πŸš€ TG4G
Directory β€Ί Cybersecurity β€Ί shroudcloud.com
πŸ›‘ Cybersecurity πŸ“ HQ: Unknown
S

shroudcloud.com

Overall Rating
β˜…β˜…β˜…β―¨β˜† 7.0/10
China Access
β˜…β˜…β˜† Basically usable
Data source
ai_crawl Β· Last updated 2026-06-08

Editorial Highlights

Valuable for security practitioners focused on authorized red-team testing.

In-Depth Review TG4G Review Β·2026-06-08 Β· For reference only

What it is

ShroudCloud is positioned as OAuth Attack Infrastructure for penetration testing firms, internal corporate red teams, and independent researchers, intended for conducting authentication attack testing in authorized scenarios. It is not a firewall, WAF, or identity protection platform in the traditional sense. Instead, it provides configurable OAuth components, including a malicious IdP and crafted RP, to help test OAuth misconfiguration issues in real targets.

Core capabilities

The current Beta scope focuses on two attack flows: Authorization Code Interception and Redirect URI Manipulation. In the former, ShroudCloud acts as a malicious IdP during the authorization handshake, capturing authorization codes and token payloads after the client ID, redirect URI, and scope are configured. In the latter, a crafted RP is used to probe redirect URI validation issues in the target IdP, including open redirects, subdomain confusion, path traversal, and fragment injection. The platform also records full HTTP requests and responses, tokens, codes, redirects, and timing data, making it easier to produce reports and preserve evidence.

Pricing and maturity

No specific pricing is disclosed in the main content. The terms of service indicate that subscriptions are billed monthly, cancellations take effect at the end of the current billing period, and partial months are not refunded. The roadmap mentions that Phase 2 will open individual subscriptions. The product is currently in private development / early access, with Phase 1 mainly centered on the waitlist, so product access remains limited. Compliance certifications, SLA, enterprise support, and payment methods are not specified.

Pros and cons

The main advantage is its highly focused positioning: it addresses the recurring pain point for red teams of having to build their own IdP/RP setups for OAuth engagements. Parameterized configuration and session logging can improve both execution and reporting efficiency. The open-source FlawedToken demo target is also useful for practice and client demos. The downside is that the current capability set is still narrow: SAML, MFA bypass, session lifecycle, IaC export, and other features remain on the roadmap. In addition, the terms mention β€œprivate VPN infrastructure services,” which does not fully align with the product positioning on the homepage, so the service scope should be clarified before procurement.

Who it is for and access from China

ShroudCloud is better suited to professional red teams, penetration testing teams, and researchers with clear, authorized authentication testing needs. It is not suitable for ordinary enterprises to purchase directly as a day-to-day security protection tool. Access from mainland China, payment support, and local compliance information are not disclosed, so china_access can only be assessed as unknown. If it is not usable, alternatives include Burp Suite Professional, OWASP ZAP, PortSwigger’s OAuth testing methodology, or a self-hosted OAuth IdP/RP test environment.

⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on shroudcloud.com official site.

About this entry

shroudcloud.com is an Unknown Cybersecurity provider. TG4G tracks its product information, an overall rating of 7.0/10, and a China-accessibility score of Workable. Click "Visit Official Site" to reach shroudcloud.com directly.

Get Started

Price not disclosed
Visit shroudcloud.com official site β†’
External link Β· prices subject to vendor site

Frequently Asked Questions

What is shroudcloud.com?
shroudcloud.com is a Unknown-based Cybersecurity provider. Valuable for security practitioners focused on authorized red-team testing.
Is shroudcloud.com usable in China?
shroudcloud.com is basically usable in mainland China, though latency may vary by ISP and time of day; have a backup proxy ready. The provider is headquartered in Unknown and primarily serves overseas markets.
How do I sign up for shroudcloud.com?
Visit the shroudcloud.com official site to complete sign-up. Registration typically requires an email (Gmail/Outlook recommended) and a payment method. Most overseas services accept credit card / PayPal / crypto. See the "Visit Official Site" button on this page for the direct link.

Browse Other Categories

View the full directory β†’