⚠ Experiencing a security incident right now? Urgent contact — (813) 321-2006 · Send urgent message
How we work

Our penetration testing process.

Built on PTES — the Penetration Testing Execution Standard — and run by human engineers, not a scanner with a report template. Here's what actually happens during a NaviSec engagement, phase by phase.

Every NaviSec penetration test moves through five phases. We don't skip straight to exploitation, and we don't stop at "found a vulnerability" — each phase builds on the last, the same way a real attacker's campaign would, so the final report reflects genuine business risk instead of a raw scanner output.

01

OSINT & Passive Recon

Before we ever touch a live system, we map what's already visible about your organization from the outside — domains and subdomains, exposed services, technology stack, employee and email exposure, and credentials that may already be circulating from past breaches. Nothing in this phase alerts your defenders; it's built entirely from public-record and open-source intelligence, the same starting point a real attacker would use.

Subdomain & DNS enumeration toolingBreach-data correlationTechnology & framework fingerprintingEmployee / email exposure mapping
02

Active Recon

This is where we start engaging the environment directly — enumerating live hosts, ports, and services; crawling and mapping web applications; fingerprinting frameworks and CMS platforms; auditing access controls. The goal isn't a vulnerability scan printout, it's a real target list our engineers understand well enough to attack manually in the next phase.

Nmap — port & service enumerationBurp Suite Pro & Nessus — web/external assessmentContent discovery & forced browsing toolingIDOR / CSRF / access-control auditing
03

Exploitation

NaviSec is deliberately not a run-a-scanner-and-report shop. Our engineers manually chain findings into proven access the way a real adversary would — on web applications that means things like SQL injection, server-side template injection, XSS, XXE, and authentication bypass; on networks and Active Directory it means credential attacks and privilege paths that automated tools alone consistently miss. Tools accelerate the work; techniques, tactics, and procedures decide the outcome.

SQLMap, Nikto & CMS-specific scanners — as leverage, not the whole testResponder, BloodHound, CrackMapExec, Impacket — AD & Windows attack pathsManual exploit development where off-the-shelf tooling falls short
04

Post-Exploitation

Getting a foothold isn't the finish line — it's where we find out what that foothold is actually worth. Can we escalate privileges? Move laterally? Reach the data or systems that matter to your business? This phase is what turns a list of vulnerabilities into a real answer to "what could an attacker actually do to us." Every action stays inside the rules of engagement agreed to before testing starts, so nothing we do causes real harm.

Privilege escalation & lateral movementCommand-and-control tooling for controlled, monitored accessBusiness-impact validation, not just proof-of-concept
05

Report Writing

Every engagement ends with a hand-crafted report, not an auto-generated scanner printout — a plain-English executive summary alongside full technical detail and proof-of-concept for every finding. It goes through internal QA before delivery, and you get a review call with the engineer who actually did the work to walk through findings and answer questions directly.

Hand-crafted executive + technical reportingProof-of-concept documentation for every findingFree retesting of remediated findings within 90 days
Remote-first, without losing fidelity

No travel required — same depth of testing.

Most internal engagements don't require anyone on-site. NaviSec built a lightweight, purpose-built appliance your team deploys in minutes — no VPN headaches, no shipped hardware in most cases — that gives our engineers secure remote access with the same fidelity as a tester sitting in your server room.

  • Deploys in minutes on VMware, VirtualBox, Hyper-V, or in-cloud
  • No compromise on internal testing depth or coverage
  • No travel cost, no scheduling around flights
The bigger picture

Where this fits in the engagement.

The five phases above are what happens during testing. The full engagement — from first contact to your final report — follows a longer lifecycle: Pre-Engagement Contact → Quoting & Scoping → Assessment → Reporting → Delivery → AfterGuard Retesting (free within 90 days). See the Penetration Testing Buyer's Guide for the full breakdown, or the Types of Penetration Testing guide to figure out which kind of test fits your environment.

Straight answers

Process questions, answered.

Do you follow a specific methodology?
Yes — PTES (the Penetration Testing Execution Standard) as our baseline, adapted into the five phases above. Want the fuller, standards-level breakdown? See our PTES methodology overview.
Do our teams need to be on-site for testing?
Almost never. Most engagements — internal and external — run fully remote, with the same depth and fidelity as if our engineer were sitting in your server room. There's no travel, no logistics, and no compromise on coverage.
Is the exploitation phase automated?
Automated tools inform the work, but exploitation itself is manual and human-led. That distinction is the difference between a vulnerability scan and a real penetration test — see why a $1,000 pentest isn't a pentest.
What happens if you find something critical mid-test?
We contact your designated point of contact immediately if we discover an extremely critical vulnerability, an active breach, or an insider threat — we don't sit on it until the final report.
Ready to scope one?

Get a real quote, not a guess.

Tell us what you need tested and we'll follow up with a scoped quote — no generic pricing, no surprises.

Get a Quote
// confidential · no obligation