How we work
A repeatable, documented audit methodology.
Every VIROXEN engagement follows the same six phases. Nothing is skipped, nothing is improvised, and every finding is traceable to a step in this process.
- Phase 01
Scoping & Rules of Engagement
Define assets, environments, windows, and legal boundaries before any test traffic is generated.
Activities
- Confirm in-scope domains, IP ranges, and APIs in writing
- Agree on test windows, rate limits, and out-of-band contacts
- Sign engagement authorisation and safe-harbour terms
Deliverable
Signed Rules of Engagement document.
- Phase 02
Reconnaissance & Attack Surface Mapping
Enumerate every reachable asset associated with the target — nothing tested is assumed.
Activities
- Passive OSINT, DNS, and certificate transparency review
- Subdomain, port, and service enumeration
- Technology fingerprinting and version inventory
Deliverable
Attack surface inventory with ownership mapping.
- Phase 03
Automated Analysis
Run structured tooling against the inventory to surface known-class issues at coverage.
Activities
- Authenticated and unauthenticated vulnerability scanning
- TLS, header, and configuration compliance checks
- Dependency and SBOM analysis for known CVEs
Deliverable
Raw findings queued for manual verification.
- Phase 04
Manual Testing & Exploitation
Verify every finding by hand and hunt for business-logic and chained issues automation cannot see.
Activities
- OWASP Top 10 and ASVS Level 2 test cases
- Authentication, authorisation, and session boundary testing
- Business logic, IDOR, race condition, and workflow abuse tests
- Proof-of-concept exploitation within Rules of Engagement
Deliverable
Verified findings with reproduction steps and evidence.
- Phase 05
Risk Scoring & Reporting
Translate technical findings into decisions engineering and leadership can act on.
Activities
- CVSS 3.1 base, temporal, and environmental scoring
- Business-impact statement per finding
- Prioritised remediation guidance mapped to owners
- Executive summary + full technical report (PDF)
Deliverable
Executive summary + technical report.
- Phase 06
Retest & Handover
Confirm fixes actually close the finding — not just the ticket.
Activities
- Free retest of remediated findings (plan-dependent)
- Fix-verification notes appended to the report
- Optional consultation on architectural follow-ups
Deliverable
Signed-off remediation report.