Pentest

An expert-led intrusion test, with authorized active exploitation, to find and prove the flaws in your environment before a real attacker does.

3 types Web · Network · Social eng.
CVSS 3.1 Severity classification
OWASP WSTG and Top 10
Custom-sized Scope and hours per client
01

Service overview

ACT's Pentest is a controlled, offensive intrusion test: the specialist takes the position of an attacker and actively looks for exploitable flaws in the client's environment, validating the real impact of each one. Unlike a vulnerability scan, every finding here is manually confirmed, exploited within agreed limits, and documented with reproducible evidence. The scope is closed together with the client, and the hours are sized project by project, according to the size and criticality of the environment.

Web Pentest

Sites, web systems, portals, and REST/GraphQL APIs. Tests guided by the OWASP WSTG and Top 10, with severity calculated in CVSS 3.1.

Network Pentest

Hosts, servers, exposed services, and Active Directory on the local network. Enumeration, exploitation, privilege escalation, and lateral movement.

Social Engineering

The human factor: phishing campaigns, pretexting, and targeted contact, with aggregated metrics on exposure and team response.

02

Testing approaches

The approach defines how much the pentester knows about the environment before starting, which directly changes the depth of findings and the time required. The choice is made with the client during the scoping stage.

Approach Available information What it simulates and where it applies
Black box None, only the target defined in scope External attacker with no prior knowledge. Measures the real exposure of the attack surface
Gray box Regular user credentials and/or partial environment information Legitimate user or attacker who has already gained initial access. Best depth/time ratio for most projects
White box Full access: documentation, architecture, privileged credentials, and source code when applicable Maximum coverage analysis, focused on finding the most flaws in the least time
Authenticated internal Network point and/or host provided by the client within the environment Insider or already-compromised workstation. Applied to internal network pentesting

Approaches can be combined in the same project: for example, an external black box phase followed by an authenticated internal phase.

03

Web Pentest: technical scope

Tests on sites, web systems, authenticated portals, and APIs, conducted based on the OWASP Web Security Testing Guide (WSTG) and classified by CVSS 3.1. The classes below make up the standard battery; actual coverage depends on the contracted scope and hours.

Vulnerability class What's tested
Broken access control IDOR/BOLA, horizontal and vertical privilege escalation, admin functions accessible to regular users, authorization bypass via parameter manipulation
Injection SQL Injection and NoSQL Injection, OS command injection, LDAP, XPath, and Server-Side Template Injection (SSTI)
Cross-Site Scripting (XSS) Reflected, stored, and DOM-based, with impact assessment on session and user data
Authentication and session Brute force and credential stuffing, password policy, MFA bypass and weakening, session fixation and invalidation, cookie attributes, JWT token manipulation and signing
Cryptographic failures TLS and cipher configuration, sensitive data in transit and at rest, use of obsolete algorithms, secret exposure in the application
Security misconfiguration Security headers, allowed HTTP methods, directory listing, verbose error messages, permissive CORS, exposed admin panels and interfaces
SSRF and forged requests Server-Side Request Forgery, access to internal resources and cloud metadata, Cross-Site Request Forgery (CSRF)
Upload and file manipulation Type and content validation, path traversal, LFI/RFI, and paths leading to remote code execution
Business logic Flow bypass, price/quantity/step manipulation, race conditions, abuse of legitimate features
REST and GraphQL APIs Authentication and authorization per endpoint, BOLA/BFLA, mass assignment, introspection enabled, abusive nested queries, lack of rate limiting
Components and dependencies Outdated technologies and libraries, versions with known and exploitable CVEs in the application's context
Information exposure Metadata, backup files, exposed repositories, comments and development artifacts, user enumeration

Every automated finding is manually validated before entering the report: false positives are not reported as vulnerabilities.

04

Network Pentest (internal): technical scope

An intrusion test on the internal infrastructure: identifying active hosts and services, exploiting the flaws found, and assessing how far an attacker would get from a point inside the network. The techniques used are mapped against MITRE ATT&CK, letting the client correlate findings with their own detection capability.

Test front What's tested
Discovery and mapping Scanning of active hosts, ports, services, and versions; identification of operating systems and of assets not inventoried by the IT team
Service vulnerabilities Outdated services or ones with exploitable CVEs, legacy protocols (SMBv1, Telnet, FTP), exposed RDP and RPC, insecurely configured running services
Active Directory Domain, user, and group enumeration; Kerberoasting and AS-REP Roasting; insecure ACLs and delegations; trust relationships; attack paths to domain admin privileges
Credentials and authentication Default, weak, and reused passwords; over-privileged service accounts; credential capture via LLMNR/NBT-NS/mDNS poisoning and SMB authentication relay
Privilege escalation Local escalation on Windows and Linux workstations and servers: incorrect permissions, vulnerable services, scheduled tasks, misapplied binaries and configurations
Lateral movement Pivoting between hosts, credential and session reuse, reach from a compromised asset: within the scope's authorized limit
Network segmentation Validating isolation between VLANs, guest networks, production environments, and administrative segments
Shares and data Accessible network shares, excessive permissions, and exposure of sensitive data to unauthorized users
Exposed internal surface Management interfaces, printers, cameras, IoT devices, consoles, and panels accessible without proper authentication
Endpoint hardening Assessment of workstation and server posture: updates, local policies, active security controls, and their effectiveness against the techniques applied

The reach of post-exploitation (persistence, lateral movement, and depth) is always limited to what was authorized in the scope agreement.

05

Social Engineering: technical scope

An assessment of security's human link: instead of attacking only systems, the test measures how the organization's people react to real manipulation attempts, and whether the incident is noticed and reported.

Vectors applied

  • Email phishing campaigns, with a controlled capture page
  • Pretexting: contact built around the company's real context
  • Phone and message-based approaches, as authorized
  • Prior OSINT: gathering public information to build the scenario

Metrics delivered

  • Campaign open and click-through rate
  • Credential submission rate
  • Time to first report to the IT team
  • Percentage of employees who identified and reported the attack

Aggregated results, not individual exposure.

The goal of the test is to measure the organization's maturity and guide awareness efforts: results are presented in consolidated form. No captured credential is used beyond proving the vector, and all are discarded at the end of the project.

06

Methodology and risk classification

Every vulnerability found receives a score calculated in CVSS 3.1 (Common Vulnerability Scoring System), with the full vector recorded in the report so the client can audit the score. The resulting severity guides remediation priority.

Severity CVSS 3.1 range Practical reading
Critical 9.0 – 10.0 Direct compromise of the environment or data; requires immediate action
High 7.0 – 8.9 Severe impact and viable exploitation; priority fix
Medium 4.0 – 6.9 Relevant impact, generally dependent on preconditions or chaining
Low 0.1 – 3.9 Limited impact; fix planned within the normal cycle
Informational 0.0 Best-practice or hardening note, with no direct associated risk
07

Frameworks and test execution

Reference frameworks

  • OWASP WSTG: web pentest testing roadmap
  • OWASP Top 10: categorization of the most critical risks
  • CVSS 3.1: scoring and severity of findings
  • MITRE ATT&CK: mapping of techniques in the network pentest

Manual execution, automated support

  • Commercial and open-source tools used to support discovery
  • Mandatory manual validation of every finding before reporting
  • Elimination of false positives: the report includes only what's confirmed
  • Chaining flaws to demonstrate real impact, not just isolated existence
  • Exploratory business-logic tests, which no scanner covers

Other frameworks can be adopted in the report upon client request.

08

Project cycle

The project follows defined phases, with an agreed start and end. Nothing is executed before the scope is formalized and written authorization is granted.

  1. 1

    Scope definition

    Survey of targets, domains, network ranges, and systems; sizing of hours according to the client's reality

  2. 2

    Authorization and NDA

    Signing of the test authorization agreement and NDA before any technical activity

  3. 3

    Kickoff

    Alignment of rules of engagement, test windows, emergency contacts, and credential handoff for gray and white box approaches

  4. 4

    Reconnaissance

    Information gathering and attack surface mapping within the authorized scope

  5. 5

    Enumeration and analysis

    Identification of services, technologies, entry points, and candidate vulnerabilities

  6. 6

    Exploitation

    Practical validation of flaws, with proof of real impact and evidence collection

  7. 7

    Post-exploitation

    Assessment of the reach achieved, escalation, lateral movement, and data access, restricted to the authorized limit

  8. 8

    Report

    Consolidation of findings, CVSS 3.1 classification, step-by-step evidence, and remediation measures

  9. 9

    Presentation

    Report presentation meeting, walking through risks, priorities, and technical clarification with the client's teams

  10. 10

    Retest

    New validation of fixed flaws, when included in the contract

The retest phase is optional and defined according to the client's preference at contracting.

09

Rules of engagement and limits

Pentest is an offensive activity conducted within strict limits. The rules below apply to all three service lines and are formalized before work begins.

What we do

  • Authorized active exploitation, to prove real impact and not just point out indicators
  • Execution exclusively within the testing window agreed with the client
  • Action restricted to the targets listed in the scope agreement
  • Logging of all activity performed, for later traceability

Limits observed

  • Denial-of-service (DoS) tests only occur with specific prior communication and authorization
  • No target outside the scope is tested, even if reachable during the work
  • Unauthorized destructive or downtime-causing actions are not performed
  • Sensitive data is accessed only to the extent needed to prove impact
  • Access, artifacts, and credentials obtained are removed or discarded at the end of the project

About testing in production environments.

When the test runs in production, there's an inherent risk of instability in fragile or undersized systems. That's why the test window, emergency contacts, and immediate-stop procedure are defined at kickoff: execution can be suspended at any time at the client's request.

10

Specifications

Format and delivery PDF report, sent by email at the end of the project
Executive summary Business risk view, general environment overview, and distribution of findings by severity
Technical report Individual breakdown of each vulnerability: description, location, CVSS 3.1 score and vector, severity, and impact
Evidence and PoC Proofs of concept with step-by-step reproduction, screenshots, and relevant requests/responses
Remediation Recommended fixes for each flaw; the choice of implementation approach remains with the client
Presentation Results presentation meeting with the pentester responsible for the project
Retest Issuance of a retest report after fixes, when included in the contract
Framework adaptation The report can be adapted to another framework or standard required by the client, upon prior alignment

Restricted distribution by design.

The report circulates exclusively between the pentester responsible for the project and the people the client names to receive it. No data, evidence, or environment information is shared outside that list, and all material collected during testing is handled under an NDA.

Want to know if Pentest solves what your operation needs?

Talk to ACT and understand, with clarity, how this solution fits your environment.

Talk to ACT