Qualify
Understand the application, assessment driver, environment, and whether the requested work belongs within our specialization.
Methodology
The exact technical methodology varies by target. The control process does not.
Understand the application, assessment driver, environment, and whether the requested work belongs within our specialization.
Identify targets, accounts, roles, tenants, exclusions, testing windows, sensitive data, stop conditions, and communication paths.
Complete Rules of Engagement and written authorization. No intrusive testing begins before this gate.
Map assets, identities, roles, objects, actions, tenant boundaries, data flows, and AI/tool trust boundaries relevant to the scope.
Use manual analysis and appropriate tooling to challenge the agreed controls while staying inside the authorized scope.
Reproduce potential findings, eliminate false positives, establish impact, and preserve the evidence required for remediation.
Deliver clear findings with affected surface, exploitation path, impact, evidence, root cause, and remediation direction.
After remediation, verify whether the original path is closed and identify material regressions within the agreed retest scope.