Penetration testing services

Every engagement is hands-on keyboard, human-in-the-loop adversarial-style testing, led by David Porcello and a team who understands how each finding impacts your business.

AI & LLM systems

OWASP GenAI Security Project aligned

Applications built on language models have a new trust boundary: the model itself, and everything it can read, call, or write. Testing covers direct and indirect prompt injection, tool and agent abuse, data exfiltration through retrieval and memory, guardrail bypass, and the conventional web and API weaknesses that surround the model.

  • Chat assistants, RAG pipelines, agentic workflows, and copilots
  • Assessment of the integration, not a benchmark of the model
  • Findings framed for the engineers who own the pipeline

Web applications & APIs

OWASP WSTG and ASVS aligned

Authenticated and unauthenticated testing of web applications and the APIs behind them, including REST, GraphQL, and websocket back ends. We focus on what automated scanners miss: broken object and function-level authorization, business-logic abuse, multi-step workflow flaws, and the places where authentication and session handling quietly diverge from design.

  • Single applications, multi-tenant SaaS platforms, app portfolios
  • Role-based testing across every provided privilege level
  • Optional white-box, source-assisted testing available

External & internal networks

PTES and NIST SP 800-115 aligned

External testing covers everything reachable from the internet: exposed services, remote-access gateways (VPN, ZTNA, SASE), mail, DNS, and shadow assets that often turn up during enumeration. Internal testing starts from an assumed breach, typically a standard user workstation or VPN account, and works toward the crown jewels through lateral movement, credential abuse, and privilege escalation.

  • Segmentation and firewall rule validation for PCI DSS scope reduction
  • Remote internal testing delivered via jump host or secure gateway
  • Wireless/RF and data exfiltration testing available on request

Cloud environments

AWS, Azure, and GCP

Cloud testing looks at the environment the way an attacker with a leaked key or a compromised developer laptop would: IAM and identity misconfiguration, over-privileged roles, exposed storage and services, metadata and instance-credential abuse, and cross-account/service paths that can connect a small foothold to the whole estate.

  • Configuration review paired with active exploitation for effective prioritization
  • Kubernetes and container platform testing when present in the environment
  • Findings mapped to CIS benchmarks when needed for an audit

Active Directory

Assumed breach to domain admin

Windows domains remain the most reliable path from a single compromised host to the entire organization. Testing covers domain and forest enumeration, credential and hash attacks, Kerberos abuse, ADCS misconfiguration, delegation, trust relationships, EDR/AV bypass, and attack paths that only a skilled tester can uncover.

  • Delivered on its own or as the internal phase of a network test
  • Hardening guidance your directory team can actually apply
  • Findings prioritized by attack path, not by count

Thick clients

Windows desktop applications

Desktop applications carry assumptions that web apps abandoned years ago: trust in the client, secrets on disk, proprietary protocols, and client-side checks that only exist in the UI. Testing covers local storage and memory, inter-process communication, protocol interception and manipulation, and the back-end services the client talks to.

  • Testing against your staging environment or in an isolated lab
  • Reverse engineering of binaries as needed
  • .NET, Java, and native applications

Mobile applications

iOS and Android, OWASP MASVS aligned

On-device and back-end testing together, because the interesting findings are usually in how the two interact. Coverage includes local data storage, keychain and keystore use, transport security and certificate pinning, platform-permission misuse, and reverse engineering of the application binary to recover secrets and hidden functionality.

  • Jailbroken and rooted device testing plus runtime instrumentation
  • API back ends tested as part of the same engagement
  • Release-candidate builds welcome

IoT & embedded devices

Hardware to cloud

Connected devices are tested end to end: the hardware and its debug interfaces, the firmware and what it stores, the local radio and network services, the mobile or web apps that manage it, and the cloud platform it reports to.

  • Firmware analysis, UART and JTAG, SPI flash
  • Bluetooth, Wi-Fi, Zigbee, and cellular interfaces
  • Pre-release product assessments and post-incident deep dives

Reverse engineering

Binary and protocol analysis

When documentation and source code aren't available, reverse engineering provides the answers. Static and dynamic analysis of binaries, firmware, and proprietary protocols to identify vulnerabilities, recover embedded secrets, and build reliable proof-of-concept exploits that demonstrate real impact.

  • Standalone engagements or as a component of thick-client, mobile, and IoT work
  • Malware and suspicious binary triage available on request

Scoping and engagement

Most work is a fixed-scope, fixed-price engagement: we agree on targets, testing windows, and rules of engagement up front, and the price doesn’t move unless the scope does. We offer black-box, grey-box, and white-box testing, and for teams that ship continuously, a recurring cadence with a retained scope is available.

Compliance-driven testing

When the test exists to satisfy a requirement, it’s scoped to that requirement from the start. Engagements can be aligned with compliance frameworks including PCI DSS, SOC 2, HIPAA, and ISO 27001. Reports include the attestation and methodology your auditor, customer, or partner needs.

Not sure what you need?

Most first conversations are a short call to work out the coverage that is right-sized for your business. Drop us an email to get started