Offensive security
Penetration Testing
Test realistic paths into the environment, demonstrate consequence safely and give the team evidence it can use to close the gaps.
The engagement
Prove which paths are exploitable
A vulnerability scan identifies possible weaknesses. A penetration test asks whether those weaknesses can be used together to reach a defined objective, cross a trust boundary or gain access that should not exist.
GDF testers work within written rules of engagement. They validate findings, preserve the evidence behind each result and stop at the level of impact authorized for the test. The report separates exploitable paths from isolated observations and includes a practical order for remediation and retesting.
Scope
External penetration testing
Controlled testing of internet-facing systems, exposed services and identity paths from an outside perspective.
Internal and assumed-breach testing
Validation of segmentation, privilege escalation, lateral movement and access to agreed objectives.
Identity and access testing
Testing of authentication, authorization, administrative paths, trust relationships and common identity attack chains.
Cloud attack-path testing
Review and controlled validation of permissions, exposure and administrative paths in supported cloud environments.
Detection validation
Safe activity designed to show what security controls and response processes can observe within the agreed scope.
Remediation retesting
Focused verification of corrected findings, with closure evidence suitable for technical and governance review.
Methodology
How the test runs
-
Frame
Agree objectives, safety boundaries, prohibited actions, contacts and evidence handling.
-
Discover
Map exposed and reachable attack paths using current information and controlled validation.
-
Demonstrate
Prove consequence only to the point authorized and necessary to support the finding.
-
Prioritize
Order remediation by path, exposure and consequence; retest the fixes that matter.
Evidence commonly examined
Evidence reviewed
- Rules of engagement and target inventory
- Validated request, response and command evidence
- Identity and privilege paths
- Network and segmentation observations
- Detection and response records
- Remediation and retest evidence
What you can expect
What you receive
- Executive risk narrative
- Technical findings with reproducible evidence
- Attack-path and consequence mapping
- Prioritized remediation plan and retest record
Frequently asked
Common questions
Is this the same as a vulnerability scan?
No. Scanning can inform discovery, but penetration testing validates conditions, combinations and consequence through controlled human analysis.
Can you test production systems?
Sometimes, under explicit rules designed for the environment. High-availability and OT systems may require passive, lab-based or tightly limited methods.
Do you guarantee no vulnerabilities remain?
No finite test can do that. We define the tested scope, period, methods and limitations so the result is not overstated.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189