Penetration testing

Black-box penetration testing

Give us a single domain, URL or IP address. We find the assets an attacker would find from that starting point, then test every one of them with non-destructive exploitation.

How it works

From one address to your full attack surface

A black-box test starts where a real attacker starts: with no inside knowledge of your environment. You provide one starting point and your authorisation to test.

Phase 1 · Discovery

Find what an attacker would find

We research and scan outward from your starting point to map the domains, hosts, services and applications connected to your organisation, including the forgotten and unmanaged assets that rarely appear in an internal inventory.

Phase 2 · Testing

Test everything we find

Every confirmed asset is scanned thoroughly and put through non-destructive exploitation, so you see what an attacker could actually achieve, not just what a scanner reports. Where one weakness opens a path to another, we follow it within the agreed scope.

What we test

Where we look

We confirm discovered assets with you before active testing, so only systems you are authorised to test are in scope.

  • Domains and subdomains linked to your starting point, from passive OSINT and active enumeration
  • IP ranges, hosts and open services across every discovered asset
  • Forgotten and unmanaged assets, such as legacy, staging and test systems left exposed
  • Web applications and APIs, tested for authentication, access-control, injection and business-logic flaws
  • Exposed management interfaces and default or weak credentials
  • Known-vulnerable and end-of-life software, plus TLS and configuration weaknesses
  • Attack paths between assets, where one weakness gives access to another

How an engagement runs

Scope. Test. Report.

  1. 01

    Scope

    We agree targets, rules of engagement and reporting requirements before any testing starts.

  2. 02

    Test

    Harness-driven, AI-accelerated testing across the agreed scope, run on our own local hardware. No denial-of-service or destructive techniques, and no client data leaves for a commercial AI.

  3. 03

    Report

    An ISO/IEC 27001:2022-aligned report with prioritised findings, evidence and remediation guidance.

What you receive

A report you can act on and audit against

  • An inventory of discovered assets: what an attacker can see from the outside
  • Executive summary written for decision-makers
  • Every finding rated with a CVSS 3.1 score and clear business impact
  • Reproduction steps and evidence for each finding
  • Short-term mitigation and long-term fix for every issue
  • ISO/IEC 27001:2022 control mapping on each finding
  • A remediation tracking & sign-off matrix for your security team
  • A retest to verify fixes and update each finding’s status

Ready to scope a black-box test?

Tell us your starting point and we’ll propose a scope.