Bug’s Life — Field Guide to Vulnerabilities
← Field Guide Index
SPC-01CORE

Penetration Testing

Classification
CORE
Method
By hand
Standards
OWASP · PTES
Duration
1–4 weeks
01 · Field Notes
Overview

What this engagement covers

Our penetration tests emulate how an actual attacker would approach your organization, from the public internet to inside your network. We combine manual testing with proven tooling to find and safely exploit vulnerabilities, then show you exactly how they chain together and what it would cost you. Testing is informed by recognised methodologies — the OWASP Web Security Testing Guide, the OWASP API Security Top 10 and PTES — adapted to your stack rather than run as a checklist.

02 · Test Coverage
What we test
Web applications (OWASP Top 10 & beyond)
  • Broken access control & insecure direct object references (IDOR)
  • Injection — SQL, NoSQL, OS command and template injection
  • Cross-site scripting (reflected, stored and DOM-based)
  • Authentication, session management and password-reset flaws
  • Server-side request forgery (SSRF) and insecure deserialization
  • Security misconfiguration, sensitive data exposure and CSRF
  • Business-logic abuse — workflow, race conditions and price/quantity tampering
APIs (OWASP API Security Top 10)
  • Broken object- and function-level authorization (BOLA / BFLA)
  • Broken authentication and JWT/token handling
  • Excessive data exposure and mass assignment
  • Missing rate limiting and resource-consumption abuse
  • Improper inventory — undocumented, shadow and deprecated endpoints
  • REST, GraphQL and webhook testing
Network & infrastructure (external + internal)
  • Exposed services, weak/default credentials and misconfigurations
  • Missing patches and known-CVE exploitation
  • Privilege escalation and lateral movement
  • Active Directory / identity attack paths (internal)
  • Network segmentation and firewall-rule weaknesses
Perspectives
  • Black-box (no prior knowledge), grey-box (limited creds) and white-box
  • Authenticated and unauthenticated testing for every user role
03 · Specimen Range
Scope of work
  • a.External penetration testing of your internet-facing perimeter
  • b.Internal penetration testing that emulates an attacker inside your network
  • c.Web application testing aligned to the OWASP Top 10 and beyond
  • d.API testing against the OWASP API Security Top 10 — auth, authorization, rate limits, data exposure
  • e.Authenticated and unauthenticated test perspectives
  • f.Safe, controlled exploitation with impact demonstrated, not just theorized
04 · Field Method
How we work
01

Scope & rules of engagement

We agree targets, timing, depth and constraints in writing before anything starts — so testing is safe, authorized and focused on what matters to you.

02

Manual testing

Certified testers work by hand — following recognised methodologies like OWASP and PTES, not just automated scanners — chaining findings the way a real attacker would to prove genuine impact.

03

Reporting

You get a prioritized report with clear proof-of-concept, business impact and step-by-step remediation your engineers can act on immediately.

04

Retest

After you fix, we re-test the findings to confirm they are resolved and issue an updated report you can share with customers or auditors.

05 · What you keep
Deliverables
  • Prioritized report ranked by real business risk
  • Proof-of-concept and reproduction steps for each finding
  • Clear, developer-friendly remediation guidance
  • A customer-shareable attestation letter for due diligence and procurement
  • Free retest to confirm your fixes worked
06 · Field Q&A
Common questions
Will testing disrupt our systems?

No. Where exploiting a vulnerability carries any risk to a live system we document it and check with you first — we never pursue a risky exploit without your explicit go-ahead.

How long does a test take?

Most engagements run 1–4 weeks depending on scope and environment. You get first findings within 48 hours of testing starting.

Can we share the report with customers and auditors?

Yes — the report is yours. We also provide a summary attestation letter designed to be handed to enterprise customers and procurement teams, and we are happy to work under NDA.

How much does a penetration test cost?

Every engagement is a fixed, upfront quote based on scope — no hourly billing and no surprises. Tell us what you need tested and you will have a price before anything is signed.

Specimen request

Ready to get started with Penetration Testing?