Home / Services / VAPT
OFF-02 · Offensive

VAPT

Vulnerability assessment and penetration testing

An automated scan tells you a port is open. A penetration test tells you that the open port led to an unauthenticated file upload, which led to a web shell, which led to a domain administrator hash, which led to your payroll database — and it shows you the screenshots. Only one of those two findings changes behavior.

Scope of work

What is included.

Required if you process card data, hold health or financial records, ship a customer-facing application, or need a test certificate for an enterprise client or regulator.

  • Web application testingManual testing against the OWASP Top 10 and the ASVS verification standard: broken access control, injection, SSRF, insecure deserialization, business-logic abuse and authentication bypass.
  • Mobile application testingAndroid and iOS binaries assessed against OWASP MASVS — insecure storage, certificate pinning, hardcoded secrets, tamper resistance and API abuse.
  • Network and infrastructureExternal perimeter and internal network testing. Service enumeration, patch validation, credential attacks, lateral movement and privilege escalation to domain admin.
  • API security testingREST, GraphQL and integration endpoints tested for authorization flaws, rate-limit absence, object-level access control failures and data over-exposure.
  • Cloud configuration reviewAzure, AWS and Microsoft 365 tenant review: public storage, over-permissive roles, absent logging, exposed management planes and identity misconfiguration.
  • Social engineeringAuthorized phishing, vishing and physical access attempts, scoped in writing and reported without naming and shaming individual staff.
Engagement sequence

Four phases, in this order.

The order matters more than the speed. Every phase has an exit condition you sign off before the next one starts.

Scope and authorize

We agree targets, testing windows, rules of engagement and an emergency contact. Nothing is touched before the authorization letter is signed by both sides.

Reconnaissance and mapping

Passive intelligence, asset discovery and attack-surface mapping. We find the assets your inventory forgot — those are usually the ones that fall.

Exploitation

Manual, chained exploitation with careful blast-radius control. Critical findings are reported the same day by phone, not held back for the final report.

Report and retest

Technical report plus an executive summary. One free retest of remediated findings within 30 days, and a clean certificate once they close.

How findings are ranked

Severity you can plan around.

Every finding is scored with CVSS v4.0 and paired with a response expectation, so remediation can be scheduled instead of debated. Critical findings are phoned through the same day we confirm them — we do not sit on them until the report.

SeverityCVSSReportedFix within
Critical9.0–10.0Same day, by phone24–48 hours
High7.0–8.9Within 24 hours1 week
Medium4.0–6.9In final report1 month
Low0.1–3.9In final reportNext cycle
Deliverables

What you receive.

  • Executive summary written for non-technical readers
  • Technical findings with CVSS v4.0 scores and reproduction steps
  • Proof-of-concept evidence and screenshots
  • Prioritized remediation guidance per finding
  • Retest report and attestation certificate
Tools & standards

What we work with.

  • Burp Suite Pro
  • Nmap
  • Metasploit
  • Nessus
  • OWASP ZAP
  • sqlmap
  • BloodHound
  • MobSF
  • OWASP ASVS
  • PTES
  • MITRE ATT&CK
Vendor position

We hold no exclusive reseller obligations. Recommendations are made on fit, your team's capacity to operate the thing, and local support availability — in that order.

Questions

VAPT, specifically.

Will testing take our systems down?

Rules of engagement are agreed in writing first. Denial-of-service techniques are excluded unless you explicitly ask for them, and destructive testing is confined to staging. For fragile production systems we schedule off-hours windows and stay on a live call.

What is the difference between the assessment and the penetration test?

The vulnerability assessment is broad and largely automated — it finds known issues across everything. The penetration test is narrow and manual — a human chains those issues into a real attack path. You want the first quarterly and the second annually, at minimum.

How long does a test take?

A single web application is typically five to eight working days plus two days of reporting. Full internal network tests run two to three weeks. Scoping calls are free.

Next step

Scope your vapt engagement.

Send us the shape of your environment. You will get a written scope, a fixed price and a delivery timeline — usually within two business days.

Book an assessment Email us directly

Scoping calls are free · Reply within one business day