The route in,
evidenced.
A scanner lists vulnerabilities. A penetration test chains them into a route to the objective and proves what lies open at the end: domain admin, customer data, production control. We test externally, internally, against web applications and in the cloud — by hand, documented, with a retest after you remediate.
What is included.
Not just finding issues — showing what an attacker can do with them.
External test
Internet-facing systems, VPN, mail and web portals; reconnaissance as an attacker with no inside knowledge.
Internal test
From the position of a compromised client or employee: Active Directory, network segmentation, servers.
Application and cloud
Web applications against OWASP; AWS, Azure and Microsoft 365 configuration from an attacker’s view.
Report and retest
Every finding with evidence, exploitability, business impact and remediation; a retest once you have fixed them.
Five steps,
one deliverable.
Scoping
Objectives, rules of engagement, time windows, emergency contacts; written authorisation.
Reconnaissance
Map the attack surface.
Exploitation
Chain weaknesses, reach the objectives, evidence every step.
Report
Technical and for management; closing debrief.
Retest
Verify remediated findings and issue the confirmation.