Required stack
필요 기술
Penetration TestingSecurity AuditWeb SecurityNetwork SecurityMobile SecurityOSINTSocial EngineeringRisk AssessmentVulnerability AssessmentBurp SuiteNmapMetasploitWiresharkNessusKali LinuxOWASP Top 10SANS Top 25LinuxReportingCVSS
Project brief
프로젝트 내용
Across my web applications, internal network infrastructure, desktop endpoints, company phones, and public social-media profiles, I need a full-scope security examination. The engagement must blend hands-on penetration testing with a structured security audit so that both technical weaknesses and policy gaps are captured in one clear deliverable.
Scope
• External and internal testing of web apps, network segments, desktops, mobile devices, and social-media assets
• Manual and automated discovery using industry-standard tools such as Burp Suite, Nmap, Metasploit, Wireshark, Nessus, Kali Linux, and OSINT/social-engineering toolkits
• Coverage of OWASP Top 10, SANS Top 25, common mobile attack vectors, and configuration hardening checks
Deliverables
• Comprehensive report linking every finding to CVSS, complete with screenshots, logs, and proof-of-concept exploits
• Executive summary for non-technical leadership and a prioritised remediation roadmap
• Post-test debrief (virtual) to walk through each issue and verify live exploitation where safe
• All artifacts supplied in both PDF and editable formats within the agreed timeline
Acceptance Criteria
• No critical or high finding may be a false positive
• Reproduction steps for each vulnerability must be provided and demonstrated during the debrief
• Testing must stay within the authorised scope and avoid service disruption
A mutual NDA and Rules of Engagement will be signed before work begins, and all data collected remains confidential. Let’s schedule the test window—after-hours or weekend slots are fine—to ensure minimal impact on daily operations and maximum visibility into our true security posture.
Scope
• External and internal testing of web apps, network segments, desktops, mobile devices, and social-media assets
• Manual and automated discovery using industry-standard tools such as Burp Suite, Nmap, Metasploit, Wireshark, Nessus, Kali Linux, and OSINT/social-engineering toolkits
• Coverage of OWASP Top 10, SANS Top 25, common mobile attack vectors, and configuration hardening checks
Deliverables
• Comprehensive report linking every finding to CVSS, complete with screenshots, logs, and proof-of-concept exploits
• Executive summary for non-technical leadership and a prioritised remediation roadmap
• Post-test debrief (virtual) to walk through each issue and verify live exploitation where safe
• All artifacts supplied in both PDF and editable formats within the agreed timeline
Acceptance Criteria
• No critical or high finding may be a false positive
• Reproduction steps for each vulnerability must be provided and demonstrated during the debrief
• Testing must stay within the authorised scope and avoid service disruption
A mutual NDA and Rules of Engagement will be signed before work begins, and all data collected remains confidential. Let’s schedule the test window—after-hours or weekend slots are fine—to ensure minimal impact on daily operations and maximum visibility into our true security posture.