Skip to content

Services/Penetration Testing

Penetration Testing

Manual and automated adversary simulation — applications, networks, hardware and everything in between.

Enquire about this service
Two Kali Linux terminal windows — htop and a Slowloris test — on the desktop

Black-box penetration test

Our most basic service, and the one most commonly offered by security consultancies. We probe your application's defences from the outside and attempt to subvert its controls, bypass its business rules and take control of it. Consultants use extensive experience plus off-the-shelf and custom tools to identify and exploit vulnerabilities.

White-box application test

A more comprehensive service: the same tests, coupled with a lightweight code review. We look for the most common classes of issue — cross-site scripting, SQL injection, code execution, cryptographic problems and many others.

This is the service we sell the most, and a way to get very quick wins if you are trying to improve an application's security stance. It is also the method we use to find many vulnerabilities in proprietary and commercial software. For a more thorough review aiming to find up to 100% of the issues in your code, see Security Code Review.

Infrastructure penetration test

Employing similar techniques, consultants probe, scan and exploit the target network — a branch, an affiliate, or the entire estate — and deliver a report of what was found and how to fix it.

Red teaming

Our most advanced offering. Two or more consultants are dropped into a target network with user or administrator access to a desktop system. From there they attempt to compromise as many desktops, servers and applications as possible, and to obtain domain administrator, while bypassing existing protections as a real attacker would.

This is the ultimate test of resilience: how the organisation behaves when an intruder is already inside.

Fuzzing

We also provide specialised fuzzing, used mostly in product-security assessments to understand how native code behaves against a malformed file or network packet.

Applicable to all of it

These services apply to applications, servers, embedded devices, firewalls, smartphones, set-top boxes, laptops, workstations, routers and similar systems.

Contact us today to find out how we can help you.

Short engagements, senior consultants, and work we actually sign our names to.