
Penetration tests that read like
engineering documents.
PTES phases 1–7 on the operator’s side, OWASP WSTG v4.2 + ASVS L2 on the coverage grid, MITRE ATT&CK v14 on the kill-chain. Every finding lands with a CVSS 4.0 score, a CWE tag, a replayable proof-of-concept, and a mapping to the obligation you actually have to answer — SOC 2 CC7.1, ISO 27001 A.5.30, NIS2 Article 21, DORA Articles 24–26, or SEC 17 CFR §229.106 disclosure.
Three paths. One truth-telling engagement.
External Recon & Report
Self-serve, non-intrusive scan of your public attack surface. TLS posture against RFC 8446 / RFC 9325, headers against the OWASP Secure Headers Project, and a Nuclei-driven CVE sweep against Shodan-visible fingerprints.
- TLS 1.2/1.3 + cipher suite baseline (RFC 9325)
- HTTP security headers per OWASP SHP
- Nuclei · Naabu · Subfinder pipeline
- CVE lookup (NVD / GitHub advisories)
- CVSS 4.0-scored PDF summary
Codebase Audit
Upload a ZIP or connect a GitHub repo. Semgrep + custom rule packs targeting OWASP ASVS L2 controls, TruffleHog / gitleaks secret scanning across git history, and CVE scoring against the OSV database. Static analysis only — runtime authorisation is out of scope by design.
- Semgrep + custom OWASP ASVS L2 rulepacks
- Secret scanning across full git history
- Dependency CVEs from OSV + GHSA
- CWE-tagged findings, CVSS 4.0 severity
- Reproducible scored PDF report
Grey-box Engagement
Manual penetration test against a production-equivalent staging environment, run to PTES phases 1–7, OWASP WSTG v4.2, and OWASP ASVS L2. CREST-aligned reporting: executive summary, technical findings with replayable proof, and a remediation roadmap. One re-test within 90 days included.
- PTES phases 1–7 · OWASP WSTG v4.2 · ASVS L2
- Authenticated multi-role & multi-tenant BOLA / BFLA
- Business-logic + session-integrity + authorisation depth
- MITRE ATT&CK for Enterprise v14 kill-chain mapping
- CVSS 4.0 severities · CWE tagging · Burp / sqlmap PoC
- Mapping: SOC 2 CC7.1 · ISO 27001 A.5.30 · DORA · NIS2 Art. 21
STRIDE-driven threat model, ATT&CK Navigator layer for the technique set in scope, NIST SP 800-30 risk framing. Assets, crown-jewel data, and non-scope carve-outs written down before any check runs.
PTES intelligence-gathering → threat-modelling → vulnerability analysis → exploitation → post-exploitation. Automated tooling (Nuclei, Semgrep, sqlmap) feeds the tester; human judgement decides where to pivot. Findings are recorded live against a shared drive so you can watch the engagement land.
Executive summary (board-ready), technical findings with a CVSS 4.0 severity + CWE + ATT&CK technique per finding, replayable proof-of-concept (Burp Repeater state, curl command, Semgrep rule), and a prioritised remediation plan with effort estimates.
One remediation re-test within 90 days is included. On request we produce a letter of attestation aligned with SOC 2 CC7.4, ISO 27001 A.5.30 evidence requirements, or a DORA Article 26 threat-led penetration testing dossier.
Every finding carries a payload you can replay.
Each finding ships with a Burp Repeater state export, a curl reproduction, the sqlmap invocation or Nuclei template used, a CVSS 4.0 vector, a CWE identifier, and the ATT&CK technique the exploit exercises. The remediation section is written for the senior engineer who will fix it, not the reader who scored it.
See your real risk picture.
Kick off with an automatic audit, or book a custom engagement with our team.