Skip to content
The //Zyber// Security

Methodology

Reproducible.
Defensible.
Uncomfortable.

One repeatable spine — six phases, PTES and NIST SP 800-115 aligned, MITRE ATT&CK-mapped. The sequence a real adversary follows, run in the open and evidenced at every step. The kind of assessment an attacker would fear and an auditor would accept.

01The instruments

Three instruments. One engagement.

Most firms pick a side — 'we're a manual shop' or 'we're an automated platform'. Both are wrong. Each instrument does what it's best at, and none of them ships a finding alone.

Automation

Breadth

Scans, fuzzers, and coverage at machine scale — the ground no human could cover by hand.

AI

Triage

Correlates, prioritizes, drafts, and kills false positives before an operator ever looks. Reading at machine scale.

Operator

Judgment

Decides what's real, chains it, and proves impact. The part no tool can do — and the part that matters.

AI reads at machine scale. Operators decide what's real. You get the coverage of both — and neither ships alone.

02The sequence

Six phases. Zero shortcuts.

PTES and NIST SP 800-115 aligned, mapped to MITRE ATT&CK. Every phase produces evidence; nothing advances on a hunch.

  1. PRE00

    Pre-engagement

    OSSTMM 3

    Signed Rules of Engagement, scope boundaries, safe words, escalation contacts, blackout windows, evidence-handling procedure. The part amateurs skip — nothing starts until it's in place.

    ROEScopeSafe wordsEvidence handling
  2. RECON01

    Reconnaissance

    PTES · NIST 800-115

    Passive OSINT and active surface mapping. Every subdomain, leaked credential, and forgotten dev environment your asset inventory missed becomes part of the attack surface we model.

    OSINTDNSASNGH dorks
  3. ENUM02

    Enumeration

    NIST 800-115 · OWASP WSTG

    Service fingerprinting, tech-stack detection, and permission-boundary mapping. We build the target model your team hasn't — the one a real adversary would work from.

    NmapAmassBurp SuiteNuclei
  4. VULN03

    Vulnerability Analysis

    PTES · NIST 800-115

    Scanning, config review, and dependency analysis — then the part that matters: AI triage kills false positives at machine scale, and operators confirm what's real. Where a vulnerability assessment ends and a penetration test loads.

    NessusNucleiSCAAI triage
  5. EXPLOIT04

    Exploitation

    PTES · MITRE ATT&CK

    Manual chains, not scanner dumps. Real adversary emulation aligned to MITRE ATT&CK, every finding proven end to end — no proof-of-concept left as theoretical.

    ATT&CKCustom TTPsChained PoCs
  6. POST-EX05

    Post-exploitation

    PTES · MITRE ATT&CK

    Lateral movement, privilege escalation, and blast-radius quantification. What can be reached, kept, monetized, or exfiltrated once the perimeter falls.

    PersistenceLateralExfil
  7. REPORT06

    Report & retest

    PTES · NIST 800-115

    Executive narrative plus technical proof, prioritized by exploitability × business impact — not a CVSS-only rack-and-stack. One retest included to confirm the fix held.

    RetestFix guidanceBoard deck

03Principles

Non-negotiables

01

Evidence, always

Every finding ships with reproduction. Screenshots, request/response pairs, PCAPs — not scanner boilerplate. If we can't prove it, we don't ship it.

02

All three instruments, every time

Automation for breadth, AI for triage, operators for judgment — and we name exactly which one found what. No black-box 'trust us'.

03

Executive + engineer

Every report tells two stories: what the board needs (impact, prioritized risk, remediation cost) and what engineering needs (reproduction, references, fix guidance).

04

Defensible under audit

Findings map to NIST, OWASP, MITRE, ISO, PCI, or HIPAA — whichever your regulator is asking about. Every report is written to survive third-party scrutiny.

04Toolchain

Openly named

Best-of-breed public tooling where it helps. Custom in-house tooling where it matters. AI in the loop where it earns its place. No black boxes — you'll know exactly what touched your systems.

Recon

AmassSubfinderGitHub dorksWaybackcertificate transparency

Web / API

Burp Suite ProNucleiSemgrepcustom scripts

Network

NmapmasscanResponderCrackMapExecBloodHound

Cloud

ProwlerScoutSuitePacucloudsplaining

AI / LLM

GarakPyRITPrompt Fuzzerin-house harness

AI-assisted

triagecorrelationpayload draftingoperator-verified

05The fact base

Nothing here is invented

Every phase, every finding, every report traces to a published standard. This is the reference set.

Offensive

PTESNIST SP 800-115OWASP WSTG v4.2OWASP Top 10OWASP ASVS 4.0MITRE ATT&CKOSSTMM 3

AI

OWASP LLM Top 10 · 2025MITRE ATLASNIST AI RMF 1.0

Risk & governance

NIST CSF 2.0NIST SP 800-30NIST SP 800-53 r5ISO 27001:2022ISO 27005:2022ISO 42001:2023

Regulatory

HIPAA 45 CFR 164NIST SP 800-66 r2PCI DSS 4.0SOC 2 TSCGDPRDPDP Act 2023

See it run on a real scope.

A scoping call is where the spine meets your systems.