Bug’s Life — Field Guide to Vulnerabilities
← Field Guide Index
SPC-02ASSESS

Vulnerability Assessment

Classification
ASSESS
Method
By hand
Standards
OWASP · PTES
Duration
1–4 weeks
01 · Field Notes
Overview

What this engagement covers

A vulnerability assessment gives you broad, repeatable coverage of your environment. We identify, validate and prioritize weaknesses — filtering out the false positives that automated scanners generate — so your team spends time fixing what actually matters instead of chasing noise.

02 · Test Coverage
What we test
Network & infrastructure
  • Missing patches and outdated, end-of-life software
  • Exposed and unnecessary services, ports and management interfaces
  • Default, weak or reused credentials
  • Insecure protocols and weak TLS/SSL configuration
  • Firewall and network-segmentation gaps
Systems & endpoints
  • Operating-system and software CVEs
  • Misconfigurations measured against CIS Benchmarks
  • Local privilege-escalation exposure
Applications
  • Known-vulnerable dependencies and components
  • Common web and server misconfigurations
  • Exposed admin panels, secrets and sensitive files
Validation
  • Manual triage to remove the false positives scanners generate
  • Risk-based prioritization mapped to your environment
03 · Specimen Range
Scope of work
  • a.Authenticated and unauthenticated vulnerability scanning
  • b.Manual validation to remove false positives
  • c.Network, server and application-layer coverage
  • d.Risk-based prioritization mapped to your environment
  • e.Optional recurring assessments to track progress over time
04 · Field Method
How we work
01

Scope & rules of engagement

We agree targets, timing, depth and constraints in writing before anything starts — so testing is safe, authorized and focused on what matters to you.

02

Manual testing

Certified testers work by hand — following recognised methodologies like OWASP and PTES, not just automated scanners — chaining findings the way a real attacker would to prove genuine impact.

03

Reporting

You get a prioritized report with clear proof-of-concept, business impact and step-by-step remediation your engineers can act on immediately.

04

Retest

After you fix, we re-test the findings to confirm they are resolved and issue an updated report you can share with customers or auditors.

05 · What you keep
Deliverables
  • A validated, de-duplicated list of real issues
  • Severity and priority for each, based on your context
  • Remediation guidance and quick wins highlighted
  • A baseline you can measure future improvement against
06 · Field Q&A
Common questions
How is this different from a penetration test?

A vulnerability assessment is about breadth — finding and prioritizing as many real weaknesses as possible. A penetration test is about depth — proving how far an attacker could actually get. Many teams start here, then pentest their highest-risk areas.

Can you run this regularly?

Yes. We can schedule recurring assessments (for example quarterly) so you can track your security posture as your environment changes.

Specimen request

Ready to get started with Vulnerability Assessment?