Penetration testing

Test the controls that matter in practice.

Authorised testing combines structured methodology, manual expertise and appropriate tooling to identify exploitable weaknesses and explain what should happen next.

Testing scope

Engagements are tailored to the authorised environment.

EX

External infrastructure

Assess internet-facing services, perimeter controls and exposed attack paths.

IN

Internal infrastructure

Review internal attack paths, segmentation, privilege and lateral movement within agreed safety constraints.

WA

Web applications

Test authentication, authorisation, business logic, input handling, session security and common application weaknesses.

AP

APIs

Assess identity, object-level authorisation, data exposure, rate controls, abuse cases and implementation flaws.

WI

Wireless

Review authorised wireless security, segmentation and access controls where included in scope.

RT

Retesting

Verify remediation and document remaining or accepted exposure.

Engagement lifecycle

Clear authority and safe execution from start to finish.

01

Scope

Define targets, exclusions, credentials, timing and safety controls.

02

Prepare

Confirm contacts, escalation paths and technical prerequisites.

03

Test

Execute approved manual and tool-assisted techniques.

04

Validate

Confirm exploitability and preserve proportionate evidence.

05

Report

Explain impact, priority, remediation and affected context.

06

Retest

Verify closure and update the outcome.

Reporting standard

Findings should support action, not just prove that a scanner ran.

Reports are written for technical remediation and stakeholder decision-making. Material issues include evidence, affected scope, impact, likelihood, recommended remediation and verification guidance.

Compliance frameworks may inform scope or reporting, but Damocles does not claim that a penetration test alone creates compliance or certification.

Define the right penetration test

Scope the environment, assurance objective and testing constraints.

We will confirm the appropriate method, access model, reporting and retest requirements.