External infrastructure
Assess internet-facing services, perimeter controls and exposed attack paths.
Authorised testing combines structured methodology, manual expertise and appropriate tooling to identify exploitable weaknesses and explain what should happen next.
Assess internet-facing services, perimeter controls and exposed attack paths.
Review internal attack paths, segmentation, privilege and lateral movement within agreed safety constraints.
Test authentication, authorisation, business logic, input handling, session security and common application weaknesses.
Assess identity, object-level authorisation, data exposure, rate controls, abuse cases and implementation flaws.
Review authorised wireless security, segmentation and access controls where included in scope.
Verify remediation and document remaining or accepted exposure.
Define targets, exclusions, credentials, timing and safety controls.
Confirm contacts, escalation paths and technical prerequisites.
Execute approved manual and tool-assisted techniques.
Confirm exploitability and preserve proportionate evidence.
Explain impact, priority, remediation and affected context.
Verify closure and update the outcome.
Reports are written for technical remediation and stakeholder decision-making. Material issues include evidence, affected scope, impact, likelihood, recommended remediation and verification guidance.
Compliance frameworks may inform scope or reporting, but Damocles does not claim that a penetration test alone creates compliance or certification.
We will confirm the appropriate method, access model, reporting and retest requirements.