Network, cloud, and identity penetration testing.
We test the routes that turn exposed infrastructure or a compromised user into material access. Findings show the chain, the evidence, and the controls that held or failed.
// What we test
- External networkPublic IP ranges, domains, perimeter devices, VPNs, SSO, exposed cloud services, email and DNS, with authorised exploitation of material weaknesses.
- Internal & identityActive Directory, Entra ID, ADFS, PKI, federation, admin tooling, segmentation, lateral movement, credential exposure, and paths to privileged systems.
- Cloud perimeterAWS, Azure, and GCP identities, federation, IAM and RBAC escalation, exposed services, CI/CD and infrastructure-as-code, SaaS connectors, logging, and detection.
- WirelessCorporate and guest Wi-Fi, WPA2/3, 802.1X, RADIUS, NAC, rogue and evil-twin resilience, client behaviour, and authorised pivot paths.
- Physical & exposureSites, visitor and badge controls, comms rooms, public infrastructure and repository exposure, supplier footprint, and impersonation risk under explicit authorisation.
// Method and evidence
Attack paths, not scanner output.
- EvidenceMaterial findings are reproduced and connected to affected assets, privilege gained, business impact, and a practical remediation path.
- DetectionWe record what logged, what alerted, and what was missed, with specific telemetry, rule, and playbook changes where detection is in scope.
- AI-assisted triageLocal or private tooling can sort reconnaissance, privilege graphs, and service volume. Humans authorise exploitation, determine severity, and write the report.
- GovernanceSigned Rules of Engagement, test windows, named escalation paths, and stop conditions. Destructive activity requires explicit approval and agreed risk controls.
- OutputsAn executive narrative, engineer-ready detail, a prioritised exposure register, and a working read-out with the operator who performed the testing.
// Delivery
01Discover & scopeObjectives, assets, safe-testing boundaries, escalation paths, and Rules of Engagement.
02Threat-led planLikely attacker paths and high-risk services determine where effort goes.
03Test & validateManual exploitation with every reportable finding reproduced.
04Report & read-outExecutive narrative, engineer detail, and a working session with both audiences.
05Retest & closeUsually within 60–90 days. Confirm fixes and capture residual risk.
Relevant standards
PTES/
MITRE ATT&CK/
ASD ISM/
Essential Eight/
NIST CSF/
ISO 27001
// Next step
Send the environment and concern.
Include the external or internal scope, identity and cloud platforms, what has already been tested, and any operational constraints.