Pentesting

Penetration testing services

A pentest is an authorised attack on your own systems: we try to break in using the techniques somebody would use for real, with your written permission and an agreed scope, and we write down what worked.

There are nine kinds, and the only thing that changes between them is what gets attacked. Pick by what you want tested, not by what it is called.

How we run one
87%
of our clients renew annually
150+
organisations across multiple European countries
7/10
confirm findings their previous provider did not find
Not sure which of the nine you need? Tell us what the system is. We will say which one fits and what scoping it would take.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Trusted by companies in highly regulated environments

What a penetration test is

A penetration test, or pentest, is a controlled attack against a system you own, agreed in advance and carried out with written permission. The aim is not a list of theoretical weaknesses: it is to find out which ones a real attacker could chain together, and prove it.

Scanners are part of it, but only the starting point. Broken authorisation, business logic that can be walked around and chains that only work in the right order are found by a person.

The Spanish name is "test de intrusión", and the two mean the same thing.

The four phases of a penetration test drawn as a loop: planning, discovery, attack and reporting, with a feedback arrow running from attack back to discovery.

How to pick, in three questions

You do not have to arrive knowing the name of the test. These three questions get you to the right one, and they are the same three we ask on the call.

  1. 01

    Where would the attacker be standing?

  2. 02

    What is the thing you would not want touched?

  3. 03

    Who is asking, and what will they accept?

Very often the answer is two: a mobile app comes with the APIs behind it, and an internal test pairs with the external one. That is normal, and it is decided before anyone quotes anything.

What a finding actually looks like

Autenticada como · [email protected]
GET /api/orders/4813
↳ el atacante cambia el ID: el servidor no comprueba nada más
ID manipulado
API · orders IDOR
200 OK DATOS DE OTRO CLIENTE
order_id4813
total€12,840.00
card_last4•••• 7421
↳ El servidor ha devuelto el pedido de otro cliente. Control de acceso roto.
Misma sesión · recorridos los ids 4801-4840 37 de 40 respondieron
idcustomertotalpropietario
4812[email protected]€188.50suyo
4813[email protected]€12,840.00no es suyo
4814[email protected]€2,306.20no es suyo
4815[email protected]€41,915.00no es suyo
… 33 ids más respondieron igual
IMPACTOFalta una comprobación de propiedad: todo el libro de pedidos

This is one real class of flaw, taken from web testing: a user changes a number in a request and the server hands over somebody else's order. No scanner signature fires, because every request is well formed and correctly authenticated. Each of the nine services has its own demo on its own page; this one is here so you can see the shape of the thing.

LOOKED AT IN ALL NINE
  • Authentication and session handling
  • Authorisation: who is allowed to reach what
  • Business logic and multi-step flows
  • Input validation and injection
  • Configuration and exposed secrets
  • Encryption in transit and at rest
  • Data and traces left where they can be read
  • Chains: what two minor flaws reach together
PTES

The seven phases, the same nine times

Whichever of the nine you buy, the method is the same one: the seven phases of the PTES. What changes between them is the target, not the process.

  1. 01 Pre-engagement interactions Scope, rules, time window, who to call if something breaks, and the written authorisation. Nothing is touched before this is signed.
  2. 02 Intelligence gathering What the target really exposes, which is almost never the list you were given. Domains, services, versions, people and anything already public.
  3. 03 Threat modelling Who would want in, what they would be after, and which paths are worth the time. This is what stops a pentest from being a list of everything at once.
  4. 04 Vulnerability analysis Where the weaknesses are, by hand and with tooling. Scanners run here, and here is where their output stops being the answer and starts being a lead.
  5. 05 Exploitation Proving it. A finding nobody managed to use is a hypothesis, and it goes in the report as one.
  6. 06 Post-exploitation What the first foothold reaches: other systems, other accounts, the data. This is the part that turns a severity into a business number.
  7. 07 Reporting Steps to reproduce, the evidence, what closing it takes, ordered by what it costs you. Plus the retest once you have fixed it.

What you get

A scope agreed before anything is touched

What is in, what is out, when it happens and who gets called if something breaks. In writing, signed by both sides.

Manual testing by certified ethical hackers

Scanners run too, but they are the floor. What is worth paying for is the finding somebody had to think of.

A report with proof, not a scanner dump

Every finding with the steps to reproduce it, the evidence that it worked and what closing it would take, ordered by what it costs your business.

A retest

Once you have fixed things, we test the same findings again. A vulnerability is not closed because a ticket says so.

When companies ask for one

01

A customer, an auditor or an insurer asks for a penetration test report before signing.

02

You are about to ship something new and nobody outside the team has tried to break it.

03

A certification or a regulation needs evidence that somebody tested it.

04

Something already happened and you want to know what else is open.

Where the findings land

Findings do not arrive as a PDF three weeks later. They land in the platform as they are confirmed, each with its evidence, its severity and its closure status, so your team can start on the first one before the test has finished.

The recorded walkthrough is not published yet. Until it is, the platform is shown live on the introductory meeting.

What our clients say

Names, roles and companies on the record.

We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
Sergi Leno, Systems Manager
ETNIA Barcelona
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
Jordi Bondia, IT Director
SALVI
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
Sergi Laencina Verdaguer, CISO
NPAW
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Juan Valer Tecedor, Software Engineer
GNOSS

Beyond pentesting

A pentest is one of five families. These are the others, in case what you actually need is one of them.

Frequently asked questions

  • What is pentesting?

    An authorised attack on your own systems, carried out with the techniques a real attacker would use, to find out what somebody could actually do and prove it. The Spanish term is "test de intrusión".

  • Is it the same as ethical hacking?

    Ethical hacking is the general term and a penetration test is the specific engagement: an agreed scope, a time window, manual testing and a report.

  • Which of the nine do we need?

    It depends on what you want tested, and quite often it is more than one: a mobile app usually comes with the APIs behind it, and an internal test pairs with the external one. We work that out in the introductory meeting before anyone quotes anything.

  • How long does it take?

    It depends on the scope, and that is what the kick-off meeting settles. Any number given before knowing what is in scope would be made up.

  • Do you do pentesting for SMEs?

    Yes. The type of test is the same and what changes is the scope: a small company usually starts with the external perimeter or with its web application, which is where almost everything it exposes lives.

  • What do you need from us to start?

    Somebody who can authorise the test, the list of what is in scope and a window to do it in. Everything else is closed in the kick-off.

Tell us what you want tested

Two lines about what the system is and what it is used for are enough for us to say which of the nine fits and what scoping it would take.

Ask for a penetration test
The person who answers is one of the people who would run it.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Or email [email protected] directly.

A pentest is one of five families. These are the others, in case what you actually need is one of them.

See every service