Skip to content
Mockingjay

Every cloud account, seen the way an attacker sees it.

Connect AWS, Azure and Google Cloud with read-only access. Mockingjay finds misconfigurations, vulnerable workloads and risky identities, then ranks them by what's actually reachable from the internet.

4 accounts · 9 regions · 6,214 resources · agentlessCloud posture
All cloudsAWSAzureGoogle Cloud
Accounts
  • AWSprod-core3 regions · 2,940 resources12 issues
  • AWSdata-platform2 regions · 1,180 resources7 issues
  • AZUREpayments-sub2 regions · 860 resources4 issues
  • GCPweb-edge2 regions · 1,234 resources5 issues
Benchmarks
  • CIS AWS Foundations87% passing
  • CIS Microsoft Azure91% passing
  • CIS Google Cloud84% passing
  • SOC 2 cloud controls89% passing
  • Storage6
  • Identity9
  • Compute5
  • Network4
  • Databases3
  • Logging1
IssueResourceExposureSeverity
Storage bucket allows public object listingaws · s3://prod-backupsInternetCritical
Security group allows SSH from 0.0.0.0/0aws · sg-0a91 · bastionInternetHigh
VM image has critical OpenSSL vulnerabilitygcp · web-pool-3InternetHigh
IAM role can assume admin across accountsaws · ci-deployerInternalHigh
Database snapshot shared with all accountsaws · rds-snap-0921Cross-accountHigh
Key vault soft-delete disabledazure · kv-paymentsInternalMedium
Audit logging disabled in one regionaws · ap-south-1InternalLow
Illustrative product view · sample data

Prioritised by reachability, not by volume.

A thousand low-risk warnings hide the one bucket that's public. Mockingjay puts internet-reachable, sensitive and over-privileged resources at the top.

Connected in minutes. Read-only, always.

  1. 01

    Create a read-only role

    Deploy our template for AWS, Azure or Google Cloud. It grants read access only; nothing can be changed.

  2. 02

    Pick accounts and regions

    Connect one account or an entire organisation, and exclude anything out of scope.

  3. 03

    Review prioritised results

    The first scan completes within 30 minutes, with findings ranked by exposure and severity.

Cloud scanning questions

What access does Mockingjay need?
Read-only access through a role you control. We never request write permissions and you can revoke access at any time.
Do you install agents?
No. Workload scanning uses cloud-native snapshots, so there is nothing to install or maintain on your instances.
How does this relate to a cloud pentest?
The scanner gives continuous coverage of configuration and known vulnerabilities. An expert cloud review through PTaaS adds manual testing of identity paths and service-specific attacks.
Which frameworks are supported?
CIS benchmarks for each cloud, plus mappings to SOC 2, ISO 27001, PCI DSS and HIPAA controls.

See what's exposed in your cloud.

Connect one account during the demo and get a prioritised view before the call ends.

Book a demo