>| P:\ENETRATION\TESTING\
Authorised offensive work against an agreed scope. External, internal, or assumed-breach. Networks, web, APIs, cloud, and identity. A written report with evidence and reproduction. Retest on request.
- >| E:\XTERNAL\INTERNAL\NETWORKS\
- >| W:\EB\API\CLOUD\
- >| I:\DENTITY\PATHS\
- >| A:\SSUMED-BREACH\
>| R:\EVERSE\ENGINEERING\
Authorised analysis of mobile applications and the binaries behind them. Static and dynamic. Findings written so engineering can act.
- >| A:\NDROID\APK\DEX\NATIVE\
- >| I:\OS\IPA\OBJECTIVE-C\SWIFT\
- >| P:\ROTOCOL\API\RECONSTRUCTION\
- >| O:\BFUSCATION\INTEGRITY\CHECKS\
>| A:\UDITS\
Review of design, source, and posture. Coordinated disclosure if a third party has to be told.
- >| A:\RCHITECTURE\DESIGN\
- >| S:\OURCE-ASSISTED\CODE\REVIEW\
- >| C:\LOUD\IDENTITY\POSTURE\
- >| D:\ETECTION\RESPONSE\
Nothing begins without a written scope. Work is logged. Client names are not published.