Case Study - Configuration Security Testing (Defaults Are Vulnerabilities)

S3 “private” with public policy. K8s dashboard without auth. 300+ defaults waiting to be headlines.

ILLUSTRATION — BASELINE DOMAINS
🖥️
Server
☁️
Cloud IAM
📦
Container
🔌
API GW
📏
vs Baseline

Client Context

Bank migrating to AWS — 120 accounts, EKS, RDS, API gateway, 400+ EC2/VMs, IaC half-adopted. OJK cloud guideline + ISO 27001 A.8 review.

Challenge

Test configurations of server, cloud, application, container, API, and security controls against defined baselines (CIS + bank hardening standard) — continuously, not as annual checklist.

Scope - Snipeyes Configuration Security Testing

  • Baseline packs: CIS AWS Foundations, CIS K8s, OS hardening (Linux/Windows), DB, WAF/gateway, TLS/headers
  • IaC review (Terraform/CloudFormation/Helm) + runtime drift detection
  • Risk-ranked misconfiguration findings with fix-as-code snippets
  • Output: misconfiguration findings + compliance-gap matrix

Key Findings (redacted)

  • CRITICAL: 4 S3 buckets “private” but policy allowed * read; 1 contained e-statement PDFs
  • HIGH: EKS dashboard + ArgoCD exposed without SSO; default admin/admin valid on 1 console
  • HIGH: 0.0.0.0/0 on 38 security groups incl. DB port; CloudTrail disabled in 17 accounts
  • 300+ drifts traced to 3 root causes: cloned insecure AMI, wildcard IAM, unmanaged Helm values

Outcome

  • Buckets + IAM + SGs remediated in 3 weeks (300+ → 12, all low); SCPs + IaC policy gates prevent recurrence
  • Golden AMI + Helm baseline published; drift alert <24h
  • OJK cloud + ISO evidence auto-generated per account

Relevance for you: If cloud grew faster than governance — baseline it before attackers baseline you.