Pentest
An expert-led intrusion test, with authorized active exploitation, to find and prove the flaws in your environment before a real attacker does.
Service overview
ACT's Pentest is a controlled, offensive intrusion test: the specialist takes the position of an attacker and actively looks for exploitable flaws in the client's environment, validating the real impact of each one. Unlike a vulnerability scan, every finding here is manually confirmed, exploited within agreed limits, and documented with reproducible evidence. The scope is closed together with the client, and the hours are sized project by project, according to the size and criticality of the environment.
Web Pentest
Sites, web systems, portals, and REST/GraphQL APIs. Tests guided by the OWASP WSTG and Top 10, with severity calculated in CVSS 3.1.
Network Pentest
Hosts, servers, exposed services, and Active Directory on the local network. Enumeration, exploitation, privilege escalation, and lateral movement.
Social Engineering
The human factor: phishing campaigns, pretexting, and targeted contact, with aggregated metrics on exposure and team response.
Testing approaches
The approach defines how much the pentester knows about the environment before starting, which directly changes the depth of findings and the time required. The choice is made with the client during the scoping stage.
| Approach | Available information | What it simulates and where it applies |
|---|---|---|
| Black box | None, only the target defined in scope | External attacker with no prior knowledge. Measures the real exposure of the attack surface |
| Gray box | Regular user credentials and/or partial environment information | Legitimate user or attacker who has already gained initial access. Best depth/time ratio for most projects |
| White box | Full access: documentation, architecture, privileged credentials, and source code when applicable | Maximum coverage analysis, focused on finding the most flaws in the least time |
| Authenticated internal | Network point and/or host provided by the client within the environment | Insider or already-compromised workstation. Applied to internal network pentesting |
Approaches can be combined in the same project: for example, an external black box phase followed by an authenticated internal phase.
Web Pentest: technical scope
Tests on sites, web systems, authenticated portals, and APIs, conducted based on the OWASP Web Security Testing Guide (WSTG) and classified by CVSS 3.1. The classes below make up the standard battery; actual coverage depends on the contracted scope and hours.
| Vulnerability class | What's tested |
|---|---|
| Broken access control | IDOR/BOLA, horizontal and vertical privilege escalation, admin functions accessible to regular users, authorization bypass via parameter manipulation |
| Injection | SQL Injection and NoSQL Injection, OS command injection, LDAP, XPath, and Server-Side Template Injection (SSTI) |
| Cross-Site Scripting (XSS) | Reflected, stored, and DOM-based, with impact assessment on session and user data |
| Authentication and session | Brute force and credential stuffing, password policy, MFA bypass and weakening, session fixation and invalidation, cookie attributes, JWT token manipulation and signing |
| Cryptographic failures | TLS and cipher configuration, sensitive data in transit and at rest, use of obsolete algorithms, secret exposure in the application |
| Security misconfiguration | Security headers, allowed HTTP methods, directory listing, verbose error messages, permissive CORS, exposed admin panels and interfaces |
| SSRF and forged requests | Server-Side Request Forgery, access to internal resources and cloud metadata, Cross-Site Request Forgery (CSRF) |
| Upload and file manipulation | Type and content validation, path traversal, LFI/RFI, and paths leading to remote code execution |
| Business logic | Flow bypass, price/quantity/step manipulation, race conditions, abuse of legitimate features |
| REST and GraphQL APIs | Authentication and authorization per endpoint, BOLA/BFLA, mass assignment, introspection enabled, abusive nested queries, lack of rate limiting |
| Components and dependencies | Outdated technologies and libraries, versions with known and exploitable CVEs in the application's context |
| Information exposure | Metadata, backup files, exposed repositories, comments and development artifacts, user enumeration |
Every automated finding is manually validated before entering the report: false positives are not reported as vulnerabilities.
Network Pentest (internal): technical scope
An intrusion test on the internal infrastructure: identifying active hosts and services, exploiting the flaws found, and assessing how far an attacker would get from a point inside the network. The techniques used are mapped against MITRE ATT&CK, letting the client correlate findings with their own detection capability.
| Test front | What's tested |
|---|---|
| Discovery and mapping | Scanning of active hosts, ports, services, and versions; identification of operating systems and of assets not inventoried by the IT team |
| Service vulnerabilities | Outdated services or ones with exploitable CVEs, legacy protocols (SMBv1, Telnet, FTP), exposed RDP and RPC, insecurely configured running services |
| Active Directory | Domain, user, and group enumeration; Kerberoasting and AS-REP Roasting; insecure ACLs and delegations; trust relationships; attack paths to domain admin privileges |
| Credentials and authentication | Default, weak, and reused passwords; over-privileged service accounts; credential capture via LLMNR/NBT-NS/mDNS poisoning and SMB authentication relay |
| Privilege escalation | Local escalation on Windows and Linux workstations and servers: incorrect permissions, vulnerable services, scheduled tasks, misapplied binaries and configurations |
| Lateral movement | Pivoting between hosts, credential and session reuse, reach from a compromised asset: within the scope's authorized limit |
| Network segmentation | Validating isolation between VLANs, guest networks, production environments, and administrative segments |
| Shares and data | Accessible network shares, excessive permissions, and exposure of sensitive data to unauthorized users |
| Exposed internal surface | Management interfaces, printers, cameras, IoT devices, consoles, and panels accessible without proper authentication |
| Endpoint hardening | Assessment of workstation and server posture: updates, local policies, active security controls, and their effectiveness against the techniques applied |
The reach of post-exploitation (persistence, lateral movement, and depth) is always limited to what was authorized in the scope agreement.
Social Engineering: technical scope
An assessment of security's human link: instead of attacking only systems, the test measures how the organization's people react to real manipulation attempts, and whether the incident is noticed and reported.
Vectors applied
- Email phishing campaigns, with a controlled capture page
- Pretexting: contact built around the company's real context
- Phone and message-based approaches, as authorized
- Prior OSINT: gathering public information to build the scenario
Metrics delivered
- Campaign open and click-through rate
- Credential submission rate
- Time to first report to the IT team
- Percentage of employees who identified and reported the attack
Aggregated results, not individual exposure.
The goal of the test is to measure the organization's maturity and guide awareness efforts: results are presented in consolidated form. No captured credential is used beyond proving the vector, and all are discarded at the end of the project.
Methodology and risk classification
Every vulnerability found receives a score calculated in CVSS 3.1 (Common Vulnerability Scoring System), with the full vector recorded in the report so the client can audit the score. The resulting severity guides remediation priority.
| Severity | CVSS 3.1 range | Practical reading |
|---|---|---|
| Critical | 9.0 – 10.0 | Direct compromise of the environment or data; requires immediate action |
| High | 7.0 – 8.9 | Severe impact and viable exploitation; priority fix |
| Medium | 4.0 – 6.9 | Relevant impact, generally dependent on preconditions or chaining |
| Low | 0.1 – 3.9 | Limited impact; fix planned within the normal cycle |
| Informational | 0.0 | Best-practice or hardening note, with no direct associated risk |
Frameworks and test execution
Reference frameworks
- OWASP WSTG: web pentest testing roadmap
- OWASP Top 10: categorization of the most critical risks
- CVSS 3.1: scoring and severity of findings
- MITRE ATT&CK: mapping of techniques in the network pentest
Manual execution, automated support
- Commercial and open-source tools used to support discovery
- Mandatory manual validation of every finding before reporting
- Elimination of false positives: the report includes only what's confirmed
- Chaining flaws to demonstrate real impact, not just isolated existence
- Exploratory business-logic tests, which no scanner covers
Other frameworks can be adopted in the report upon client request.
Project cycle
The project follows defined phases, with an agreed start and end. Nothing is executed before the scope is formalized and written authorization is granted.
-
1
Scope definition
Survey of targets, domains, network ranges, and systems; sizing of hours according to the client's reality
-
2
Authorization and NDA
Signing of the test authorization agreement and NDA before any technical activity
-
3
Kickoff
Alignment of rules of engagement, test windows, emergency contacts, and credential handoff for gray and white box approaches
-
4
Reconnaissance
Information gathering and attack surface mapping within the authorized scope
-
5
Enumeration and analysis
Identification of services, technologies, entry points, and candidate vulnerabilities
-
6
Exploitation
Practical validation of flaws, with proof of real impact and evidence collection
-
7
Post-exploitation
Assessment of the reach achieved, escalation, lateral movement, and data access, restricted to the authorized limit
-
8
Report
Consolidation of findings, CVSS 3.1 classification, step-by-step evidence, and remediation measures
-
9
Presentation
Report presentation meeting, walking through risks, priorities, and technical clarification with the client's teams
-
10
Retest
New validation of fixed flaws, when included in the contract
The retest phase is optional and defined according to the client's preference at contracting.
Rules of engagement and limits
Pentest is an offensive activity conducted within strict limits. The rules below apply to all three service lines and are formalized before work begins.
What we do
- Authorized active exploitation, to prove real impact and not just point out indicators
- Execution exclusively within the testing window agreed with the client
- Action restricted to the targets listed in the scope agreement
- Logging of all activity performed, for later traceability
Limits observed
- Denial-of-service (DoS) tests only occur with specific prior communication and authorization
- No target outside the scope is tested, even if reachable during the work
- Unauthorized destructive or downtime-causing actions are not performed
- Sensitive data is accessed only to the extent needed to prove impact
- Access, artifacts, and credentials obtained are removed or discarded at the end of the project
About testing in production environments.
When the test runs in production, there's an inherent risk of instability in fragile or undersized systems. That's why the test window, emergency contacts, and immediate-stop procedure are defined at kickoff: execution can be suspended at any time at the client's request.
Specifications
| Format and delivery | PDF report, sent by email at the end of the project |
| Executive summary | Business risk view, general environment overview, and distribution of findings by severity |
| Technical report | Individual breakdown of each vulnerability: description, location, CVSS 3.1 score and vector, severity, and impact |
| Evidence and PoC | Proofs of concept with step-by-step reproduction, screenshots, and relevant requests/responses |
| Remediation | Recommended fixes for each flaw; the choice of implementation approach remains with the client |
| Presentation | Results presentation meeting with the pentester responsible for the project |
| Retest | Issuance of a retest report after fixes, when included in the contract |
| Framework adaptation | The report can be adapted to another framework or standard required by the client, upon prior alignment |
Restricted distribution by design.
The report circulates exclusively between the pentester responsible for the project and the people the client names to receive it. No data, evidence, or environment information is shared outside that list, and all material collected during testing is handled under an NDA.
Want to know if Pentest solves what your operation needs?
Talk to ACT and understand, with clarity, how this solution fits your environment.
Talk to ACT