Our penetration testing process.
Built on PTES — the Penetration Testing Execution Standard — and run by human engineers, not a scanner with a report template. Here's what actually happens during a NaviSec engagement, phase by phase.
Every NaviSec penetration test moves through five phases. We don't skip straight to exploitation, and we don't stop at "found a vulnerability" — each phase builds on the last, the same way a real attacker's campaign would, so the final report reflects genuine business risk instead of a raw scanner output.
OSINT & Passive Recon
Before we ever touch a live system, we map what's already visible about your organization from the outside — domains and subdomains, exposed services, technology stack, employee and email exposure, and credentials that may already be circulating from past breaches. Nothing in this phase alerts your defenders; it's built entirely from public-record and open-source intelligence, the same starting point a real attacker would use.
Active Recon
This is where we start engaging the environment directly — enumerating live hosts, ports, and services; crawling and mapping web applications; fingerprinting frameworks and CMS platforms; auditing access controls. The goal isn't a vulnerability scan printout, it's a real target list our engineers understand well enough to attack manually in the next phase.
Exploitation
NaviSec is deliberately not a run-a-scanner-and-report shop. Our engineers manually chain findings into proven access the way a real adversary would — on web applications that means things like SQL injection, server-side template injection, XSS, XXE, and authentication bypass; on networks and Active Directory it means credential attacks and privilege paths that automated tools alone consistently miss. Tools accelerate the work; techniques, tactics, and procedures decide the outcome.
Post-Exploitation
Getting a foothold isn't the finish line — it's where we find out what that foothold is actually worth. Can we escalate privileges? Move laterally? Reach the data or systems that matter to your business? This phase is what turns a list of vulnerabilities into a real answer to "what could an attacker actually do to us." Every action stays inside the rules of engagement agreed to before testing starts, so nothing we do causes real harm.
Report Writing
Every engagement ends with a hand-crafted report, not an auto-generated scanner printout — a plain-English executive summary alongside full technical detail and proof-of-concept for every finding. It goes through internal QA before delivery, and you get a review call with the engineer who actually did the work to walk through findings and answer questions directly.
No travel required — same depth of testing.
Most internal engagements don't require anyone on-site. NaviSec built a lightweight, purpose-built appliance your team deploys in minutes — no VPN headaches, no shipped hardware in most cases — that gives our engineers secure remote access with the same fidelity as a tester sitting in your server room.
- Deploys in minutes on VMware, VirtualBox, Hyper-V, or in-cloud
- No compromise on internal testing depth or coverage
- No travel cost, no scheduling around flights
Where this fits in the engagement.
The five phases above are what happens during testing. The full engagement — from first contact to your final report — follows a longer lifecycle: Pre-Engagement Contact → Quoting & Scoping → Assessment → Reporting → Delivery → AfterGuard Retesting (free within 90 days). See the Penetration Testing Buyer's Guide for the full breakdown, or the Types of Penetration Testing guide to figure out which kind of test fits your environment.
Process questions, answered.
Do you follow a specific methodology?
Do our teams need to be on-site for testing?
Is the exploitation phase automated?
What happens if you find something critical mid-test?
Get a real quote, not a guess.
Tell us what you need tested and we'll follow up with a scoped quote — no generic pricing, no surprises.
Get a Quote