Penetration testing
Manually verified exploitation across web applications, REST and GraphQL APIs, internal networks and mobile. Every finding comes with reproduction steps and a severity justified in CVSS.
SERVICES
Penetration testing, continuous monitoring of your exposed surface and Active Directory audits. The same team runs all three, with no phase subcontracted, manual verified exploitation and a closed deliverable in every engagement, retest included.
SCOPE
Manually verified exploitation across web applications, REST and GraphQL APIs, internal networks and mobile. Every finding comes with reproduction steps and a severity justified in CVSS.
We monitor your external surface throughout the engagement. In-house tooling takes on the repetitive steps and CTI coverage extends to forums and the dark web. Every alert is validated by a person before it goes out.
An audit of your domain: escalation paths, Kerberos, vulnerable GPOs and obsolete trust relationships. The deliverable includes a privilege-path graph and a prioritised hardening plan.
COMPARISON
Each service addresses a different situation, and none of the three replaces the other two.
| Penetration testing | Continuous monitoring | Active Directory | |
|---|---|---|---|
| Duration | Closed window, with a start and an end | Continuous, for the contracted period | Closed window, with a start and an end |
| Typical scope | Web, API, infrastructure or mobile | All authorised infrastructure, and its providers | A full forest or domain |
| How we test | Manual exploitation with a PoC | Manual review supported by in-house tooling | Manual exploitation with a PoC |
| Deliverables | Technical report with CVSS | Exposure dashboard and alerts | Graph and hardening plan |
| Retest | Included | Included: each fix is rechecked in the next cycle | Included |
COVERAGE
These surfaces are distributed across the three services. The scope itself, assets in and out, is agreed in writing before the work starts.
Tell us which assets you want tested. We reply within 24 hours.