenge
Test configurations of server, cloud, application, container, API, and security controls against defined baselines (CIS + bank hardening standard) — continuously, not as annual checklist.
Scope - Snipeyes Configuration Security Testing
- Baseline packs: CIS AWS Foundations, CIS K8s, OS hardening (Linux/Windows), DB, WAF/gateway, TLS/headers
- IaC review (Terraform/CloudFormation/Helm) + runtime drift detection
- Risk-ranked misconfiguration findings with fix-as-code snippets
- Output: misconfiguration findings + compliance-gap matrix
Key Findings (redacted)
- CRITICAL: 4 S3 buckets “private” but policy allowed
*read; 1 contained e-statement PDFs - HIGH: EKS dashboard + ArgoCD exposed without SSO; default
admin/adminvalid on 1 console - HIGH:
0.0.0.0/0on 38 security groups incl. DB port; CloudTrail disabled in 17 accounts - 300+ drifts traced to 3 root causes: cloned insecure AMI, wildcard IAM, unmanaged Helm values
Outcome
- Buckets + IAM + SGs remediated in 3 weeks (300+ → 12, all low); SCPs + IaC policy gates prevent recurrence
- Golden AMI + Helm baseline published; drift alert <24h
- OJK cloud + ISO evidence auto-generated per account
Relevance for you: If cloud grew faster than governance — baseline it before attackers baseline you.