Network · Cloud · Identity

Initial access, lateral movement, and blast radius—tested as connected paths.

Network, cloud, and identity penetration testing.

We test the routes that turn exposed infrastructure or a compromised user into material access. Findings show the chain, the evidence, and the controls that held or failed.

  • External networkPublic IP ranges, domains, perimeter devices, VPNs, SSO, exposed cloud services, email and DNS, with authorised exploitation of material weaknesses.
  • Internal & identityActive Directory, Entra ID, ADFS, PKI, federation, admin tooling, segmentation, lateral movement, credential exposure, and paths to privileged systems.
  • Cloud perimeterAWS, Azure, and GCP identities, federation, IAM and RBAC escalation, exposed services, CI/CD and infrastructure-as-code, SaaS connectors, logging, and detection.
  • WirelessCorporate and guest Wi-Fi, WPA2/3, 802.1X, RADIUS, NAC, rogue and evil-twin resilience, client behaviour, and authorised pivot paths.
  • Physical & exposureSites, visitor and badge controls, comms rooms, public infrastructure and repository exposure, supplier footprint, and impersonation risk under explicit authorisation.
Human-led judgement

Automation can widen coverage. Operators make every risk and exploitation decision.

Attack paths, not scanner output.

  • EvidenceMaterial findings are reproduced and connected to affected assets, privilege gained, business impact, and a practical remediation path.
  • DetectionWe record what logged, what alerted, and what was missed, with specific telemetry, rule, and playbook changes where detection is in scope.
  • AI-assisted triageLocal or private tooling can sort reconnaissance, privilege graphs, and service volume. Humans authorise exploitation, determine severity, and write the report.
  • GovernanceSigned Rules of Engagement, test windows, named escalation paths, and stop conditions. Destructive activity requires explicit approval and agreed risk controls.
  • OutputsAn executive narrative, engineer-ready detail, a prioritised exposure register, and a working read-out with the operator who performed the testing.
01Discover & scopeObjectives, assets, safe-testing boundaries, escalation paths, and Rules of Engagement.
02Threat-led planLikely attacker paths and high-risk services determine where effort goes.
03Test & validateManual exploitation with every reportable finding reproduced.
04Report & read-outExecutive narrative, engineer detail, and a working session with both audiences.
05Retest & closeUsually within 60–90 days. Confirm fixes and capture residual risk.
Relevant standards PTES/ MITRE ATT&CK/ ASD ISM/ Essential Eight/ NIST CSF/ ISO 27001
Scope first

Most engagements run for two to four weeks.

Send the environment and concern.

Include the external or internal scope, identity and cloud platforms, what has already been tested, and any operational constraints.