// Section 01

Our Assessment
Methodology

We follow industry best practices, blending automated scanning with deep manual testing to uncover complex vulnerabilities.

// Method 01

Black Box

Simulating an external hacker attack without prior information about your system. The tester only knows the target URL and attempts to penetrate the system like a real-world attacker.

Core Benefits:
  • Real-world attacker perspective
  • Uncover vulnerabilities exposed to the public
  • Test your perimeter defense
  • Suitable for compliance requirements (PCI DSS, Security Audits)
BEST FOR: E-commerce, public-facing applications, websites with sensitive data
// Method 02

Grey Box

Testing with limited information such as standard user accounts. Simulating insider threat scenarios or an attacker who gained initial access to the system.

Core Benefits:
  • Balance between coverage and efficiency
  • Focus on privilege escalation
  • Find business logic flaws in business process
  • More time-efficient execution
BEST FOR: Web applications, SaaS platforms, internal systems
// Method 03

White Box

Comprehensive testing with full access to source code, documentation, and infrastructure. Includes code review and architecture analysis.

Core Benefits:
  • Most thorough coverage (including code-level vulnerabilities)
  • Detect logic bombs and backdoors
  • Code review for secure coding practices
  • Detailed remediation guidance
BEST FOR: Applications before production launch, fintech, healthcare
// Section 02

Scope &
Complexity Tiers

SIMPLE

Complexity Tier
Characteristics:
  • Static website or basic WordPress
  • 5-20 pages/endpoints
  • Minimal or no database interaction
  • Simple authentication (admin panel only)
  • No payment gateway
  • No API integration
  • Shared hosting or basic VPS
Scope:
  • OWASP Top 10 basic checks
  • Authentication testing
  • Input validation
  • SSL/TLS configuration
  • Basic information disclosure
Duration: 3-5 Days
Deliverables: Executive summary, Vulnerability report, Risk rating, Basic remediation steps.

MEDIUM

Complexity Tier
Characteristics:
  • Dynamic web application with database
  • 20-50 endpoints/pages
  • User authentication & role-based access
  • Form processing & file upload
  • Payment gateway integration
  • CRUD operations
  • REST API (basic)
Scope:
  • Full OWASP Top 10
  • Business logic testing
  • Session management
  • Authorization bypass attempts
  • API security testing
  • File upload vulnerabilities
  • Payment flow security
Duration: 5-7 Days
Deliverables: Executive summary, Detailed tech report, PoC, Risk matrix, Remediation roadmap.

COMPLEX

Complexity Tier
Characteristics:
  • Multi-tier architecture
  • 50-100+ endpoints
  • Complex user roles & permissions
  • Multiple API integrations
  • Real-time features (WebSocket)
  • Mobile app backend
  • Cloud infrastructure (AWS/GCP/Azure)
Scope:
  • OWASP Top 10 + API Security
  • Advanced business logic flaws
  • Race conditions
  • GraphQL/REST API deep testing
  • Third-party integration security
  • Mobile API security
  • Cloud misconfigurations
Duration: 7-12 Days
Deliverables: Exec summary, Detailed report, Attack narratives, Video PoC, CVSS scoring, Compliance mapping.
// Section 03

Client
Requirements

Required Preparation

  • Scope definition: Target URL/IP, In-scope subdomains, Allowed hours
  • Legal docs: Signed agreement, Auth letter, NDA
  • Emergency contact: Tech support (24/7), Escalation contact
  • Preparation: System backup prior to testing, IT team info

X NOT Required

  • User credentials
  • Source code
  • Documentation (Architecture, etc.)
  • Infrastructure details
// Section 04

Testing Process

Engagement Timeline
End-to-end Execution
PHASE 01

Pre-engagement

Kickoff meeting, scope finalization, legal agreement signing, access provisioning, and rules of engagement (2-3 days).

PHASE 02

Reconnaissance

Information gathering, asset discovery, attack surface mapping, and threat modeling (1-2 days).

PHASE 03

Active Testing

Vulnerability scanning, manual exploitation, business logic testing, privilege escalation attempts (3-15 days).

PHASE 04

Reporting

Vulnerability documentation, risk assessment, proof of concept creation, executive summary (2-3 days).

PHASE 05

Presentation

Findings presentation, Q&A session, remediation roadmap discussion, and priority setting (1 day).

PHASE 06

Retest (Optional)

Verify fixes, regression testing, updated report, and security posture assessment (2-3 days).

// Deliverables & Add-ons

Value Added
Services

Sample Pentest Report

View a live example of our professional security audit report complete with Executive Summary, CVSS Severity Score, POC, and Remediation Guide.

DOWNLOAD PDF

Retest Service

Verify remediation effectiveness. Retesting exclusively for identified issues.

STATUS: Verification Included / Available On-Demand
// Why Choose Us

Our Competitive
Edge

Proven Track

10+ successful assessments, 0 data breach during testing, 98% client satisfaction.

Manual Focus

Manual testing (not just scanner), business logic focus, real-world attack scenarios.

Local Support

Indonesian & English reporting, local business hours, on-site meeting available.