Pole 01
Audit & offensive security
We assess your security posture using the same techniques as real attackers. Our deliverables are immediately actionable by your teams, not a CVE catalogue sorted by automated score.
Assessment scopes
Methodology
Contractual definition of scope, objectives, rules of engagement and test windows. Designation of client-side points of contact for emergency situations.
Information gathering about the scope without direct interaction with target systems. Analysis of unintentional exposures.
Active testing across defined vectors. Each identified vulnerability is verified and its exploitability confirmed before being documented.
Executive summary (one to two pages, no technical jargon), detailed technical report with proof of concept, remediation table prioritised by criticality and estimated effort.
Debrief session with technical teams and, if requested, a separate session for management. Questions on prioritisation and remediation approach are answered.
Deliverables
Executive summary
One to two pages. Overall risk, key vulnerabilities and potential impact. Written for management with no technical prerequisites.
Technical report
Detailed description of each vulnerability, reproducible proof of concept, CVE or CWE reference where applicable, realistic exploitation scenario.
Remediation table
Each finding ranked by criticality and estimated remediation effort. Enables informed prioritisation between competing priorities and available resources.
Post-audit support
Available on request: verification that identified vulnerabilities have been correctly remediated after your teams complete their fixes.