Network assessment
Internal and external testing of your network perimeter and internal segmentation. We look for the paths between a foothold and something that matters: flat networks, over-permissioned service accounts, forgotten trust relationships, and credentials reachable from places they should not be.
Application and API testing
Runtime testing of web applications and the APIs behind them: authentication and session handling, authorization boundaries between accounts and tenants, injection, business logic that can be driven somewhere it was not designed to go, and the endpoints that never made it into documentation.
Red teaming
Objective-based adversary simulation rather than a checklist. We agree a goal (reach a specific dataset, obtain domain administrator, place a payload in a production pipeline) and pursue it across whatever combination of technical, physical, and social paths exists, while your defenders respond as they would to a real intrusion.
IoT and embedded
Testing of connected devices and the systems around them: firmware extraction and analysis, hardware interfaces left enabled from development, the protocols devices use to talk to each other, and the cloud services they report to. Relevant to anyone shipping a product with a radio in it.
Assumed breach
The engagement that starts where most others stop. We begin with the access an attacker would have after a successful phish and measure what happens next: how far that foothold reaches, how quickly it is detected, and whether your containment actually contains. Usually the most informative test for an organization with a mature perimeter.
Cloud and container assessment
Testing of AWS, Azure, and GCP environments and the workloads running in them: identity and role boundaries, over-broad permissions, publicly reachable storage and services, container escape paths, and orchestration configuration. Non-adversarial posture review is covered separately.
See also: Cloud Architecture Assessment