OUR METHODOLOGY
A process built to find real risk, and prove it is gone.
Every Cybros engagement follows the same rigorous, standards-aligned path, from a signed scope to a free retest. No scan-and-dash, no scanner noise. Here is exactly how we work, phase by phase.
HOW WE OPERATE
Four rules that never change, whatever we are testing.
- Manual-first, alwaysHumans lead, tools support. Only a senior tester finds the logic flaws and chained exploits scanners miss.
- Only senior testersEvery engagement is run by certified offensive-security pros. No juniors cutting their teeth, no outsourcing.
- Every finding is realWe only report what we can reproduce and prove impact for. Zero false positives padding the count.
- Closure, not just discoveryWe retest every fix at no extra cost, so a risk is provably closed, not just found and forgotten.
THE ENGAGEMENT
One engagement, phase by phase.
Scroll through a real engagement. The panel shows what actually happens; the artifact is what you walk away with.
- Before a single packet
Scope & Rules of Engagement
We agree exactly what is in scope, what is off limits, and how we reach it. Targets, test windows, emergency contacts and data-handling rules all go in writing before any testing begins.
You get: A signed scope and rules of engagement. No surprises, no scope creep.
- In scope: web app, API, staging
- Window: Mon to Fri, 09:00 to 18:00 UTC
- Off limits: production data, denial of service
- Escalation contact on file
Countersigned, both parties Signed - See what an attacker sees
Recon & Attack-Surface Mapping
We map the real, reachable attack surface: subdomains, exposed services, technologies and the forgotten hosts your last scan never listed. Passive first, then active, always inside scope.
You get: An attacker's-eye view of everything you actually expose.
$ subfinder -d contoso-financial.com -silent
api.contoso-financial.com
staging.contoso-financial.com [200]
legacy-vpn.contoso-financial.com
$ nmap -sV --top-ports 1000 staging...
443/tcp open https nginx 1.18
8080/tcp open http jenkins (unauth)
# 3 subdomains your last scan missed
- Where humans beat scanners
Manual Exploitation
This is the core of the engagement. Senior testers probe by hand and chain flaws the way a real attacker would, then safely prove exploitability. Broken access control, privilege escalation, business-logic abuse: the issues no scanner reliably finds.
You get: Verified, real findings with proof, not scanner guesses.
GET /api/v2/accounts/1337 200 (us)
GET /api/v2/accounts/1338 200 (another tenant)
PATCH /api/v2/accounts/1338 204 verified
# ownership never checked server-side
# result: full account takeover
- The deliverable you act on
Reporting
Every finding lands with a CVSS 3.1 score, reproduction steps, evidence and business impact, plus a concrete fix. An executive summary frames the risk for leadership; the technical detail is written for the engineers who close it.
You get: A report your board and your engineers can both use.
CybrosREF CYB-2609Penetration Test ReportContoso Financial2 Critical4 High2 MediumCONFIDENTIAL · SAMPLE01 / 29 - We do not vanish at delivery
Remediation Support
We work with your team through the fixes: answering questions, clarifying reproduction, and helping you prioritise by real risk rather than raw count. You are never left holding a PDF and a deadline.
You get: A clear, prioritised remediation roadmap and a team that answers.
- P1IDOR account takeoverIn progress
- P1IAM privilege escalationPlanned
- P2Secrets in mobile storage Fixed
- Proof the risk is gone
Free Retest
Once you have shipped the fixes, we re-test every finding and confirm closure. It is included in the engagement at no extra cost, because a finding is not done until it is provably closed.
You get: Documented proof each risk is closed. Free.
$ retest CYB-2609 --all
[1/3] IDOR account takeover ....... FIXED
[2/3] IAM privilege escalation .... FIXED
[3/3] Secrets in mobile storage ... FIXED
3 of 3 findings closed.
# retest included, no extra cost
THE RULEBOOK
Run against the standards your auditors recognise.
We do not improvise. Every phase maps to an established methodology, so the evidence you hand an auditor is defensible on its own terms.
- PTESEnd-to-end engagement structure.
- OWASP Top 10 & ASVSWeb app coverage and verification depth.
- OWASP API Top 10API access-control and abuse testing.
- OWASP MASVSThe iOS and Android mobile standard.
- NIST SP 800-115Technical assessment methodology.
- MITRE ATT&CKReal adversary techniques we map to.
- CIS BenchmarksSecure-configuration baselines.
SEE IT IN PRACTICE
This process, in a finished report.
See exactly how a Cybros finding reads: the evidence, the CVSS score, the business impact, and the fix.
READY WHEN YOU ARE
See this process run on your own systems.
Book a free 30-minute scoping call, or download our sample report first.