home / methodology

How We Actually
Test

No raw scanner exports. Every engagement follows a structured, standards-aligned methodology — manual exploitation, evidence-backed findings, and a free retest to confirm every fix.

engagement.log
standards.ref
# engagement_id: GS-2026-0411 [✓] 01_scope rules of engagement signed [✓] 02_recon attack surface mapped [✓] 03_analyze 14 candidate findings [~] 04_exploit manual verification in progress [ ] 05_impact pending [ ] 06_report pending [ ] 07_retest pending # aligned_to: PTES, OWASP WSTG, NIST SP 800-115, MITRE ATT&CK
PTES — Penetration Testing Execution Standard OWASP Testing Guide & API Top 10 NIST SP 800-115 OSSTMM MITRE ATT&CK CREST-aligned reporting
the process

Six Phases, Every Engagement

The same disciplined process runs underneath every service we offer — network, web application, wireless, or cloud.

// PHASE 01 — SCOPING

Scoping & Rules of Engagement

We define in-scope and out-of-scope assets, testing windows, escalation contacts, and what's explicitly off-limits — a signed rules-of-engagement document before a single packet is sent.

Scope DefinitionLegal Authorization
// PHASE 02 — RECONNAISSANCE

Reconnaissance & Enumeration

Passive OSINT and active scanning to build a full map of the attack surface — hosts, services, technologies, exposed credentials, and every entry point available to an attacker.

OSINTEnumeration
// PHASE 03 — ANALYSIS

Vulnerability Analysis

Correlate enumerated data against known CVEs, misconfigurations, and weak protocols. Candidate findings are prioritised by real exploitability and business impact, not CVSS score alone.

CVE CorrelationRisk Prioritisation
// PHASE 04 — EXPLOITATION

Manual Exploitation

Every candidate finding is manually exploited under controlled conditions to prove real-world impact — not just flagged and left theoretical. This is what separates a pentest from a scan.

Proof of ConceptControlled Testing
// PHASE 05 — IMPACT

Post-Exploitation & Impact Analysis

Determine how far a successful compromise reaches — privilege escalation, lateral movement, and data exposure — mapped to business risk your leadership team can act on.

Privilege EscalationBusiness Impact
// PHASE 06 — REPORTING & RETEST

Reporting & Free Retest

A prioritised report with evidence, remediation guidance, and executive summary — followed by a free retest once fixes are deployed, with a signed confirmation letter on closure.

Evidence-Based ReportRetest Included
quality & rigor

Why the Process Holds Up

Consistency matters as much as skill — every engagement goes through the same quality gates before it reaches your desk.

peer_review.log

Peer-Reviewed Findings

Every finding is independently reviewed by a second senior tester before it's included in the report — cutting false positives and confirming exploitation evidence is reproducible.

manual_first.policy

Manual-First Testing

Automated tools establish a baseline only. Every reported vulnerability is manually verified and exploited by a certified tester — never delivered as an unfiltered scanner dump.

evidence.chain

Evidence-Backed Reporting

Every finding ships with request/response data, screenshots, or command output — so your team can reproduce and verify each issue without taking our word for it.

certifications.list

Certified Testers

Engagements are led by testers holding industry certifications such as OSCP, OSCE, CRTO, and CREST — with continuous internal training as attacker techniques evolve.

comms_channel.open

Open Communication

A direct Slack or email channel stays open with your team for the full engagement — critical findings are flagged immediately, not held until the final report.

compliance_mapping.csv

Compliance-Ready Output

Findings are mapped to PCI DSS, ISO 27001, SOC 2, and HIPAA controls on request — ready to hand directly to auditors and enterprise security questionnaires.

frequently asked

Common Questions

Straight answers about the standards, rigor, and structure behind every engagement.

What penetration testing methodology do you follow?
Our engagements follow a structured six-phase process aligned to the Penetration Testing Execution Standard (PTES), the OWASP Web Security Testing Guide, NIST SP 800-115, and MITRE ATT&CK for threat-informed testing — covering scoping, reconnaissance, vulnerability analysis, exploitation, post-exploitation, and reporting with retest.
Is your testing manual or automated?
Automated scanning is used only to establish a fast baseline. Every finding is manually verified and exploited by a certified tester to confirm real-world impact and eliminate false positives — no report is ever a raw scanner export.
What standards and frameworks does your methodology align with?
Our methodology aligns with PTES, OWASP Testing Guide and OWASP API Security Top 10, NIST SP 800-115, OSSTMM, and MITRE ATT&CK, and maps findings to compliance frameworks including PCI DSS, ISO 27001, SOC 2, and HIPAA on request.
Do you retest findings after remediation?
Yes. Every engagement includes a free retest window after remediation. We re-verify each finding and issue a signed confirmation letter, commonly used as evidence for compliance audits and cyber insurance renewals.
How do you avoid disrupting production systems during testing?
Rules of engagement are agreed before testing starts, denial-of-service techniques are excluded by default, high-risk exploitation steps require pre-approval, and a direct communication channel with your team stays open for the duration of the engagement.
// standards-aligned, evidence-backed

Test It the Right Way

Whichever service you need — network, web application, wireless, or cloud — the same rigorous methodology runs underneath it. Let's scope your engagement.