Home/Methodology
How we work

Our methodology

Every engagement runs through the same four-phase process, grounded in NIST, OWASP, and industry best practice — so results are repeatable, defensible, and directly actionable, and can support your compliance efforts.

The process
01

Information Gathering & Enumeration

The most crucial stage of the assessment. We learn everything we can about your environment — technologies in use, possible entry points, exposed services, and anything else publicly discoverable. What we find here is the baseline for every test that follows.

02

Vulnerability Detection

Using a hybrid of manual testing techniques and automated tooling, we identify candidate vulnerabilities across the full attack surface.

03

Analysis

Now it’s time to build a plan. Based on everything learned so far, we decide which attack vectors to pursue, prioritizing by likelihood and business impact — then begin targeted testing.

04

Exploitation & Leverage

Where the real work begins. A successful attack is almost always the result of chaining vulnerabilities together until the target is compromised. This is a circular process — issues are tested, exploited, and then leveraged to uncover more — repeating until the objective is achieved.

Aligned to NIST SP 800-115 PTES OWASP OWASP MASVS MITRE ATT&CK
02  /  The deliverable

A formal report you can act on.

We test your web applications, network hosts, APIs, and mobile applications, then walk your team through what we found. The report documents every finding with impact, reproduction, and prioritized remediation — and can be used to support compliance (PCI, HIPAA, and others) or best practice.

Every report includes
Executive summary, business-risk framed
Transparent risk-rating methodology
Detailed findings with reproduction & evidence
Strategic, root-cause recommendations
Remediation & retest tracking
03  /  What comes next

We stay with you through remediation.

Once testing wraps, we work closely with your team to make sure every issue is understood, and retest fixes to confirm they hold. The goal is simple: peace of mind that your team is applying secure practices correctly and effectively.

Get started

Put our process to work.

Tell us what’s in scope and we’ll come back with a plan, a timeline, and a fixed quote.

Contact Rarefied