Home / How we work
Methodology
Authorised, scoped and evidenced.
Offensive security only works if it is legitimate. Every engagement begins with written authorisation and a defined boundary, and ends with evidence your team and your auditors can rely on.
Authorisation
Signed scope, targets, exclusions, stop conditions and emergency contacts. Nothing is tested before this exists.
Research
Open-source and technical research on the agreed targets. Attack paths are built specifically for your environment.
Execution
Testing runs to scope, with findings and evidence captured as they are produced and safe-stop rules observed.
Investigation
Every attack is followed by a full-scale cyber-forensic investigation, with malware sent to R&D.
Hardening
The holistic understanding of the threat and malware drives infrastructure hardening and advanced threat detection.
Before we start
What has to be true.
- Written authorisation from someone with the authority to grant it, naming the scope.
- A named emergency contact reachable during testing, including out of hours.
- Stop conditions agreed in advance — the findings that end the engagement early.
- Explicit exclusions for systems, third parties and data that must not be touched.
- A data handling agreement covering anything captured during the work.
- Agreed notification for critical findings, so you are not reading them in a report weeks later.
Third parties are never in scope by default. Cloud providers, SaaS vendors, suppliers and your own customers each have their own authorisation requirements. If a test would touch a third party, it is either excluded or we tell you what permission you need to obtain first.
We will decline work. If a request would require testing without authorisation, targeting individuals outside the agreed population, or producing work intended to harm a person or organisation, we decline it. That is not a formality — it is the line that separates this work from the thing it imitates.
Evidence
What the engagement leaves behind.
| Deliverable | Contents |
|---|---|
| Findings report | Ordered by what an attacker would do next, with reproduction steps and evidence. |
| Forensic report | Who, what, when, why and how — with a reconstructed timeline. |
| Malware analysis | Capability, persistence, indicators and derived detection logic. |
| Hardening plan | Prioritised infrastructure and configuration changes. |
| Detection package | Rules and hunting queries built from observed behaviour. |
| Walkthrough | A session with your engineers, not a PDF handover. |
| Retest | Verification that remediation actually closed the path. |
Legal
The paperwork that makes it legitimate.
Start the scoping conversation.
Tell us what you want tested and what must not be touched. We will produce a scope document and authorisation pack for your legal team to review.