PENTESTBOX

Offensive Security and Penetration Testing

Our licensed testers attack your estate by hand, then help your team close what they find.



Who tests

Our testers hold GPEN and CISSP, and Provintell holds NACSA licensing for penetration testing in Malaysia. A person runs your engagement.

What we test

  • Web and API Applications, endpoints, auth flows
  • Mobile iOS and Android
  • Network Internal and external infrastructure
  • Cloud AWS, Azure, Google Cloud configuration
  • Red team Exercises against your detection capability
Automated scanning gives us coverage. The findings that change your risk come from a tester chaining two weaknesses together that no scanner connects.

How an engagement runs

  1. Scope

    We agree what is in scope with your team, and what is explicitly out. Targets, environments and any system too fragile to touch during business hours.

    Nothing tested by surprise

  2. Rules of engagement, in writing

    Test window, escalation contacts, what we stop for and who we call. Signed before anyone touches a target.

    Signed before we start

  3. Test

    A NACSA-licensed tester holding GPEN and CISSP runs your engagement by hand, inside the agreed window.

    A person, not a scan report

  4. Findings as we confirm them

    You get each finding when we verify it, so your engineers can start fixing before the report lands. Anything critical reaches you the same day by phone.

    Critical findings, same day

  5. Report

    The exploit path step by step, what it gave us, and what closes it. Written for the engineer who has to fix it.

    Reproducible, not just scored

  6. Retest, then feed it back

    We retest once your team has remediated. Confirmed exploit paths go into your CodeRed ASM picture and into our detection coverage for your estate.

    The next attacker meets an alert

Drawing it against a retainer

Penetration testing and red teaming can also be drawn against CodeRed IR service credits, if you hold that retainer.

Ask for a quotation

Give us the counts for what you want tested. Approximate numbers are fine at this stage. Request a PENTESTBOX quotation.