Black Ghost
Red Team · Offensive

Pentest.Manual, deep, no noise.

Penetration testing run by hand by senior operators, with automated tooling only in a supporting role. We map the real path an adversary would take to your critical assets and deliver reproducible evidence, prioritized by business impact.

Web · API · MobileNetwork · CloudManual-ledUnder NDA + SOW
Book scoping call Message us on WhatsApp
01 / WHAT WE TEST

Six surfaces. Scoped and priced per asset.

Standardized scopes. Custom scopes available on request.

Application Layer

Web Application

One web application: authentication, session, business logic and full OWASP Top 10 coverage.

Application Layer

API

REST, GraphQL or SOAP. Authentication, authorization, rate limiting, schema introspection and business logic abuse.

Application Layer

Mobile App

iOS or Android. Static analysis, dynamic instrumentation, backend coverage and runtime manipulation.

Infrastructure

External Network

Internet-facing IP ranges, perimeter, VPN gateways and exposed admin panels. The attacker’s view from the outside.

Infrastructure

Internal Network

Active Directory, lateral movement, segmentation testing and domain escalation from an assumed foothold.

Cloud

Cloud Security Review

AWS, Azure or GCP. IAM policies, storage exposure, network segmentation, identity boundaries and secret hygiene.

02 / DEPTH TIERS

Three tiers. Same methodology, different intensity.

Calibrate depth to the maturity and risk of the asset.

Essential

Fast validation

Gray box approach, full coverage and one retest included. Ideal to validate a specific asset quickly.

Advanced

Extended depth

Black, gray or white box, threat modeling, extended business logic analysis and remediation support with your dev team.

Continuous

Recurring coverage

Testing throughout the year, unlimited retests and attestation letters for SOC 2, ISO 27001 or PCI.

03 / HOW WE RUN IT

From scope to retest. Every critical finding validated by hand.

01

Scoping & Rules of Engagement

We define scope, windows and limits before any package. Nothing starts without a signed SOW and Rules of Engagement.

02

Reconnaissance & modeling

Attack surface enumeration and threat modeling to prioritize the vectors that actually matter for your context.

03

Manual exploitation

Senior operators validate every vector by hand, with automated tooling serving as support to the process.

04

Post-exploitation

Privilege escalation, lateral movement and real impact assessment all the way to critical assets and data.

05

Report & readout

Reproducible technical document + one-page executive summary. Presentation call with the lead operator.

06

Retest

We confirm the fix worked. The retest is included in every engagement at no extra cost.

04 / WHAT YOU GET

Deliverables. Straight to what matters.

Technical report with evidence, reproduction steps and risk-prioritized recommendations.

One-page executive summary for the C-level and the board, ready to use with nothing to translate.

Readout session with the operator who ran the test.

At least one retest to validate the applied fixes.

Attestation letter for SOC 2, ISO 27001 or PCI (Advanced and Continuous tiers).

Findings integration with Jira, Slack or Linear where applicable.

05 / SPECIAL ENGAGEMENTS

Beyond standard pentest. Capabilities on demand.

Specialized scopes, quoted case-by-case after scoping.

Source Code Review

Manual + SAST, architecture-aware, to reach what a black box test cannot see.

IoT / Hardware Pentest

Firmware, radio, embedded systems and supply chain. From the bench to the device in production.

AI / LLM Security

Prompt injection, model abuse, data leakage and autonomous agent boundaries.

Ready to see the real path to your assets?

Book a 30-minute scoping call. We define the right scope together across web, API, mobile, network or cloud, with no sales theater.

Book scoping callWhatsApp