02 · Attack · Exploit · Prove
Penetration Testing
Adversary emulation, not scanner theater.
A time-boxed offensive engagement against a defined scope — web, mobile, network, cloud, or full-chain. Manual exploitation, MITRE ATT&CK-mapped, evidence-preserving, and AI-accelerated where it buys coverage. We prove impact, not presence — and we hand your defenders everything they need to catch the next operator who tries it.
Outcomes
- +Confirmed exploitation paths, not a theoretical CVE list
- +Every TTP mapped to MITRE ATT&CK for your detection engineering
- +An executive narrative your board will actually read
- +Optional purple-team debrief with your defenders
01Scope
What we cover
In scope
- +Black-box, grey-box, or white-box models — your choice
- +Web + API + mobile + thick-client + cloud + on-prem network
- +Authenticated and unauthenticated test paths
- +Chained exploitation across boundaries when scoped
- +Optional coordinated notification with your SOC / MSSP
Out of scope
- −Denial-of-service testing (excluded by default; opt-in only)
- −Exfiltration of real customer PII (we use synthetic proxies)
- −Destructive actions on production data
02Approach
How the engagement runs
Pre-engagement
Signed Rules of Engagement, safe words, escalation contacts, blackout windows, evidence-handling procedure. Nothing starts until this is in place.
Reconnaissance
Passive OSINT + active discovery, AI-correlated. Every engagement starts here — and we spend real time on it.
Enumeration
Service, tech-stack, and trust-boundary mapping. The target model your team never drew.
Vulnerability Analysis
Candidate weaknesses identified and confirmed; AI triage clears the noise so operator hours go to what's actually exploitable.
Exploitation
Manual, iterative, chained. Custom TTPs where CVEs don't fit — the chains a scanner will never find.
Post-exploitation
Lateral movement, privilege escalation, blast-radius quantification. What could a real adversary do with what we took?
Report & retest
Two-audience report; optional live purple-team walkthrough so your defenders learn to detect every step. Retest within 90 days.
03Deliverables
What you receive
Every artifact is defensible under external audit and actionable for engineering.
- 01Penetration Test Report (executive + technical + appendices)
- 02MITRE ATT&CK matrix mapping of every TTP used
- 03Attack-narrative video walkthrough (optional)
- 04Purple-team session with detection-engineering guidance
- 05Retest of critical/high findings within 90 days
04Frameworks
Regulator-defensible mapping
05Timeline
Typical engagement pace
Scoping + ROE
1–2 weeks
Testing window
3–6 weeks
Reporting
1–2 weeks
Purple-team + retest
1 week
06FAQ
Common questions
Different question? Raise it on a scoping call — we'd rather flag surprises early.
How is this different from a vulnerability assessment?+
A VA identifies weaknesses. A pen test proves they matter — by chaining them, escalating privileges, and demonstrating real business impact. A VA answers what's wrong; a pen test answers what could actually happen.
Do you use automated tools and AI?+
For coverage and triage, yes — Burp, Nmap, custom fuzzers, and AI to correlate and prioritize. For exploitation and chaining, an operator drives every shot. Automation finds the door; a human decides whether to walk through it.
Can we run purple-team exercises alongside?+
Yes. We can share our TTPs in real time with your SOC over a shared channel, or debrief at the end. Included in most engagements.
Book a scoping call.
Fixed scope, fixed price, delivered within 6–10 weeks of kickoff. Detailed engagement letter within 5 business days of our first call.
Book a scoping call