SECURITY

We attack first, before someone else does.

Controlled attacks on your systems, strictly under contract and with written authorisation. We look for the routes a real attacker would take, and we prove every finding.

FRAMEFOUR RULES
01 Under contract only
02 Written authorisation
03 Bounded scope
04 Full confidentiality
6 AREAS IN SCOPE
01PROCESSFROM SCOPING TO RETEST

How a test runs.

01
Scoping and authorisation
FOUNDATION

We define the targets and the limits and put the engagement in writing. We only test what the authorised owner has signed off.

02
Reconnaissance and attack
EXECUTION

External perimeter, web applications, firewall and social engineering. Where it makes sense, we use semi-automated attack chains.

03
Analysis
FINDINGS

Every weakness is proven and rated by CVSS. You receive prioritised countermeasures rather than a long list.

04
Retest
OPTIONAL

On request we check after remediation whether the gaps have actually been closed.

02SCOPESIX AREAS

What we test.

01 EXTERNAL PERIMETER

Everything reachable from the outside. Servers, services and open ports at the edge of your network.

02 INTERNAL NETWORKS

What an attacker reaches once they have a foothold. Lateral movement and privilege escalation.

03 WEB APPLICATIONS AND APIS

Login, sessions, inputs and interfaces. The flaws most often exploited in day-to-day use.

04 FIREWALL AND CLOUD

Rules, permissions and default settings in your cloud. The door here is often wider open than assumed.

05 SOCIAL ENGINEERING

People as the way into the system. Phishing and pretexts, agreed in advance and without exposing your staff.

06 ATTACK CHAINS

Several weaknesses joined into one realistic path in, not just listed in isolation.

Which of these areas belong in the test we decide together during scoping. None of it runs without your authorisation.

04SAMPLE REPORTTHE RESULT

What you receive.

At the end there is a report your team can work with straight away. Traceable, proven and sorted by urgency.

It opens with the management summary: the situation, the biggest risks and the key steps on one page. For the level that decides, not the level that fixes. Behind it, every single finding follows with four fixed fields.

PER FINDING
Description

What the weakness is and why it is a problem.

PER FINDING
Severity by CVSS

A traceable rating, so it is clear what comes first.

PER FINDING
Reproduction

The path to the finding, step by step. So your team can reproduce it themselves.

PER FINDING
Countermeasure

A concrete proposal for how to close the gap. No generic advice.

05CONTACTMUNICH

Let us talk about
your attack surface.

A reply within two working days, with a concrete scoping proposal.

START A MANDATE MANDATE REVIEW