Penetration Testing Methodology
Consultant-led penetration testing. An approach that works.
Consultant-led penetration testing. An approach that works.
How we test
Testing phases
Standards and frameworks
Every engagement produces a written report delivered within two business days of testing completion. Reports are written for two audiences: the technical teams responsible for remediation, and the business stakeholders who need to understand the risk and sign off on remediation priorities.
Findings are tracked live in the Exploitr platform throughout testing, so your team can see what is being found without waiting for the report.

How engagements are delivered
Common questions
Our penetration testing services are CREST-accredited, and our methodology draws from:
OWASP Web Security Testing Guide (WSTG) and OWASP API Security Top 10 for application testing
NIST SP 800-115 and the Penetration Testing Execution Standard (PTES) for network and infrastructure testing
MITRE ATT&CK framework for adversary technique selection and findings mapping.
For mobile application testing, we reference the OWASP MASVS.
We also take into account NCSC guidance on penetration testing for engagements delivered to UK organisations.
All testing is manually led. Automated tools are used selectively, for example for large-scale parameter fuzzing or directory enumeration, but every finding is reviewed and validated by the consultant. Business logic flaws, authorisation vulnerabilities, and chained attack paths are identified with the human analysis that automated tools cannot replicate.
You will not receive a repackaged vulnerability scan.
The core principles are consistent across all service types: manual, intelligence-driven testing by an in-house consultant, with a fixed price confirmed before work begins. The specific frameworks and test cases are applied depending on what is in scope.
For web application testing, we follow the OWASP WSTG. For API testing, the OWASP API Security Top 10. For network and infrastructure, NIST SP 800-115 and PTES. For mobile applications, the OWASP MASVS. See the services overview for a full breakdown by service type.
These terms describe how much information is shared with the tester before the engagement begins.
Black-box (or closed book) testing simulates an external attacker with no prior knowledge of your environment. Grey-box testing provides the tester with partial information, typically credentials or access as an authenticated user. This is the most common approach for web application and API assessments. White-box (aka. transparent or open book) testing gives the tester full access to source code, architecture documentation, and credentials.
For a full comparison and guidance on which approach to choose, see the services FAQ.
Scoping happens during the initial conversation, by call or by email. We ask about the systems or applications that are to be tested, their complexity, any compliance context, and your objectives. From that we produce a fixed-price written proposal that confirms the targets that are in scope, the methodology and approach that will be applied, the deliverables that you will receive, and the wider rules of engagement like any testing windows or exclusions.
For more detail on how scoping typically works in practice, see our articles on scoping a web application assessment and scoping a network penetration test.
Critical findings are escalated to your named technical contact the same day they are discovered, and are not held until the report is delivered. This gives your team the option to begin remediation before the testing window closes, where we can re-test the findings there and then.
You can also view any findings in real time throughout the engagement via the Exploitr platform.
We do not use AI tools to perform penetration testing. Our methodology is based on manual, intelligence-driven testing by experienced consultants.
While AI can assist in certain tasks, it cannot replace the nuanced analysis and decision-making required to identify complex vulnerabilities and business logic flaws. See our AI policy for more information.