SERVICE 02 · PENETRATION TESTING

Penetration testing that proves what's exploitable, not what's theoretical.

Authorized adversarial testing with scope, rules of engagement, and authorization defined in writing before work begins. Findings are ranked by exploitability and business impact, with reproduction steps your engineering team can act on.

THE PROBLEM

A vulnerability scan can tell you what might be exposed. It cannot tell you what happens when someone tries: which credentials fall, which paths chain together, which systems an attacker reaches from the first foothold. Much of the industry sells scans dressed as tests, with automated output, minimal validation, and findings nobody can reproduce. The result is a report that satisfies a requirement without answering the question that matters. What could an attacker actually do here? Strace penetration testing exists to answer that question, with evidence.

WHAT WE OFFER

Three testing scopes.

AST-A

External network penetration testing

Testing of your internet-facing perimeter from an external adversary’s position: exposed services, remote access, mail and web infrastructure, and the credential and configuration weaknesses attackers reach first. Conducted under written rules of engagement. Deliverable: findings ranked by exploitability and business impact, with reproduction steps and remediation guidance.

AST-B

Internal network & Active Directory penetration testing

Testing from an assumed-breach position inside the network: lateral movement paths, Active Directory misconfigurations, privilege escalation chains, credential exposure, and the segmentation gaps that turn one compromised workstation into a domain-wide incident. Deliverable: a chained attack-path narrative with prioritized remediation.

AST-C

Web application penetration testing

Manual, hands-on testing of your web applications, going beyond what automated scanners find: authentication and session handling, access control, injection, and business-logic abuse. Deliverable: findings with evidence, reproduction steps, and remediation guidance mapped to each finding.

Post-remediation retesting is available for findings identified during a Strace testing engagement. We re-execute the original attack paths, confirm which findings are closed, and issue an updated report you can hand to leadership, auditors, or your cyber insurance carrier.

WHO THIS IS FOR

Mid-market organizations that need evidence of exploitable exposure, not another scan report · Companies with annual penetration testing obligations from customers, auditors, or cyber insurance carriers · Organizations validating their environment after major infrastructure or identity changes · Leadership teams that want to know what an attacker could reach before the board asks · MSPs and channel partners needing senior offensive-security depth for their clients

HOW WE WORK

Four phases. Written authorization throughout.

01 · SCOPE

Define the targets, objectives, testing windows, and constraints with the practitioners who will actually run the test.

02 · AUTHORIZE

Written rules of engagement and authorization before any testing begins: points of contact, escalation paths, and handling for fragile systems.

03 · TEST

Hands-on adversarial testing within the agreed scope. Exploitation is controlled, evidence is captured, and anything potentially disruptive is coordinated first.

04 · REPORT

Findings ranked by exploitability and business impact, with reproduction steps, evidence, and remediation guidance, plus an executive summary written for leadership.

WHAT EVERY FINDING INCLUDES

  • Severity ranked by exploitability and business impact, not scanner score
  • Reproduction steps an engineer can follow
  • Evidence captured during testing
  • Concrete remediation guidance per finding
  • An executive summary written for leadership, not just engineers
  • Post-remediation retesting available as a scoped follow-up

ENGAGEMENT STRUCTURE

Penetration testing engagements are scoped per environment. External, internal and Active Directory, and web application testing are offered individually or combined. Scope, rules of engagement, testing windows, and written authorization are defined before testing begins. Pricing on quote after a short scoping conversation.

Post-remediation retesting is scoped as a follow-up engagement, validating that findings from the original test are closed.

FAQ

START THE CONVERSATION

Tell us what you need tested. We'll scope it with you directly.

A 30-minute consultation with the practitioners who run the tests: scope, rules of engagement, and a fixed proposal before any work begins.