Penetration testing · offensive security

Penetration testing —
authorized, proven, repeatable

Aegis builds continuous penetration testing into the SOC: it probes WAN, LAN, web, VPN and DNS like a real attacker, with Rules of Engagement, a WORM ledger and a mandatory retest — every finding ends with evidence in the report (HR / EN / SR).

Every action authorized (RoE) WORM ledger — immutable trail Mandatory retest
What we test

We strike first — with permission

Defence is proven by attack. Aegis continuously probes your attack surface the way a real adversary would — with full authorisation and a record of every action.

Recon and discovery

Mapping the attack surface — host:port, DNS and neighborhood, with a quick risk assessment.

Web-app attacks

SQLi, IDOR, SSTI, LFI and upload-RCE plus JWT, API, GraphQL and CORS checks — real chains, not just scanning.

Multi-CMS and ERP

Enumeration and CVEs for WordPress, Drupal and others, with auth-bypass checks on ERP systems.

WAN and LAN

External and internal surface, with AAP attack-path analysis of where an attacker could reach.

VPN and access

Testing VPN gateways and remote access as common entry points.

L7 resilience test

A controlled load test of the application with graphs and auto-abort — never a real packet flood.

Boundaries and ethics: every run requires authorization (consent, a signer, Rules of Engagement). Phishing and DDoS are carried out only by explicit agreement — „DDoS“ is exclusively a controlled L7 resilience test with an auto-abort as soon as the target starts to degrade, never a real packet flood.
Evidence framework

A finding that stands up to audit

A pentest without evidence is an opinion. Aegis ties every finding to an immutable trail, a clear closing condition and a report an auditor understands.

RoE and consent

Every engagement has signed rules, a scope and a signatory before the first action.

WORM ledger

An immutable, append-only record of every action and finding for an irrefutable audit.

Hard-block until retest

A critical finding stays open until a retest confirms the fix has actually been applied.

AAP — attack path

Attack-path analysis shows where an adversary would reach and which node to cut first.

SARIF + PDF (HR/EN/SR)

Reports for the development team and for audit, in three languages.

Lab (SAST)

Static code analysis as a complement to dynamic testing of the application.

SAMPLE FINDING

What a single finding looks like

The following example is fictitious and serves solely to illustrate the report structure.

Illustrative example · anonymized Severity: HIGH

SQL injection in the search parameter

MITRE ATT&CK: T1190 — exploitation of a public-facing application · CWE-89

Description: the search parameter is passed into an SQL query without proper parameterisation, which allows injecting conditions and reading data beyond its intended scope.

Evidence (redacted): GET /trazi?q=1%27-- returns a response confirming the injection; the full PoC chain is recorded in the ledger.

Recommendation: parameterised queries (prepared statements), input validation and least-privilege for the database.

Retest: mandatory — the finding remains in HARD-BLOCK status until the fix is confirmed by a retest.

10.000+
pentest findings
5.300+
WORM ledger records
19.000+
cases processed
13.000+
detection rules

Aggregated, anonymized and illustratively rounded production metrics.

Basics

What penetration testing is

Penetration testing (a pentest) is an authorised, controlled attack on your systems whose goal is to find and prove real weaknesses before an attacker exploits them.

Rules of Engagement (RoE)

RoE are the rules of engagement: scope, permitted methods, timing and contacts. Without a signed RoE and consent, there is no test — that is what separates a pentest from a real attack.

Test phases

  1. Recon — mapping the attack surface (host, port, DNS, neighborhood).
  2. Exploitation — checking whether a weakness can actually be exploited.
  3. Post-exploitation — what an attacker would reach (attack-path).
  4. Report and retest — proof, recommendation and re-check after the fix.

How it differs from scanning

Scanning lists possible weaknesses; a pentest proves them. That's why it pairs with continuous vulnerability assessment — breadth plus depth. For entities under NIS2, a pentest is also proof that the measures are actually been tested.

Frequently asked questions

Penetration testing — frequently asked questions

Is every test authorized? +
Yes. Every run requires authorization — consent, a signatory and Rules of Engagement with a defined scope. Without them there is no test.
What is the WORM ledger and why does it matter? +
A WORM (write once, read many) ledger is an immutable, append-only record of every action and finding. It provides an indisputable audit trail and prevents results from being altered after the fact.
Do you perform a real DDoS attack? +
No. What we offer is a controlled L7 resilience test with presets and load graphs and an auto-abort as soon as the target starts to degrade. It is never a real volumetric packet flood.
Do I get a report I can show? +
Yes. Findings come as a SARIF and PDF report in Croatian, English or Serbian, with evidence, a recommendation and retest status — ready for audit and for the development team.
RELATED

Keep exploring the platform

Check your defences before an attacker does

Let us agree on the scope and Rules of Engagement, then show a pentest with proof: findings, the attack path and an audit-ready report.

Odgovaramo isti radni dan · info@aegis.hr