Home  /  Services

Services

Four service lines, scoped independently or combined into a single engagement.

Network

Network Penetration Testing

External and internal testing that shows what an attacker can genuinely reach, take, and hold. Not what a scanner guesses might be possible.

External testing starts from the internet with nothing but your in-scope ranges and domains. We map what you're actually exposing. The forgotten subdomain, the staging box that somehow got a public IP, the VPN appliance two versions behind. Then we try to use it.

Internal testing assumes the breach already happened. We start from a network drop, a compromised workstation, or a low-privilege account and work toward whatever you actually care about. Domain admin, the database, the payment path.

Scope This Engagement

What is covered

  • External perimeter enumeration and exploitation
  • Internal network testing and lateral movement
  • Active Directory attack path analysis (Kerberoasting, delegation abuse, ACL paths)
  • Network segmentation and firewall rule validation
  • Credential harvesting and password policy auditing
  • Legacy protocol abuse (LLMNR/NBT-NS, SMB signing, NTLM relay)

Good fit: Best for organizations with an on-premise or hybrid footprint, an annual testing requirement, or a recent merger that changed the network shape.

Applications

Web Application & API Assessment

Manual, authenticated testing against your application logic. It's the class of flaw no automated tool has ever reliably found.

Scanners are good at spotting a missing header. They're terrible at spotting the endpoint that lets user A read user B's records by changing a number. We test with real accounts at every privilege level, and most of our time goes on the second kind of problem.

API testing runs the same way. We work from your spec where there is one and from traffic capture where there isn't, then probe authorization on every method of every endpoint instead of trusting the gateway to handle it.

Scope This Engagement

What is covered

  • OWASP Top 10 and OWASP API Security Top 10 coverage
  • Broken object-level and function-level authorization (IDOR / BOLA / BFLA)
  • Injection, SSRF, deserialization and file-handling flaws
  • Authentication, session management, SSO and token handling
  • Business logic abuse and workflow bypass
  • REST, GraphQL, SOAP and websocket endpoints
  • Multi-tenant isolation testing for SaaS platforms

Good fit: Best for SaaS products, customer portals, anything handling regulated data, and any application about to face a customer security review.

Cloud & Wireless

Cloud, Wireless & Social Engineering

The attack surface that doesn't live in a rack. Misconfigured cloud identity, open airwaves, and the people who'll click the link.

Cloud breaches are rarely exploits. It's a public bucket, an over-permissive role, a key committed to a repo, a metadata service reachable from an app that should never have been able to reach it. We review your AWS, Azure or GCP environment for those paths, then chain them to show the real blast radius.

Wireless testing covers the ways in that bypass your perimeter entirely. If you want it, we'll also run a phishing campaign against your people. It's measured carefully and reported without naming names. The point is better training, not embarrassing anyone.

Scope This Engagement

What is covered

  • AWS, Azure and GCP configuration and IAM review
  • Privilege-escalation and cross-account path analysis
  • Container, Kubernetes and CI/CD pipeline review
  • Secrets exposure in code, images and build artifacts
  • Wireless assessment, rogue AP and guest network isolation
  • Phishing and vishing campaigns

Good fit: Best for cloud-native teams, organizations mid-migration, and anyone who has never had an outsider look at their IAM policies.

Compliance

Compliance-Driven Penetration Testing

Testing scoped to satisfy your framework and evidenced so your auditor accepts it the first time, while still being a real test.

A compliance-driven test has two audiences. Your auditor needs to see the right scope covered by a qualified independent party, with evidence and dates. Your engineers need findings worth fixing. Most firms optimize for one and shortchange the other.

We scope against the control language itself, so the deliverable maps finding by finding to the requirement it evidences. You get the attestation letter, the evidence package, and a report that would've been worth buying even if nobody were auditing you.

Scope This Engagement

What is covered

  • HITRUST CSF, scoped to the assessment boundary
  • SOC 2 Type II, supporting CC4 and CC7 control evidence
  • PCI DSS Requirement 11.4: internal, external and segmentation
  • HIPAA Security Rule, technical safeguard evaluation
  • ISO 27001 Annex A technical testing evidence
  • Customer security questionnaires and vendor reviews
  • Attestation letter suitable for external distribution

Good fit: Best for healthcare, fintech, and any organization whose sales cycle keeps stalling on a security review.

Advisory

Security Consulting & Advisory

Most testing firms hand you a list of problems and leave. This is the other half: help designing, building and running the program that stops those findings coming back.

Most of fifteen years in this field went to the defensive side. Building security programs from nothing, securing cloud environments, standing up vulnerability management, getting organizations through HITRUST and SOC 2. That's a different job from breaking in, and it's the one that decides whether next year's test comes back cleaner.

Engagements get scoped to what you actually need. A one-off architecture review, a remediation plan after somebody else's penetration test, or ongoing fractional security leadership for a team that isn't ready to hire a full-time CISO. We're just as willing to tell you that you need less help than you thought.

Scope This Engagement

What is covered

  • Security program design and build-out from scratch
  • Cloud security architecture and IAM review (AWS, Azure, GCP)
  • Vulnerability management program design and tooling
  • Compliance readiness: HITRUST, SOC 2, HIPAA, PCI DSS
  • Security awareness program design
  • Fractional and interim security leadership
  • Remediation planning and hands-on engineering support

Good fit: Best for organizations with a security problem but no security team, and for teams that need senior help without committing to a full-time hire.

Not sure which one you need?

That's a normal place to start. Describe the environment and what's worrying you, and we'll tell you what's worth testing. Sometimes the honest answer is less than you were about to buy.