Service catalogue

Everything we do,
and how it is scoped.

Grouped by the argument rather than the filing system. Identify what is already there, close it, then stop new problems appearing. Each entry lists what the work covers, the unit we count to scope it, and what you get at the end.

01 · Identify

Find what is already there. Every finding is exploited and validated by hand before it reaches your report.

1.1

Vulnerability assessment

Identifies and reports known technical vulnerabilities on a server or service, improving its resilience.

Automated vulnerability analysis across the target, with manual validation of the results to remove false positives.

This is scanning with validation, not a penetration test. We keep the distinction visible in the proposal so nobody is surprised later by what it did not cover.

Scoped by
IP addresses
Model
Black box
Delivers
Report of identified vulnerabilities with mitigation recommendations

1.2

External infrastructure penetration test

Simulates an attacker with no prior access, from the internet, against your exposed infrastructure.

Controlled exploitation and manual validation of every vulnerability found. The assessment can cover specific assets or the whole public surface the company owns.

Scoped by
Public IP addresses, exposed services
Model
Black box, grey box
Delivers
Executive report, technical report, prioritised remediation list, results session

1.3

Web application penetration test

Assesses the application from the perspective of an attacker on the internet, with and without valid credentials.

Testing across authentication, authorisation, session management, user input and business logic, with a focus on the OWASP Top 10 categories. Business logic and authorisation flaws are where scanners stop and manual testing earns its money.

Scoped by
URLs, applications, user roles
Model
Black box, grey box, white box
Delivers
Executive report, technical report, prioritised remediation list, results session

1.4

Internal network penetration test

Simulates an attacker already inside the network, whether a malicious insider or a compromised workstation.

An in-depth test of internal infrastructure to identify and exploit weaknesses that could compromise the confidentiality, integrity or availability of your systems, including Active Directory paths to privilege.

Scoped by
Servers, Active Directory domains, network segments
Model
Grey box, normally with standard user credentials, which shows the environment from both an anonymous and an authenticated position
Delivers
Executive summary, findings with proofs of concept, business impact, mitigation plan

1.5

Mobile application penetration test

Covers the application, local storage on the device, and the APIs behind it.

Analysis of the mobile application and its backend, including data stored on the device, communication with the server and authentication controls, following OWASP MASVS.

Scoped by
Applications, platforms (iOS, Android), APIs
Model
Grey box
Delivers
Executive report, technical report, prioritised remediation list

1.6

Wireless network penetration test

The wireless network is often where the external perimeter and the internal network touch.

Assessment of authentication mechanisms, segregation between guest and corporate networks, and whether an attacker in the vicinity can reach the internal network.

Scoped by
SSIDs, physical sites
Model
Black box, grey box
Delivers
Technical report with findings and configuration recommendations

1.7

Cloud and hybrid environment testing

In cloud environments most failures are not in the software. They are in the configuration.

Review and testing of identity configuration, permissions, service exposure and environment segregation across cloud and hybrid infrastructure.

Scoped by
Subscriptions, accounts, environments
Model
Grey box, with read access to configuration
Delivers
Technical report with the configurations at risk and the path to correction

1.8

OT and ICS environment testing

Industrial environments where availability is the dominant requirement and a conventional test is unacceptable.

Security assessment of operational technology with methodology adapted to how critical the systems are, and without actions that would compromise the availability of the operation. Few providers have validated competence in this area.

Scoped by
Cells, PLCs, automation networks, SCADA systems
Model
Grey box, with the operations team present throughout
Delivers
Executive report, technical report, phased remediation plan

1.9

Red teaming

An objective-led exercise, with no scope announced to the defensive teams, to measure detection and response rather than the mere existence of vulnerabilities.

Simulation of a real attacker over several weeks, combining technical, physical and social engineering vectors, against objectives agreed in advance with management.

Scoped by
Agreed objectives, campaign duration
Model
Black box
Delivers
Campaign report, event timeline, detection and response analysis, joint session with the defensive team

1.10

Phishing and social engineering

A large share of attacks do not begin with a vulnerable component. They begin with a person.

Simulated phishing sent to staff to measure susceptibility and the response to this kind of threat. We agree in advance what happens to people who fail: the campaign measures the process, not the individuals.

Scoped by
Users with email accounts
Model
Single or recurring campaign
Delivers
Report with open, click and credential submission rates, and failure analysis

1.11

Physical intrusion test

An attacker who walks into the building does not need to get past the firewall.

Assessment of physical access controls, including attempts at unauthorised entry and connection to internal network points. Requires a signed authorisation letter and a reachable contact for the whole execution window.

Scoped by
Sites, buildings
Model
Black box
Delivers
Report with the route taken, evidence and control recommendations

1.12

Vulnerability management

A penetration test once in a company's life does not solve the problem. Continuous testing does.

New tests run every month against your assets, with real-time visibility of anything newly found. Instead of a report that ages, you get a live record: we find a vulnerability and it appears immediately for verification and assignment; you fix one and update its status, and it is re-checked as soon as possible.

Scoped by
Assets under watch, cadence
Model
Continuous
Delivers
Access to the vulnerability record, periodic reports, regression checks

02 · Fix

Finding the problem is the easy half. Closing it without breaking the product is the other.

2.1

Remediation consulting

Not every company has an internal IT or development team, which can make our recommendations hard to act on.

We work alongside your team through the whole correction process. Need help implementing new validation inside the software we tested? We guide the team in the language they already use. Struggling to configure a domain controller with new group policies? We help you reach the right settings. Whatever needs correcting, you get practical advice and direct support rather than a document.

Scoped by
Hours or days of support
Model
Remote or on site
Delivers
Record of the sessions and a technical opinion on the corrections implemented

2.2

Architecture and design review

Applied before the system exists, this is the point where a correction costs least.

Review of the proposed architecture against ISO/IEC 27001, OWASP and NIST references, identifying design flaws before implementation rather than after.

Scoped by
Systems or projects under review
Model
White box
Delivers
Review report with design flaws identified and recommendations

2.3

Retest

Validation of the corrections you implemented, against the identifiers in the original report.

Each vulnerability is re-assessed against the identifier it was given originally, and the result is issued as an addendum that keeps the original numbering. Normally included in the price of the original test.

Scoped by
Vulnerabilities to revalidate
Model
Follows the original engagement
Delivers
Addendum to the original report with the status of each finding

03 · Prevent

We fixed what was there. Now how do you stop new problems appearing? All training can be delivered in person or remotely, and tailored to the failures found in earlier tests, which makes the examples recognisable to the people in the room.

3.1

Awareness and good practice

Designed for the whole organisation, including people who do not work in technical roles.

How to recognise the most common threats and scams, and the tools each person can use to improve their own security day to day. Where a phishing campaign ran first, its results become the material for the session.

Scoped by
Participants, number of sessions
Model
In person or remote
Delivers
Session materials and attendance report

3.2

Secure web application development

Designed for development teams.

Guided by the OWASP Top 10 and our internal security framework, this explains how the most frequent vulnerabilities work inside the code, in the language the company actually uses. Entirely hands-on: we provide vulnerable laboratories, demonstrate how each vulnerability is exploited and corrected, and give the team the chance to apply the techniques themselves.

Scoped by
Participants, number of sessions, language
Model
In person or remote
Delivers
Training materials, exercise laboratories, attendance report

3.3

Network security

Designed for IT and systems teams.

How the most frequent weaknesses in corporate infrastructure work, with laboratories where we demonstrate how they are exploited and corrected, and the team applies that knowledge directly.

Scoped by
Participants, number of sessions
Model
In person or remote
Delivers
Training materials, exercise laboratories, attendance report

04 · Anything else

The categories above cover what we are asked for most. They do not cover everything we can do.

4.1

Unusual and one-off targets

If it has an interface, it has an attack surface. The category it belongs to is our problem, not yours.

Some of the work we are proudest of did not fit a category when it arrived. We have tested smart TV applications, and we regularly assess targets we have not seen before. Where the target is genuinely new to us we say so, and we scope a short exploratory phase first so that neither side is guessing about the effort.

Describe what you have. We will tell you what a test would look like and what it would cost, or tell you plainly that we are not the right people for it. A referral to someone better suited is a better outcome for you than a test we are learning on at your expense.

Scoped by
Agreed case by case, after we have seen the target
Model
Depends on the target and the access available
Delivers
The same reporting as any other engagement: executive report, technical report, prioritised remediation, retest

Not sure which of these you need?

Most clients are not, at first. Describe the systems you are worried about and we will tell you where to start, including when the honest answer is that you do not need us yet.

Working languages
Portuguese, English