Black-box / Grey-box penetration test
The most common type of penetration test. We probe your application's defences from the outside and attempt to subvert its controls, bypass its business rules and take control of it. Consultants use extensive experience plus off-the-shelf and custom tools to identify and exploit vulnerabilities.
White-box application test
A more comprehensive service: the same tests, coupled with a lightweight code review. We look for the most common classes of issues: cross-site scripting, SQL injection, code execution, cryptographic problems and many others.
This is the service we sell the most, and a way to get very quick wins if you are trying to improve an application's security stance. It is also the method we use to find many vulnerabilities in proprietary and commercial software. For a more thorough review aiming to find up to 100% of the issues in your code, see our Security Code Review service.
Infrastructure penetration test
Employing similar techniques to the application penetration tests, consultants probe, scan and exploit the target network, a branch, an affiliate, or the entire server estate, and deliver a report of what was found and how to fix it.
Red teaming
Our most advanced offering. Two or more consultants are given access to a target network, with user or administrator access to a desktop system as a normal user in the organisation. From there they attempt to compromise as many desktops, servers and applications as possible, with the ultimate goal to obtain domain administrator, while bypassing security protections, as a real attacker would.
This is the ultimate test of resilience: how the organisation behaves when an intruder is already inside.
Applicable to all of it
These services apply to applications, servers, embedded devices, firewalls, smartphones, set-top boxes, laptops, workstations, routers and similar systems.
