Skip to content

SERVICES

Three offensive security services, each engaged on its own

Penetration testing, continuous monitoring of your exposed surface and Active Directory audits. The same team runs all three, with no phase subcontracted, manual verified exploitation and a closed deliverable in every engagement, retest included.

SCOPE

What each service covers and what is delivered

SERVICE 01

Penetration testing

  • Web
  • API
  • Infra
  • Mobile

Manually verified exploitation across web applications, REST and GraphQL APIs, internal networks and mobile. Every finding comes with reproduction steps and a severity justified in CVSS.

SERVICE 02

Continuous monitoring

  • Attack surface
  • CVE
  • Leaked credentials
  • Crimeware forums
  • Phishing
  • Telegram
  • Providers
  • 24/7

We monitor your external surface throughout the engagement. In-house tooling takes on the repetitive steps and CTI coverage extends to forums and the dark web. Every alert is validated by a person before it goes out.

SERVICE 03

Active Directory audit

  • Kerberos
  • GPO
  • PrivEsc
  • Trusts
  • Lateral movement
  • EDR evasion

An audit of your domain: escalation paths, Kerberos, vulnerable GPOs and obsolete trust relationships. The deliverable includes a privilege-path graph and a prioritised hardening plan.

COMPARISON

The three services compared

Each service addresses a different situation, and none of the three replaces the other two.

Penetration testingContinuous monitoringActive Directory
DurationClosed window, with a start and an endContinuous, for the contracted periodClosed window, with a start and an end
Typical scopeWeb, API, infrastructure or mobileAll authorised infrastructure, and its providersA full forest or domain
How we testManual exploitation with a PoCManual review supported by in-house toolingManual exploitation with a PoC
DeliverablesTechnical report with CVSSExposure dashboard and alertsGraph and hardening plan
RetestIncludedIncluded: each fix is rechecked in the next cycleIncluded

COVERAGE

Surfaces we test

These surfaces are distributed across the three services. The scope itself, assets in and out, is agreed in writing before the work starts.

01
Web applicationsPortals, dashboards and session-based SPAs.
02
APIsREST and GraphQL, authenticated and unauthenticated.
03
Internal networkSegmentation, exposed services and lateral movement.
04
Active DirectoryKerberos, GPOs, delegations and trusts.
05
CloudAWS, Azure and GCP. IAM and storage.
06
MobileiOS and Android, client and backend.
07
External surfaceForgotten assets, subdomains and open panels.
08
LeaksCredentials and source code on forums and the dark web.
09
CTIThreat intelligence for your sector.
10
Human factorTargeted phishing, by prior agreement.

Request a proposal with the scope defined

Tell us which assets you want tested. We reply within 24 hours.

Request an auditCall