Technical Walkthroughs

How an external network pentest works

The real sequence of an external network penetration test: scope and rules of engagement, reconnaissance, perimeter analysis, exploitation, reporting and retest, plus what the test will not cover.

MA

How an internal network pentest works

The sequence of a real internal network penetration test: the starting point we agree, what a domain account becomes, what you get at the end, how long it takes and what the exercise deliberately does not cover.

MA

How an API pentest works

A plain account of an API penetration test from the rules of engagement to the retest: what happens in each phase, what you get at the end, and the limits of what the test can tell you.

MA

How a web application pentest works

The seven phases of a web application penetration test, what has to be ready before day one, how long it runs, what lands in your inbox at the end, and the things it deliberately does not cover.

CF

How a mobile application pentest works

The real sequence of an iOS or Android engagement: what gets agreed before day one, what happens on a device we control, what reaches your backend, what you receive, and the six things this test deliberately does not cover.

MA

How a wireless pentest works

The real sequence of a wireless penetration test, from the rules of engagement to the retest: what happens at each phase, what you need ready, how long it takes, and what this test deliberately does not cover.

MA

Our pentesting methodology, end to end

The seven phases of an Asperis engagement, from scope and rules of engagement through to the retest, with the standard behind each one, the duration ranges we scope to, and a plain list of what a penetration test does not cover.

CF

How an IoT pentest works

A connected product is hardware, firmware, a radio and a cloud backend at once. Here is the sequence we run across all four, what you receive, how long it takes and where the test stops.

CF