Home / Penetration testing

Penetration testing

Scoped, point-in-time engagements against a defined target. Most clients start here, and many then move the external estate onto continuous coverage once the report is delivered.

How an engagement runs

We scope the target with you, agree the rules of engagement in writing, and verify you are entitled to authorise the testing. A consultant then works the target for the agreed duration, typically a week for a single application, and you receive a written report with findings rated using CVSS v3.1 and business context applied.

Critical and high findings are raised as they are confirmed rather than held back for the report. A retest of the findings is included once your team has applied fixes.

What the report will tell you it could not finish

Read the limitations section of any penetration test report, including ours, and you will find a line about limited time or partial coverage. It is honest rather than evasive. Password spraying has to run slowly to avoid locking accounts out. Content discovery across a large estate takes days per host. Nobody can test the change your team ships the week after testing ended. Those tasks get sampled or dropped, because the week runs out before the work does.

That is the gap continuous testing exists to close, and it is the usual reason clients move their external estate onto it after a first engagement.

Applications and APIs

Web application

Authenticated and unauthenticated assessment of a web application, aligned to OWASP ASVS, covering every layer from client-side logic to server configuration and business logic.

  • Injection flaws, including SQLi, XSS, XXE, SSTI and CRLF
  • Authentication, session management and single sign-on
  • Access control, IDOR and privilege escalation between roles
  • SSRF and out-of-band exploitation
  • Business logic and workflow abuse
  • Third-party component and supply chain risk

Mobile application

Static and dynamic analysis of iOS and Android applications against OWASP MASVS, covering the binary, runtime behaviour, local storage and the backend it talks to.

  • Static binary analysis
  • Dynamic runtime analysis and instrumentation
  • Insecure local data storage, including Keychain and SharedPreferences
  • Certificate pinning bypass and traffic interception
  • Deep link, intent and IPC exploitation on Android
  • Backend API review against the OWASP API Top 10

API, GraphQL and gRPC

API security testing across REST, GraphQL, gRPC and WebSocket interfaces, covering both authenticated and unauthenticated attack paths.

  • Broken object-level and function-level authorisation
  • GraphQL introspection abuse and batching attacks
  • gRPC service enumeration and proto injection
  • Mass assignment and excessive data exposure
  • Authentication bypass and token manipulation
  • Rate limiting and resource consumption

Infrastructure and cloud

External network

Assessment of your internet-facing estate: what is exposed, what is reachable, and what an attacker without credentials can do with it.

  • Discovery and enumeration of the external footprint
  • Reachable services, versions and known-vulnerable software
  • Remote access endpoints, including VPN and management interfaces
  • Transport security, mail and DNS configuration
  • Exposed web content, staging environments and admin panels

Cloud configuration

Review of AWS, Azure and Google Cloud environments, focused on the configuration and permission paths that turn a small mistake into account compromise.

  • Storage exposure across buckets and containers
  • IAM permissions and privilege escalation paths
  • Network exposure created by cloud configuration
  • Secrets in metadata, environment configuration and build settings
  • Logging and audit configuration

Containers and Kubernetes

Assessment of containerised environments, from image hardening through to live cluster exploitation, across Docker, Kubernetes, OpenShift, EKS, AKS and GKE.

  • Container image hardening assessment
  • Kubernetes RBAC review, including ServiceAccount abuse
  • Privileged container and host path mount exploitation
  • Namespace isolation and network policy gaps
  • Secrets management across etcd, mounted secrets and environment variables
  • Alignment to CIS Kubernetes Benchmarks

Serverless and FaaS

Testing of serverless architectures on AWS Lambda, Azure Functions and Google Cloud Functions.

  • Event source injection through SQS, SNS and S3 triggers
  • Excessive IAM role permissions and privilege escalation
  • Function-to-function trust exploitation
  • Dependency vulnerability analysis and SBOM review
  • Cold-start environment variable and secrets exposure
  • Denial-of-wallet attack surface

Identity, AI systems and people

Identity and access

Assessment of identity infrastructure, single sign-on, privileged access management and conditional access policy.

  • OAuth and OIDC flow abuse, including token leakage
  • SAML assertion forgery and XML signature wrapping
  • MFA bypass techniques, and where coverage is missing
  • Privileged access management review
  • RBAC and ABAC misconfiguration and privilege escalation
  • Conditional access policy validation and segmentation gaps

LLM and AI systems

Red-teaming of applications built on large language models and agentic pipelines, aligned to the OWASP LLM Top 10.

  • Direct and indirect prompt injection
  • Jailbreaking and system prompt extraction
  • RAG pipeline poisoning and retrieval manipulation
  • Tool-use and function-call exploitation in agentic systems
  • Data exfiltration through model output channels
  • Multi-agent trust boundary and orchestration flaws

Phishing simulation

A scoped phishing campaign measuring whether your controls and training hold, reported in aggregate only.

  • Campaign design and lure review against agreed boundaries
  • Measurement of what your technical controls caught first
  • Aggregate click, submit and report rates
  • Whether your reporting path works, and how quickly staff use it
  • No individual is named to management, and results are never used for discipline
  • Approval must come from HR or an executive rather than IT

What we do not test

  • Operational technology and industrial control systems.
  • Physical devices and the firmware that runs on them.
  • Radio and telecommunications infrastructure.
  • Physical security and on-site social engineering.

If you need one of these, we would rather point you to someone who does it properly than take the work.

Scoping and pricing

Engagements are quoted on scope: what the target is, how much of it there is, and whether testing is authenticated. A single web application assessed over a week is the common starting point. We confirm the price in a written proposal before anything begins.

Ask about continuous testing at the same time. The base package covers a year of external coverage for roughly what an annual test costs, and it is where the long-running work above actually gets finished. Most clients scope both in one conversation: a deep engagement on the application that matters, and continuous coverage on the estate that keeps moving.