Our approach
A rigorous methodology, concrete results.
Our penetration tests combine human expertise and targeted automation to cover your entire attack surface, from scoping to reporting.
Framework & resources
Grey Box approach
Access to client-provided information and test accounts (roles, API documentation, authentication schema, architecture). The objective is to maximise functional coverage and test depth while remaining within a realistic attack framework.
Mobilised resources
2 experts over 6 working days (~12 man-days). Typical breakdown: in-depth manual testing, targeted automation, analysis and reporting.
OWASP framework
Tests structured according to OWASP WSTG and Top 10 categories (reconnaissance, session, auth, authorisations, injections, business logic, config). Extension possible on LLM/AI attacks if the target includes such features.
What is Grey Box?
Our penetration tests use a Grey Box approach: you provide us with test accounts and some architecture information. Not too much, not too little, just enough to simulate a realistic attacker.
- Multi-role coverage, Testing across profiles (user, manager, admin…) reveals authorisation flaws, often the most critical in web contexts.
- Business logic tested, Knowledge of workflows enables testing of business rule bypasses, impossible with a pure Black Box approach.
- Maximum efficiency, Less time lost on blind discovery, more time allocated to high-value tests.
Pentest walkthrough
Scoping & preparation
Validation of the scope (URLs, subdomains, environments), exclusions and constraints. Setting up Grey Box access and the test plan.
- Scoping form
- Role-based test accounts validated before start
Mapping & reconnaissance
Building an exhaustive view of the attack surface: pages, endpoints, flows, roles and components. Identification of technologies, authentication mechanisms and open-source intelligence leaks.
- Endpoint inventory
- Fingerprinting
- Auth analysis
- OSINT / dark web check
Security testing
In-depth manual tests and targeted automation across the full OWASP spectrum: authentication, authorisations, injections, XSS/CSRF, business logic, configuration and, where applicable, AI attacks.
- Auth & session
- Access control (IDOR/BOLA)
- Injections
- XSS/CSRF/CORS
- Files & uploads
- Business logic
- Config & deployment
- AI testing (LLM)
Consolidation & risk assessment
Validation of findings: reproducibility, impact, prerequisites and realistic exploitation scenarios. False positive elimination, root-cause grouping, scoring and prioritisation.
- Verified reproducibility
- False positives eliminated
- Criticality scoring
Reporting & deliverables
Closing meeting presenting results, top risks, quick wins and structural recommendations. Delivery of a detailed executive and technical report.
- Executive summary
- Technical report (vulnerabilities, evidence, recommendations)
- Optional retest
Frequently asked questions
What you need to know before starting
What is a penetration test?
A penetration test (pentest) is an authorised simulated cyberattack performed by cybersecurity experts. The goal is to identify exploitable vulnerabilities before a real attacker does, then provide a clear and prioritised remediation plan.
How long does a pentest take?
Duration depends on scope. A standard web application pentest typically takes 5 to 10 working days. A network infrastructure test is often scoped at 5 to 15 days. We define the appropriate duration together during the initial scoping phase.
What is the difference between black box, grey box and white box testing?
In black box testing, experts have no prior information about the target. In grey box, our default approach, test credentials and limited access are provided to maximise functional coverage. In white box, source code and full technical documentation are shared.
Do I need to notify my cloud provider before a pentest?
Yes, some providers (AWS, Azure, OVH…) require prior notification for security tests on their infrastructure. We guide you through this process systematically during the scoping phase.
How does a penetration test actually work?
An engagement is broken into four phases. First, scoping: defining the perimeter, rules of engagement and required accesses. Then reconnaissance and exploitation: our experts follow recognised methodologies, including the OWASP Top 10 for web applications, to map the attack surface, identify vulnerabilities and exploit them in a controlled manner. Next, report writing: an executive deliverable summarising the risks and a technical deliverable detailing each vulnerability with its CVSS severity score and remediation steps. Finally, an optional retest to verify that the fixes have been correctly applied.
Ready to test your application?
Our experts define the scope with you and provide a quote tailored to your needs.