Details.
A scoped manual review of named projects, subscriptions or accounts. Resources and identity are assessed together, findings are validated against the architecture, and confirmed issues are chained into attack paths. Operational resilience is out of scope. Includes verified attack paths with proof of concept and prioritised fixes.
