Skip to content

Services/Penetration Testing

Penetration Testing

Manual and automated adversary simulation: applications, networks, hardware and everything in between.

Enquire about this service
Two Kali Linux terminal windows, htop and a Slowloris test, on the desktop

Black-box / Grey-box penetration test

The most common type of penetration test. We probe your application's defences from the outside and attempt to subvert its controls, bypass its business rules and take control of it. Consultants use extensive experience plus off-the-shelf and custom tools to identify and exploit vulnerabilities.

White-box application test

A more comprehensive service: the same tests, coupled with a lightweight code review. We look for the most common classes of issues: cross-site scripting, SQL injection, code execution, cryptographic problems and many others.

This is the service we sell the most, and a way to get very quick wins if you are trying to improve an application's security stance. It is also the method we use to find many vulnerabilities in proprietary and commercial software. For a more thorough review aiming to find up to 100% of the issues in your code, see our Security Code Review service.

Infrastructure penetration test

Employing similar techniques to the application penetration tests, consultants probe, scan and exploit the target network, a branch, an affiliate, or the entire server estate, and deliver a report of what was found and how to fix it.

Red teaming

Our most advanced offering. Two or more consultants are given access to a target network, with user or administrator access to a desktop system as a normal user in the organisation. From there they attempt to compromise as many desktops, servers and applications as possible, with the ultimate goal to obtain domain administrator, while bypassing security protections, as a real attacker would.

This is the ultimate test of resilience: how the organisation behaves when an intruder is already inside.

Applicable to all of it

These services apply to applications, servers, embedded devices, firewalls, smartphones, set-top boxes, laptops, workstations, routers and similar systems.

Contact us today to find out how we can help you.

Short or long engagements conducted by senior consultants and experts in technical cyber security.