Englishالعربية Soon
Under attack?
Penetration testing · Offensive security

A scanner tells you what is open. A tester tells you what that costs you.

Authorised, scoped testing that chains real weaknesses together the way an attacker would, and reports what an intruder could actually reach, take or disrupt in your environment. Remediation support and a retest are part of the engagement.

Scope
Agreed in writing
Method
Tooling plus manual
Evidence
Reproduction steps
Ranking
By business impact
Retest
Included
Debrief
With your engineers
Test types

Nine test types, and who each one simulates

Most clients combine two or three rather than buying all of them. Durations assume a mid-sized environment and are confirmed at scoping.

Test
Simulates
Typical duration
Primary deliverable
External network
An unauthenticated attacker on the internet
1 to 2 weeks
Exploitable perimeter findings with proof and a retest
Internal network
An attacker with a foothold inside
2 to 3 weeks
Attack paths to domain and critical systems
Web application
An anonymous and an authenticated user
1 to 3 weeks
Injection, access control and business logic findings
API
A partner or a malicious client
1 to 2 weeks
Authorisation, validation and data exposure findings
Mobile application
A user with a rooted device
1 to 2 weeks
Storage, transport and platform-specific findings
Cloud configuration
A compromised identity in your tenant
1 to 2 weeks
Identity, exposure and misconfiguration findings
Wireless
Somebody in the car park
3 to 5 days
Authentication and segmentation findings
Social engineering
A phishing or pretext operator
1 to 2 weeks
Behavioural results, reported without naming individuals
Payment and devices
A criminal group targeting cash or cards
2 to 3 weeks
Device, transaction and standard-aligned findings
Method

Six phases, agreed before anyone touches a system

The methodology is not the interesting part. Doing it in a defined order, with authorisation in writing and an escalation contact who answers the phone, is what makes the result usable rather than alarming.

01
Scope
Targets, objectives, constraints, timing, escalation contacts and written authorisation agreed and signed.
02
Reconnaissance
Information gathered passively and actively to map the real attack surface, not the documented one.
03
Analysis
Weaknesses identified with tooling and by hand, then assessed for whether they are genuinely exploitable here.
04
Exploitation
Weaknesses exercised in a controlled way to establish real impact, within the agreed rules of engagement.
05
Report
Findings ranked by business impact, with reproduction steps, evidence and specific remediation guidance.
06
Retest
Fixes verified after remediation, and the report reissued so it reflects your current state.
Deliverable

What the report contains

An executive summary that a non-technical reader can act on, then per-finding detail: how it was reached, what it exposed, how to reproduce it, evidence, and the specific change that fixes it. Ranked by business impact rather than by scanner severity.

See a sample →

Deliverable

What it does not contain

Raw scanner output presented as findings. Severity ratings copied from a database without reference to your environment. A hundred low-risk observations padding out a thin engagement.

Talk to an engineer →

Related

Where testing usually leads

Vulnerability management

An annual test is a snapshot. Exposure needs a running process between them.

Red teaming

Once the perimeter holds, test whether your team would notice somebody patient.

Secure code review

For applications you build yourselves, the cheapest place to find a flaw is in the code.

Scope a test properly, once.

A scoping call defines targets, constraints and authorisation. We will tell you if a cheaper test would answer your question.