Services
Partners
Use cases
Clients
Company
Contact
FRENDE

Penetration testing (pentest)

Measure how your systems actually hold up by reproducing an attacker's behaviour — in a controlled, documented setting, with no impact on production. It is the offensive half of your cybersecurity programme, commonly called a pentest.

Offensive cybersecurity

Think like an attacker, without the risk.

We reproduce the full path of an attack — from the exposed surface through to your data — to reveal what a real adversary could actually reach.

ExternalInternalApplicationRed Team
Typical attack path in a penetration test ATTACK PATH Internetattack surfacePerimeterfirewall · VPNApplicationweb · mobileActive Directorylateral movement Dataobjective
Services

Services in detail

External penetration testing

Assessment of the perimeter exposed to the Internet: services, applications, information leaks and access paths from outside.

Internal penetration testing

Simulation of an attacker already on the network: lateral movement, privilege escalation and Active Directory compromise.

Application penetration testing

Web, mobile and thick clients assessed against OWASP (ASVS/MASVS): business logic, authentication, injection and access control.

Red Team & Purple Team

Objective-driven attack scenarios, with or without the defence team involved, mapped to MITRE ATT&CK, to test your cybersecurity end to end.

Industrial infrastructure & OT

ICS/SCADA environments assessed with an approach built around availability and safety constraints.

Embedded systems & IoT

Hardware and software analysis: debug interfaces, firmware, radio communications and proprietary protocols.

Artificial intelligence systems

LLM- and agent-based applications: prompt injection, exfiltration, guardrail bypass (OWASP LLM Top 10).

Code review

Static and manual source code analysis to fix vulnerabilities at the root, before they reach production.

What you get

Deliverables & approach

  • Report prioritised by real risk
  • Reproducible proof of exploitation
  • Actionable remediation plan
  • Technical and executive debriefs
  • Retest to confirm the fixes
Request a quote
Methodology

How a test unfolds

  1. 1
    Scoping
    Scope, objectives and rules of engagement agreed with you.
  2. 2
    Reconnaissance
    Mapping of the exposed surface and enumeration of services.
  3. 3
    Exploitation
    Confirmation of vulnerabilities and initial access.
  4. 4
    Lateral movement
    Privilege escalation and progression towards critical assets.
  5. 5
    Debrief
    Prioritised report, remediation plan and retest.
Frequently asked questions

Frequently asked questions

The risk is never nil, and pretending otherwise would be dishonest. It is framed: the rules of engagement set the scope, the working windows, the excluded actions — denial of service, altering data — and a reachable contact on both sides for the duration of the test. On the most sensitive environments, industrial or embedded, we favour a lab replica or a maintenance window. In practice, most of the work is observation and controlled exploitation.

Two readings of the same work. An executive debrief: what an attacker could reach, the business risk attached to it and the decisions to take. A technical part: each vulnerability with reproducible proof of exploitation, its context and its fix. Findings are prioritised by the real risk in your environment, not by a raw score. A retest then confirms the fixes hold.

A penetration test seeks coverage: within a given scope, find as many exploitable vulnerabilities as possible. A Red Team seeks an objective — reach this data, this system — by the quietest path, without warning the defence. The first measures your exposure, the second your ability to detect and react. A Red Team only makes sense once that ability exists: starting there means paying a lot to learn it is missing.

Let's talk about your scope.

A technical conversation, with no commitment, to frame your need and propose the most relevant engagement.