Methodology
Reproducible.
Defensible.
Uncomfortable.
One repeatable spine — six phases, PTES and NIST SP 800-115 aligned, MITRE ATT&CK-mapped. The sequence a real adversary follows, run in the open and evidenced at every step. The kind of assessment an attacker would fear and an auditor would accept.
01The instruments
Three instruments. One engagement.
Most firms pick a side — 'we're a manual shop' or 'we're an automated platform'. Both are wrong. Each instrument does what it's best at, and none of them ships a finding alone.
Automation
BreadthScans, fuzzers, and coverage at machine scale — the ground no human could cover by hand.
AI
TriageCorrelates, prioritizes, drafts, and kills false positives before an operator ever looks. Reading at machine scale.
Operator
JudgmentDecides what's real, chains it, and proves impact. The part no tool can do — and the part that matters.
AI reads at machine scale. Operators decide what's real. You get the coverage of both — and neither ships alone.
02The sequence
Six phases. Zero shortcuts.
PTES and NIST SP 800-115 aligned, mapped to MITRE ATT&CK. Every phase produces evidence; nothing advances on a hunch.
- PRE00
Pre-engagement
OSSTMM 3
Signed Rules of Engagement, scope boundaries, safe words, escalation contacts, blackout windows, evidence-handling procedure. The part amateurs skip — nothing starts until it's in place.
ROEScopeSafe wordsEvidence handling - RECON01
Reconnaissance
PTES · NIST 800-115
Passive OSINT and active surface mapping. Every subdomain, leaked credential, and forgotten dev environment your asset inventory missed becomes part of the attack surface we model.
OSINTDNSASNGH dorks - ENUM02
Enumeration
NIST 800-115 · OWASP WSTG
Service fingerprinting, tech-stack detection, and permission-boundary mapping. We build the target model your team hasn't — the one a real adversary would work from.
NmapAmassBurp SuiteNuclei - VULN03
Vulnerability Analysis
PTES · NIST 800-115
Scanning, config review, and dependency analysis — then the part that matters: AI triage kills false positives at machine scale, and operators confirm what's real. Where a vulnerability assessment ends and a penetration test loads.
NessusNucleiSCAAI triage - EXPLOIT04
Exploitation
PTES · MITRE ATT&CK
Manual chains, not scanner dumps. Real adversary emulation aligned to MITRE ATT&CK, every finding proven end to end — no proof-of-concept left as theoretical.
ATT&CKCustom TTPsChained PoCs - POST-EX05
Post-exploitation
PTES · MITRE ATT&CK
Lateral movement, privilege escalation, and blast-radius quantification. What can be reached, kept, monetized, or exfiltrated once the perimeter falls.
PersistenceLateralExfil - REPORT06
Report & retest
PTES · NIST 800-115
Executive narrative plus technical proof, prioritized by exploitability × business impact — not a CVSS-only rack-and-stack. One retest included to confirm the fix held.
RetestFix guidanceBoard deck
03Principles
Non-negotiables
Evidence, always
Every finding ships with reproduction. Screenshots, request/response pairs, PCAPs — not scanner boilerplate. If we can't prove it, we don't ship it.
All three instruments, every time
Automation for breadth, AI for triage, operators for judgment — and we name exactly which one found what. No black-box 'trust us'.
Executive + engineer
Every report tells two stories: what the board needs (impact, prioritized risk, remediation cost) and what engineering needs (reproduction, references, fix guidance).
Defensible under audit
Findings map to NIST, OWASP, MITRE, ISO, PCI, or HIPAA — whichever your regulator is asking about. Every report is written to survive third-party scrutiny.
04Toolchain
Openly named
Best-of-breed public tooling where it helps. Custom in-house tooling where it matters. AI in the loop where it earns its place. No black boxes — you'll know exactly what touched your systems.
Recon
Web / API
Network
Cloud
AI / LLM
AI-assisted
05The fact base
Nothing here is invented
Every phase, every finding, every report traces to a published standard. This is the reference set.
Offensive
AI
Risk & governance
Regulatory