Skip to content

Questions

Frequently asked questions

Questions that come up on pentest, offensive security and hiring calls. A direct answer, with a longer guide when the topic needs more room.

Compare

Pentest or offensive security

Both ideas show up in the same purchase email. They are not the same job. The right choice starts with the question you need answered, not the name that sounds more expensive.

Open the guide

Pentest

What is the difference between a vulnerability scan and a pentest?

A scan walks what is exposed and returns a list: CVE, a weak setting, an old version. It does not prove someone gets in. A pentest takes those candidates — and what the scanner missed — and tries to exploit. If it opens, the report has the path, the impact and what to close. If it does not, the alert is not a cover finding. Buying only a scan and calling it a pentest buys volume. A team that needs to decide a sprint needs the path.

Open the guide

Will a pentest take production down?

The test is controlled. We exploit to validate impact, not to become an incident. Critical production, hours and what is off-limits go into scope before the first request. A destructive payload outside the agreement is not part of the work. If the environment is too fragile for the window, the slice changes — staging, one module, one tenant. What does not change is writing the limit.

What has to be in a pentest report?

The problem title — not only the CVE. Preconditions. Steps the team can repeat without guessing. Impact on data, an account or a process. What to close first. A tool alert that did not hold is not a cover finding. A score alone does not prioritize a sprint. If one finding depends on another, that is explicit.

Open the guide

Offense

Does offensive security replace pentest?

No. Pentest covers a surface in depth: this application, this API, this tenant. Offensive security pursues an objective: an account, data, a system. If the main application has never been tested, starting with a mission exercise is usually early — the edge is still too open. Many companies use both in the same year, in different cycles. One package promising both on the same timeline delivers both halfway.

Open the guide

Does offensive security include social engineering?

Only if it is written in scope. Without explicit authorization, email, phone and QR codes stay out. The service name in the contract does not unlock that. When it is in, the rules say who can be targeted, what is never asked for (customer data, money) and how the exercise stops if a real incident appears. Physical access uses the same rule: authorized or out.

Do you tell the SOC during an offensive exercise?

Only if the rules of engagement say so. The defense can be blind — and we measure what slipped. The internal team can follow on the channel and watch the advance. Both formats exist. Mixing full surprise and a war room on the same day almost never works.

Cloud

Does cloud offense need an admin user?

It needs the agreed starting point: a read credential, a pipeline role, a standard user. Full admin is almost never required. The map is IAM — what that role can assume, what trust between accounts unlocks, what a function can reach on metadata. A CIS benchmark helps reconnaissance. It does not replace showing the path.

Does a startup with one cloud account qualify?

Yes. A small account with loose IAM is a common target: an access key from someone who left, a temporary role nobody removed, an open bucket in front of an API. Size is not the filter. Exposure is. The slice fits in a meeting. An enterprise pack pasted onto a startup does not.

AppSec

Do you need source code?

No. Source shortens the path: we find the function, the middleware, what the token carries. Without it, the work follows the surface and the behavior — the same IDOR shows up in the request. For deep AppSec, source helps. For a pentest of a live system, a test credential and the agreed environment are enough to start. Access is discussed after the slice, not in the first email.

Does an API with no UI count?

Yes. A large part of the attack lives in the API. The UI is a client. Authentication, IDOR, mass assignment, a webhook that trusts a header and what the token carries show up in the request, with or without a front end. Mobile is the same slice: the binary matters, the API behind it matters more.

Pricing

Is there a shelf price for pentest?

No. Without a slice there is no number. Surface, depth, window, production or staging, retest and whether the cycle is ongoing change the design. Anyone who locks a fee in the first email is selling a day pack. That can fit a tiny app. It almost never fits the environment that shows up on the call. The useful number exists after the system and what is at stake are on the table.

Open the guide

Process

Is the work one-off or ongoing?

Both. A single shot fits when the object is still: this release, this tenant. An ongoing cycle fits when the product ships every week and the cloud gains a role mid-quarter. Each cycle has a new slice — it is not the same test on autopilot. A retest of what was closed is in when you ask for it. Without a conversation after delivery, the PDF becomes a file.

Guides

Guides

Next step

Want to book a meeting?

Tell us the company size and what needs to be protected — the system, the environment, what is at stake. From the call, we assess the scenario and build the work within your scope.