// penetration_testing

Authorized break-ins.
Full reports.

Every business has vulnerabilities. Better to have me find them first — with written authorization, working proof-of-concept, and a fix list you can actually action.

// what_we_test

Five attack surfaces. One methodology.

I test the things attackers actually target. No abstract checklists — I try to break in, document exactly how, and hand you the map.

01

Web Applications

OWASP Top 10 and beyond — injection, broken access control, auth flaws, SSRF, business-logic abuse. Manual testing, not just an automated scan you could have run yourself.

02

APIs

REST and GraphQL. Broken object-level authorization (BOLA), mass assignment, rate-limit gaps, and token handling. The OWASP API Top 10 exists because APIs leak differently than web apps.

03

Cloud

AWS, GCP, Azure. Misconfigured S3 buckets, over-permissioned IAM roles, exposed metadata endpoints, and public snapshots. Most cloud breaches are configuration, not zero-days.

04

Wi-Fi & Network

Rogue APs, weak WPA2 handshakes, VLAN hopping, lateral movement from a foothold. If someone can sit in your parking lot, they're already inside the perimeter you thought you had.

05

Social Engineering

Phishing simulations and pretext calls, scoped and authorized. Roughly 3 in 4 breaches involve a human element (Verizon DBIR), so I test the people too — respectfully, with a debrief.

// methodology

Recon → Scan → Exploit → Report.

Aligned to PTES and the MITRE ATT&CK framework. Every finding maps to a real technique with a CVSS v3.1 score so you can prioritize by actual risk, not vibes.

01

Reconnaissance

Passive and active. OSINT footprinting, DNS enumeration, subdomain discovery with Amass, technology fingerprinting. I learn what an attacker learns before touching a single input field.

02

Scanning & Enumeration

Nmap for the surface, Nuclei for known CVEs, Burp Suite for the web layer. Automated scanning finds the low-hanging fruit fast so I can spend my time on the hard stuff.

03

Exploitation

Manual, careful, scoped. I confirm every vulnerability with a working proof-of-concept — no theoretical "this could be exploitable." If I say it's exploitable, I have the screenshot.

04

Reporting & Retest

An executive summary your board can read plus a technical appendix your engineers can fix from. CVSS scores, reproduction steps, remediation guidance. One free retest of critical findings included.

// pricing

Scoped to your surface.

Pricing scales with scope and depth. Every engagement starts within 48 hours of a signed authorization letter.

External Quick-Scan

$497

Single external target

  • External perimeter test
  • Automated + manual triage
  • Top findings report
  • 48-hour turnaround

Web App / API Test

$1,997

Full application assessment

  • OWASP Top 10 coverage
  • Authenticated + unauth testing
  • Working PoC per finding
  • Full report + free retest

Full Internal Engagement

$4,997

Internal + lateral movement

  • Internal network + AD
  • Cloud config review
  • Social engineering (optional)
  • Executive + technical report

All engagements require a signed authorization-to-test agreement. Retainer and multi-target discounts available.

Find your holes before someone else does.

Tell me your scope. I'll tell you whether a quick-scan or a full engagement makes sense — no upsell.

Request a Scoping Call