SecureBlockLog inStart a pentest
Methodology

Depth you can audit. Not just claim.

Every engagement follows OWASP WSTG, PTES, and NIST SP 800-115, executed by testers holding OSCP, CREST, and OSCE credentials. Here is how we work, phase by phase.

Standards

The frameworks we execute against.

Not a marketing checkbox. Every applicable check from every listed standard is performed and traceable in the report.

OWASP WSTG

Web Security Testing Guide is the backbone of every web-app engagement — every applicable check is executed and documented.

OWASP MASVS

Mobile Application Security Verification Standard drives our iOS and Android practice, covering all L1 and L2 controls.

PTES

Penetration Testing Execution Standard structures the engagement phases from pre-engagement through post-exploitation.

NIST SP 800-115

NIST guide to technical assessment shapes our reporting format and evidence documentation practice.

MITRE ATT&CK

Every red team technique is mapped to an ATT&CK tactic and technique ID so your blue team can align detections.

CIS Benchmarks

Cloud configuration reviews are baselined against the relevant CIS Benchmark for AWS, Azure, and GCP.

Engagement phases

Eight phases, every engagement, every time.

Same rigour whether you are testing one web app or twenty.

01

Pre-engagement

Mutual NDA, scope confirmation, credential exchange via secrets manager, engagement letter, shared Slack channel.

02

Reconnaissance

Passive OSINT plus active enumeration to map every endpoint, role, integration, and reachable service before touching an exploit.

03

Threat modelling

Assets ranked by business impact. Attack paths hypothesised against your architecture before testing prioritises them.

04

Vulnerability identification

Manual review supported by targeted automation. Every finding gets validated by a second engineer before it lands in the report.

05

Exploitation

Confirmed exploitability, end-to-end. Business logic chains and multi-step abuse cases where they apply — not just proof-of-concept payloads.

06

Post-exploitation

Where scoped and consented: lateral movement, privilege escalation, and data-access proofs demonstrate real impact.

07

Reporting

Executive summary, full technical report with CVSS, evidence artifacts, remediation guidance, and framework-specific packs.

08

Retest

Once fixes ship, testers verify each finding and reissue the report with an updated status log. Included within 90 days.

Methodology

Depth you can audit, not just claim.

Every engagement follows OWASP WSTG, PTES and NIST SP 800-115, executed by testers who hold OSCP, CREST CRT or OSCE.

OWASP WSTGPTESNIST SP 800-115MITRE ATT&CK
Day 0
Kickoff call

Scope confirmed, credentials exchanged, NDA in place.

Day 1–10
Active testing

Manual testing. Confirmed findings published as they land.

Day 12
Report delivered

Evidence-ready report with remediation per finding.

Within 90 days
Free retest

We verify your fixes and reissue the report.

app.secureblock.com/projects/acme-corp-web/findings/sb-01
Projects/Acme Corp/Vulnerabilities/Horizontal IDOR — invoices
Horizontal IDOR on /api/v2/invoices/{id}
Description

An authenticated user can access invoice records belonging to other tenants by substituting their own resource identifier in the URL path. The ownership check is absent server-side — the API returns data for any valid integer ID regardless of the caller's tenant.

Steps to reproduce
  1. 1. Authenticate as Tenant A. Retrieve any invoice: GET /api/v2/invoices/1842
  2. 2. Replace the ID with a known Tenant B value: GET /api/v2/invoices/1843
  3. 3. Server returns 200 OK with Tenant B billing data.
Impact

Complete tenant isolation bypass. Any authenticated user can enumerate and exfiltrate invoice data, payment terms, and line items for every customer in the system.

Vulnerability context
Risk
critical9.1
Target
api.acme.com
Day 2 of 10
Status
Open
Created by
M. Kovač
OSCP · 14 Jan 2026
Affected asset
/api/v2/invoices/{id}
Testers

Who actually shows up on your engagement.

Certifications are the floor, not the ceiling. Every SecureBlock tester holds these credentials at minimum.

OSCP
Offensive Security Certified Professional

Hands-on offensive certification requiring a 24-hour practical exam. Baseline for every SecureBlock tester.

CREST CRT
CREST Registered Tester

Independent industry credential recognised by regulators in the UK, EU, and Australia.

OSCE
Offensive Security Certified Expert

Advanced exploitation credential held by senior testers who lead complex engagements and red team exercises.

OSWE
Offensive Security Web Expert

Web-focused advanced credential held by the leads on our web/API practice.

Read the methodology in a real engagement.

Every SecureBlock report opens with a methodology section referencing the specific standards used on that engagement.