What this engagement is designed to answer
The goal is not to collect the largest number of findings. It is to determine where meaningful compromise is possible, how an attacker could get there, what the impact looks like, and what should be fixed first.
Typical coverage
- External perimeter testing
- Internal network testing
- Active Directory attack paths
- Segmentation validation
- Privilege escalation
- Retesting
Engagement workflow
1. Scope and objectives
Define systems, constraints, test depth, critical assets, access requirements, communication channels, and success criteria.
2. Reconnaissance and testing
Map the relevant attack surface, use automation where it improves coverage, and apply manual testing where context and judgment matter.
3. Validation and attack paths
Confirm findings, remove false positives, safely demonstrate impact, and combine weaknesses when that exposes a more realistic path.
4. Reporting and debrief
Deliver an executive view of risk plus technical evidence, severity rationale, reproduction steps, and practical remediation.
5. Retest
Verify fixes and document closure so the engagement produces measurable improvement.
Frequently asked questions
Do you rely on vulnerability scanners?
Automation helps with breadth and repeatability, but it does not replace manual validation. Scanner findings are treated as leads until a human can establish context and exploitability.
What does the final report include?
An executive summary, scope and methodology, prioritized findings, technical evidence, business impact, remediation guidance, and a debrief.
Can findings be retested?
Yes. Retesting is part of the remediation loop and helps teams verify that fixes actually close the identified path.