Every cloud account, seen the way an attacker sees it.
Connect AWS, Azure and Google Cloud with read-only access. Mockingjay finds misconfigurations, vulnerable workloads and risky identities, then ranks them by what's actually reachable from the internet.
- AWS
- Microsoft Azure
- Google Cloud
- Agentless
- CIS benchmarks
- Identity risk
- AWSprod-core3 regions · 2,940 resources12 issues
- AWSdata-platform2 regions · 1,180 resources7 issues
- AZUREpayments-sub2 regions · 860 resources4 issues
- GCPweb-edge2 regions · 1,234 resources5 issues
- CIS AWS Foundations87% passing
- CIS Microsoft Azure91% passing
- CIS Google Cloud84% passing
- SOC 2 cloud controls89% passing
- Storage6
- Identity9
- Compute5
- Network4
- Databases3
- Logging1
| Issue | Resource | Exposure | Severity |
|---|---|---|---|
| Storage bucket allows public object listing | aws · s3://prod-backups | Internet | Critical |
| Security group allows SSH from 0.0.0.0/0 | aws · sg-0a91 · bastion | Internet | High |
| VM image has critical OpenSSL vulnerability | gcp · web-pool-3 | Internet | High |
| IAM role can assume admin across accounts | aws · ci-deployer | Internal | High |
| Database snapshot shared with all accounts | aws · rds-snap-0921 | Cross-account | High |
| Key vault soft-delete disabled | azure · kv-payments | Internal | Medium |
| Audit logging disabled in one region | aws · ap-south-1 | Internal | Low |
Prioritised by reachability, not by volume.
A thousand low-risk warnings hide the one bucket that's public. Mockingjay puts internet-reachable, sensitive and over-privileged resources at the top.
Misconfiguration checks
Hundreds of checks across storage, compute, networking, databases and logging, mapped to CIS benchmarks.
Workload vulnerabilities
Agentless snapshot scanning of VMs and container images for known vulnerabilities and outdated packages.
Identity and access risk
Find over-privileged roles, unused keys and paths that let one identity escalate to admin.
Internet exposure first
Every finding carries a reachability label, so publicly exposed resources rise to the top.
Fix guidance in your terms
Console steps, CLI commands and infrastructure-as-code snippets for each misconfiguration.
Continuous, not quarterly
Scans run on a schedule and on change events, so drift is caught soon after it happens.
Connected in minutes. Read-only, always.
- 01
Create a read-only role
Deploy our template for AWS, Azure or Google Cloud. It grants read access only; nothing can be changed.
- 02
Pick accounts and regions
Connect one account or an entire organisation, and exclude anything out of scope.
- 03
Review prioritised results
The first scan completes within 30 minutes, with findings ranked by exposure and severity.
Cloud scanning questions
- What access does Mockingjay need?
- Read-only access through a role you control. We never request write permissions and you can revoke access at any time.
- Do you install agents?
- No. Workload scanning uses cloud-native snapshots, so there is nothing to install or maintain on your instances.
- How does this relate to a cloud pentest?
- The scanner gives continuous coverage of configuration and known vulnerabilities. An expert cloud review through PTaaS adds manual testing of identity paths and service-specific attacks.
- Which frameworks are supported?
- CIS benchmarks for each cloud, plus mappings to SOC 2, ISO 27001, PCI DSS and HIPAA controls.
See what's exposed in your cloud.
Connect one account during the demo and get a prioritised view before the call ends.
