Samen Steeve
MY SERVICES.
Back to services

Services

Security Audit & Pentest

You don't need a simple automated scan. You need a clear picture of your actual exposure, your weaknesses, and the most credible attack scenarios in your context. Most serious incidents don't start with a spectacular attack — they start with a misconfiguration, an overly broad access, a forgotten permission. I assess your systems across three axes: external exposure analysis, penetration testing (internal infra, application web/API/mobile, OWASP) and cloud audit (AWS, Azure, GCP). Every engagement is scoped based on your organization, your security maturity and your business priorities.

When it is relevant

Audit before launching an exposed application or one handling sensitive data (healthcare, finance, HR)

Discuss this service

Expected outcomes

A clear picture of your actual exposure: exploitable vulnerabilities, their severity and operational scope — not a raw scanner dump.

Exploitation evidence understandable by leadership to decide fast, and actionable by your technical teams to fix effectively.

A remediation plan prioritized by business impact order, with concrete and structured recommendations.

A retest report to confirm fixed vulnerabilities are no longer exploitable and reduce residual risk.

Engagement scope

External exposure: services, interfaces and configurations visible from the Internet — IP/domain scanning, service mapping, manual exploitation of sensitive targets.

Internal systems: simulating an attacker with network access (compromised VPN, Wi-Fi, physical access) — Active Directory mapping, privilege escalation, access to sensitive data.

Web apps, REST/GraphQL APIs and mobile apps (Android/iOS): authentication flows, high-impact routes (billing, admin, export) and business logic following OWASP.

Cloud environments (AWS/Azure/GCP): IAM configurations, exposed buckets, permissive firewall rules, secrets in environment variables — aligned with CIS benchmarks.

What you get (Deliverables)

  • Executive summary readable by leadership: overall risk level, priorities and recommended actions
  • Detailed technical report with findings, exploitation evidence and severity ratings
  • Remediation plan prioritized by business impact with concrete and actionable recommendations
  • Technical debrief workshop with your developers, IT team or vendors
  • Retest report after priority vulnerabilities are fixed

Typical Use Cases

  • Audit before launching an exposed application or one handling sensitive data (healthcare, finance, HR)
  • Security level validation before a client deployment, external audit or certification
  • Internal penetration test to assess risks from network access (employees, VPN, Wi-Fi, physical access)
  • Cloud configuration audit (AWS/Azure/GCP) to detect exposed attack surfaces and excessive permissions

FAQ

What is the difference between black box, grey box and white box testing?

In black box testing, the audit is conducted with no information provided — real-world attack conditions. In grey box, some access or information is provided, ideal for testing authenticated portals. In white box, the scope and internal elements are shared for a deeper analysis. I recommend grey box for most engagements.

Is the report understandable by leadership?

Yes. The executive summary is designed for a non-technical reader: overall risk level, priorities and recommended actions. The detailed technical report with exploitation evidence is intended for your developers and IT teams.

Do you perform cloud audits?

Yes, I audit AWS, Azure and GCP environments: IAM configurations, exposed services, open S3 buckets, permissive firewall rules, secrets in environment variables. The report includes recommendations aligned with CIS benchmarks.

Can a retest be done after fixes are applied?

Yes, and it is strongly recommended. The retest confirms that fixed vulnerabilities are no longer exploitable and reduces residual risk. It can be scheduled at report delivery or triggered after your remediation is complete.

We clarify your needs before selling a solution.

Describe the context, constraints, and what is blocking you today. I will reply with a concrete technical assessment.

Discuss this service