// penetration_testing
Every business has vulnerabilities. Better to have me find them first — with written authorization, working proof-of-concept, and a fix list you can actually action.
// what_we_test
I test the things attackers actually target. No abstract checklists — I try to break in, document exactly how, and hand you the map.
01
OWASP Top 10 and beyond — injection, broken access control, auth flaws, SSRF, business-logic abuse. Manual testing, not just an automated scan you could have run yourself.
02
REST and GraphQL. Broken object-level authorization (BOLA), mass assignment, rate-limit gaps, and token handling. The OWASP API Top 10 exists because APIs leak differently than web apps.
03
AWS, GCP, Azure. Misconfigured S3 buckets, over-permissioned IAM roles, exposed metadata endpoints, and public snapshots. Most cloud breaches are configuration, not zero-days.
04
Rogue APs, weak WPA2 handshakes, VLAN hopping, lateral movement from a foothold. If someone can sit in your parking lot, they're already inside the perimeter you thought you had.
05
Phishing simulations and pretext calls, scoped and authorized. Roughly 3 in 4 breaches involve a human element (Verizon DBIR), so I test the people too — respectfully, with a debrief.
// methodology
Aligned to PTES and the MITRE ATT&CK framework. Every finding maps to a real technique with a CVSS v3.1 score so you can prioritize by actual risk, not vibes.
Passive and active. OSINT footprinting, DNS enumeration, subdomain discovery with Amass, technology fingerprinting. I learn what an attacker learns before touching a single input field.
Nmap for the surface, Nuclei for known CVEs, Burp Suite for the web layer. Automated scanning finds the low-hanging fruit fast so I can spend my time on the hard stuff.
Manual, careful, scoped. I confirm every vulnerability with a working proof-of-concept — no theoretical "this could be exploitable." If I say it's exploitable, I have the screenshot.
An executive summary your board can read plus a technical appendix your engineers can fix from. CVSS scores, reproduction steps, remediation guidance. One free retest of critical findings included.
// pricing
Pricing scales with scope and depth. Every engagement starts within 48 hours of a signed authorization letter.
External Quick-Scan
$497
Single external target
Web App / API Test
$1,997
Full application assessment
Full Internal Engagement
$4,997
Internal + lateral movement
All engagements require a signed authorization-to-test agreement. Retainer and multi-target discounts available.