SVC—03 · ASSESSMENT

Network and infrastructure penetration testing

Controlled exploitation of reachable infrastructure and identity paths within explicit operational boundaries.

Start scoping
NIST SP 800-115PTESMITRE ATT&CK 19.1PCI DSS 4.0.1 11.4 where applicable

TEST BOUNDARY

What sits inside the boundary

Active hosts, public IPs, sites, segments and trust boundaries
Directory services, VPN, remote access, management and lateral movement
Segmentation and scope-reduction controls where applicable

ACCESS MODES

Knowledge level is scoped

External
Internal
Assumed breach

DELIVERY—LEDGER

Deliverables you can inspect.

OUTPUT

Reachability and attack-path map

Exploitation evidence and root-cause analysis

Segmentation result and prioritized remediation

EFFORT—DRIVER

Active hosts, sites and segments

Identity forests and access prerequisites

On-site, clearance and testing-window constraints

EXPLICIT—LIMIT

No persistence, destructive change or service interruption without specific authorization

Third-party networks require written authority

POINT—IN—TIME

Precision includes what we do not claim.

A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.

Method and limitations

SCOPE—NEXT

Define the boundary before the fee.

Build a scope draft