Security · Penetration Testing
Find the gap before the attacker does
External and internal network, web application and wireless penetration tests; beyond vulnerability scanning, findings verified with real attack scenarios and a prioritized remediation plan.
Scope
External · Internal · Web · Wi-Fi
Methodology
OWASP · PTES
Verification
Free retest
A scanner lists; a penetration test proves
Automated scanning produces hundreds of findings; only a penetration test shows which can really be exploited. Sentinel tests are run under an authorized scope document with methods that do not affect production; every finding is reported with evidence, impact and remediation steps. Retesting after remediation is free.
Real attack scenarios
Vulnerability chaining, privilege escalation and lateral movement; not “open in theory” but “we got this far”.
Actionable report
Executive summary, technical findings, evidence screenshots and step-by-step remediation advice.
Remediation verification
Free retest after fixes and a closure report.
Test types
Test areas chosen in the scope document
External network penetration test
Internet-facing systems, VPN, e-mail, DNS
Internal network penetration test
Lateral movement, Active Directory, privilege escalation
Web application
OWASP Top 10, authentication, business logic
Wireless
WPA2/3, guest network isolation, rogue access points
Social engineering
Phishing simulation (optional)
Vulnerability scanning
Authenticated scans, false-positive filtering
Report and presentation
Separate presentations for management and the technical team
Retest
Verification after remediation, closure report
Process
From scope to closure report
Penetration test flow
Scope and authorization
Targets, rules, timing
Authorization letter
Written approval
Testing
Discovery, exploitation, evidence
Evidence
Impact demonstration
Report and retest
Remediation plan, verification
Tests are planned so as not to affect production; critical findings are reported immediately without waiting for the report.
OWASP · PTES · MITRE ATT&CK
Packages
Three packages by scope
Quick visibility
Vulnerability Assessment
Authenticated scan and a filtered report
By number of IPs / applications
Project based
- External and internal scan
- False-positive filtering
- Prioritized list
- Remediation advice
- Most popular
Standard
Penetration Test
External, internal and web application test
By scope
Project based
- Manual exploitation and chaining
- Evidence-based findings report
- Management and technical presentation
- Free retest
Ongoing
Annual Program
Two tests a year and quarterly scanning
Annual
12 months
- 2 penetration tests a year
- Quarterly vulnerability scan
- Phishing simulation
- Annual security posture report
Frequently asked questions
The most common questions about penetration testing
Risky tests (denial of service etc.) are excluded in the scope document; test hours and a communication channel are agreed in advance. Critical findings are reported immediately.
1 to 3 weeks depending on scope; the report is delivered one week after testing ends.
The report serves as the periodic test evidence requested in audits; the methodology and scope document are attached to the report.
Your own team or Sentinel (hardening service). The report is written clearly enough for a team to apply the remediation steps independently.
An NDA is signed, test data is stored encrypted and destroyed at the end of the project; the report is delivered only to the people you designate.
Free IT Health Check
See your infrastructure through a sentinel’s eyes.
Current state assessment, risk inventory and a prioritized roadmap. No commitment.