Coverage and perspectives
See the controlled procedures, attacker or reviewer viewpoints, access requirements and scope conditions behind the service.
Choose the actual service you need: a specific penetration test, application or cloud assurance, managed security operations, network and firewall engineering, incident readiness or specialist remediation. Governed technical services publish the coverage, evidence, framework or control mappings, limitations and commercial boundary before the work begins.
Damocles service profiles separate the commercial description from the controlled technical assurance record. The technical layer identifies the authorised testing or reviewer perspectives, coverage areas, required access, evidence produced, framework references, applicability and limitations relevant to that service.
Control mappings are not treated as a marketing badge. Where an engagement produces evidence relevant to an approved security framework or control objective, the mapping states whether that behaviour is directly assessed, whether the result is supporting evidence for a broader assessment, or whether the reference is contextual only. The assurance boundary remains visible so a scoped technical service is not represented as complete compliance or certification.
See the controlled procedures, attacker or reviewer viewpoints, access requirements and scope conditions behind the service.
See how relevant technical evidence maps to approved methodologies, standards or control objectives and how that mapping should be interpreted.
See the report outputs, reproducible evidence and the retest, rescan, configuration review or operational evidence used to review closure where included.
Penetration testing is not one generic service. Damocles separates the engagement by attacker perspective, technology and trust boundary so the customer can see exactly what is being assessed.
Assess public IPs, exposed services, remote access, perimeter devices and internet-facing management paths from the perspective of an unauthenticated external attacker. The result shows which public exposures can provide an initial foothold and what should be fixed first.
View External Testing →Model a compromised workstation, user or internal position and test lateral movement, privilege escalation, segmentation, administrative paths and access to sensitive systems. The result shows the blast radius of an internal foothold.
View Internal Testing →Test authentication, authorisation, sessions, business logic, file handling, input processing and sensitive-data exposure across public and authenticated application functions. Multiple user roles can be included to validate real access boundaries.
View Web Application Testing →Assess REST, GraphQL or other application interfaces for authentication, object-level authorisation, privileged functions, data exposure, workflow abuse and unsafe server-side trust. Request-level evidence is provided for development teams.
View API Testing →Assess corporate, guest and operational wireless networks, authentication, encryption, onboarding, client isolation, segmentation and the systems reachable after connection. Wireless and internal testing can be combined for a full post-connect compromise scenario.
View Wireless Testing →Test credential exposure, privilege escalation, delegation, trust relationships, service identities and administrative paths that can turn one compromised account into broader control of the environment.
View Identity Testing →Assess iOS and Android application security including local storage, tokens, transport security, platform permissions, deep links, application trust and supporting APIs. Mobile and API testing can be combined for end-to-end coverage.
View Mobile Testing →A realistic compromise can move across more than one attack surface. An external weakness may provide a foothold, an identity path may provide privilege, segmentation may fail, and an internal service may provide the final access to sensitive systems. Damocles can combine selected testing services under one authorised engagement where that broader question matters.
The combined scope still names the individual test types, target sets, identities and boundaries so the customer knows what was covered. This prevents a broad “penetration test” label from hiding gaps in web, API, wireless, identity or internal testing.
Assess the public perimeter and then model what an attacker could do after gaining an internal foothold or credential.
Test the customer-facing application and its server-side interfaces together across roles, objects and business workflows.
Combine host, service and segmentation testing with Active Directory and privilege attack paths.
These services examine code, architecture, cloud trust and implementation detail where the customer needs root-cause assurance and engineering-ready remediation.
Review authentication, authorisation, tenancy, business logic, sensitive-data handling, secrets, cryptography, logging and security-sensitive code paths. Findings reference the affected design or implementation so developers can correct the root cause.
View Secure Code Review →Assess cloud identity, privilege, landing zones, network exposure, data, workloads, secrets, logging, monitoring, backup and recovery against the intended architecture. The customer receives immediate fixes and a structural improvement roadmap.
View Cloud Security Review →Use Guardian Katana for recurring or separately scoped active website and API assessment, evidence, findings and rescans where the customer needs ongoing application assurance beyond a once-off penetration test.
Explore Katana →Managed services define the protected estate, expected data sources, service coverage, analyst or policy responsibilities, customer/MSP ownership, exceptions and reporting. Monitoring coverage does not by itself imply authority to isolate endpoints, disable identities or make production changes.
Source onboarding, source-health monitoring, alert triage, investigation, escalation, action tracking and service reporting with explicit boundaries for customer/MSP ownership, containment authority, incident response and remediation engineering.
View Managed Security Operations →Turn asset and vulnerability data into prioritised remediation with ownership, due dates, exceptions, evidence and resolution review. The service focuses on removing exposure rather than delivering recurring scanner exports.
Explore Vulnerability Management →Operate endpoint protection, operating-system patching, supported application patching, maintenance windows, restart state and exceptions across the agreed endpoint estate.
Explore Endpoint Protection →Operate managed DNS security policy, malicious-destination blocking, identity context, exception handling and investigation follow-up for the approved users and devices.
Explore DNS Protection →Operate and tune web-application firewall policy for approved applications, including change handling, attack visibility, exception control and customer follow-up through Guardian.
Explore Svalinn →Put Damocles analysts behind compatible monitoring and protection sources for triage, investigation, escalation, action tracking and service reporting.
Explore Aegis →Damocles network security work can be a focused review, an architecture or migration design, or hands-on implementation support. Each governed review publishes its technical coverage and evidence model separately from any implementation work.
Review zones, rule purpose, source and destination scope, services, applications, NAT, administrative access, stale policy and risky exceptions against the intended architecture.
View Firewall Security Review →Assess trust zones, routing, firewall enforcement and management paths between user, server, cloud, OT, guest and restricted networks. Findings identify where the intended security boundary is not actually enforced.
View Network Segmentation Review →Review VPN and remote-access architecture, identity integration, MFA, certificates, pre-login, device trust, session controls and administrative access paths.
View Remote Access & VPN Security Review →Current-state discovery, target design, object and rule mapping, NAT and routing review, change sequencing, rollback planning, implementation support and post-change validation for firewall platform migrations.
View Firewall Migration & Implementation →Assess peer state, failover paths, upstream dependencies, routing behaviour, management access, maintenance design and recovery controls for critical network security infrastructure.
View Network Resilience & High Availability Review →Review authentication, management planes, logging, backups, firmware, SNMP, administrative access, configuration control and monitoring against the operational role of the device.
View Network Device Hardening Review →Review incident roles, escalation, evidence sources, containment authority, communications, external providers, recovery decisions and technical playbooks before an incident forces the organisation to improvise.
View Incident Readiness →Run an executive, technical or combined scenario that tests real decision paths, contacts, evidence, provider responsibilities, containment authority and recovery assumptions rather than simply reading the plan aloud.
View Incident Readiness →Design and implement approved configuration, segmentation, firewall, identity, endpoint, cloud or other security changes where the customer needs specialist delivery support after an assessment or incident.
Discuss remediation engineering →Penetration testing, code review, cloud review, network review and incident-readiness work are normally scoped around a defined environment and set of deliverables. The statement of work identifies the included targets, accounts, repositories, locations, working windows, evidence, briefing and retest or follow-up allowance.
Managed Security Operations and managed protection products use recurring quantities and service responsibilities such as endpoints, sources, ingestion, websites, protected applications, coverage hours, escalation and retention. Those commitments are confirmed in the relevant package or service schedule.
Where the customer needs implementation after an assessment, Damocles can scope remediation engineering separately so the original assurance work remains independent and the production change has its own design, approval, rollback and validation controls.
We will scope the specific penetration test, assurance engagement, managed service or engineering work required and make the technical coverage, evidence, responsibilities, deliverables and boundaries clear before the work begins.