Aegis builds continuous penetration testing into the SOC: it probes WAN, LAN, web, VPN and DNS like a real attacker, with Rules of Engagement, a WORM ledger and a mandatory retest — every finding ends with evidence in the report (HR / EN / SR).
Defence is proven by attack. Aegis continuously probes your attack surface the way a real adversary would — with full authorisation and a record of every action.
Mapping the attack surface — host:port, DNS and neighborhood, with a quick risk assessment.
SQLi, IDOR, SSTI, LFI and upload-RCE plus JWT, API, GraphQL and CORS checks — real chains, not just scanning.
Enumeration and CVEs for WordPress, Drupal and others, with auth-bypass checks on ERP systems.
External and internal surface, with AAP attack-path analysis of where an attacker could reach.
Testing VPN gateways and remote access as common entry points.
A controlled load test of the application with graphs and auto-abort — never a real packet flood.
A pentest without evidence is an opinion. Aegis ties every finding to an immutable trail, a clear closing condition and a report an auditor understands.
Every engagement has signed rules, a scope and a signatory before the first action.
An immutable, append-only record of every action and finding for an irrefutable audit.
A critical finding stays open until a retest confirms the fix has actually been applied.
Attack-path analysis shows where an adversary would reach and which node to cut first.
Reports for the development team and for audit, in three languages.
Static code analysis as a complement to dynamic testing of the application.
The following example is fictitious and serves solely to illustrate the report structure.
MITRE ATT&CK: T1190 — exploitation of a public-facing application · CWE-89
Description: the search parameter is passed into an SQL query without proper parameterisation, which allows injecting conditions and reading data beyond its intended scope.
Evidence (redacted): GET /trazi?q=1%27-- returns a response confirming the injection; the full PoC chain is recorded in the ledger.
Recommendation: parameterised queries (prepared statements), input validation and least-privilege for the database.
Retest: mandatory — the finding remains in HARD-BLOCK status until the fix is confirmed by a retest.
Aggregated, anonymized and illustratively rounded production metrics.
Penetration testing (a pentest) is an authorised, controlled attack on your systems whose goal is to find and prove real weaknesses before an attacker exploits them.
RoE are the rules of engagement: scope, permitted methods, timing and contacts. Without a signed RoE and consent, there is no test — that is what separates a pentest from a real attack.
Scanning lists possible weaknesses; a pentest proves them. That's why it pairs with continuous vulnerability assessment — breadth plus depth. For entities under NIS2, a pentest is also proof that the measures are actually been tested.
Let us agree on the scope and Rules of Engagement, then show a pentest with proof: findings, the attack path and an audit-ready report.