From outside through the perimeter into the internal network, onto the servers and into your cloud. Not as a list of individual findings, but as the path an attacker would take.
The value is in the chaining: several findings, harmless on their own, together make up the path from outside to privilege escalation.
Management summary for the decision-making level, technical section for the admins
Every finding with CVSS score, how it was exploited and a description of the fix
Reproducible proofs of concept that your team can recreate for itself
Prioritisation: what gets patched right away and what belongs in the hardening strategy
We deliver the test and the technical evidence. Certification, legal advice and reports to authorities are not part of it.
After every major change to your architecture and whenever new core services are rolled out. Beyond that, a test once a year is the usual rhythm; ISO 27001, TISAX and NIS2 do not themselves prescribe a fixed interval. Your IP ranges are being probed by automated tools every single day anyway.
A list of the IP ranges and domains that are in scope, a technical contact person and, for the internal part, network access or a notebook connected to your network. Everything else we clarify together at the kickoff.
Forgotten servers, old DMZ systems, services on default ports. That is exactly where the way in begins.
Incorrect ACLs, unsecured services and routing problems open up paths that need no exploit at all.
One click or a compromised client quickly leads to critical privileges.
Many rule sets keep attackers out and let data leave unhindered. We check whether a connection to a command-and-control server can be set up from your network and whether data can leak out via DNS tunnelling or ICMP without anyone noticing.
In our tests, misconfigurations are regularly more dangerous than missing patches. A fully patched server remains attackable if it uses default passwords, offers Telnet or unsecured SNMP, or can be reached via LLMNR and NBT-NS. That is why we test against the principle of least privilege, not just against the patch level.
The classic network boundary is disappearing. Alongside the on-premise servers, we look at IAM policies, misconfigured storage buckets and insecure API interfaces. In hybrid setups the transition matters most: can someone get from a compromised server into your tenant?
The Infrastructure Pentest hardens systems. Red Teaming also tests whether your blue team notices movement in the network at all. Add Social Engineering and the test starts where real attacks start: with a click on a client that we then work from.
A pentest is not a load test. We work with targeted exploits and scans that take availability into account, agree maintenance windows beforehand and get in touch before we move on to critical systems.
Yes. The focus is on IAM policies, storage buckets, API interfaces and, in hybrid setups, the transition between on-prem and tenant.
That is part of it. We try to set up a C2 channel and exfiltrate data via DNS tunnelling or ICMP, and record what your filters see of it.
It separates the management summary from the technical section, rates every finding by CVSS, shows the exploitation as a PoC and sorts by urgency. We remain available afterwards for questions about implementation.
Both, and the interesting part is the transition. From outside we see what a stranger sees. From inside we simulate the situation after a click on a client and check which paths are open from there.
Shadow IT, old DMZ systems and unpatched hosts are the classic way in. We look for them in the first two zones, and the report lists them individually.
In a free initial call we agree scope, zones and rules of engagement. Afterwards you receive a written quote.