Separate what is exposed from what becomes reachable.
The useful question is not simply which ports are open. Testing establishes what an unauthenticated external actor or an authorized internal starting point can reach, which trust boundaries hold, and where one condition enables the next.
SCOPE → DISCOVER → TEST → VALIDATE → REPORT → RETEST
Each boundary is tested independently, then examined as part of the complete path.
- 01EXTERNAL
- 02PERIMETER
- 03IDENTITY
- 04INTERNAL
- 05OBJECTIVE
TRUST BOUNDARY / CONTROL EVIDENCE
ASSESSMENT BOUNDARY
What is being assessed?
The engagement boundary is defined by systems, identities, workflows and restrictions—not only a list of URLs or assets.
- Internet-facing systems, services and remote-access infrastructure
- Internal segments from agreed starting points
- Network appliances, management and administrative interfaces
- Authentication, credential exposure and known exploitable weaknesses
- Segmentation, trust relationships and service-to-service reachability
- Privilege escalation, lateral movement and Active Directory attack paths where applicable
What Botnet tests.
Testing is manual-led and supported by appropriate tooling. Findings are manually validated before reporting. Coverage follows reachable trust decisions and agreed risk; source-code review is not implied unless explicitly scoped.
External exposure
Reachable services, management surfaces and exploitable configurations across supplied ranges.
Authentication
Credential, protocol and access-control behavior within explicit safety limits.
Segmentation
Whether agreed network zones and management boundaries restrict movement as intended.
Service risk
Protocol configuration, exposed software behavior and practical exploit conditions.
Privilege path
Controlled validation from the starting identity or host toward agreed objectives.
Control visibility
Selected prevention and telemetry observations when control validation is included.
How the work progresses.
- 01
Partition
Confirm ranges, zones, ownership, test origin and fragile systems.
- 02
Discover
Map reachable services without implying disruptive load testing.
- 03
Analyze
Prioritize trust, identity and administrative paths.
- 04
Validate
Test selected conditions within the Rules of Engagement.
- 05
Connect
Document how exposures combine across network boundaries.
- 06
Close
Deliver evidence, remediation sequence and agreed re-test.
EVIDENCE + ACTION
What the customer receives.
- External and/or internal exposure map
- Validated technical findings
- Segmentation, Active Directory and privilege-path observations where applicable
- Reproducible evidence and affected assets
- Severity/risk context and prioritized remediation guidance
- Limitations, excluded systems and one re-test result for agreed remediated findings
Evidence over assumption.
01Paths prioritized over raw service inventory
02External and internal starting conditions kept explicit
03Production-aware safety boundaries
04Evidence separates reachability from inference
Before scoping.
Does testing include denial of service?
No. Availability or load testing is not implied and would require separate explicit scope and safeguards.
Can internal testing use an assumed foothold?
Yes, when the starting host, identity, access and permitted techniques are agreed.
Are credentials required?
That depends on the assessment mode. Credentialed and uncredentialed perspectives answer different questions and must be defined during scoping.
Define the target, constraints and required evidence.
An assessment request starts a scoping conversation. It does not authorize testing. Work proceeds only after scope acceptance, executed authorization/SOW and kickoff.