How we work

A repeatable, documented audit methodology.

Every VIROXEN engagement follows the same six phases. Nothing is skipped, nothing is improvised, and every finding is traceable to a step in this process.

  1. Phase 01

    Scoping & Rules of Engagement

    Define assets, environments, windows, and legal boundaries before any test traffic is generated.

    Activities

    • Confirm in-scope domains, IP ranges, and APIs in writing
    • Agree on test windows, rate limits, and out-of-band contacts
    • Sign engagement authorisation and safe-harbour terms

    Deliverable

    Signed Rules of Engagement document.

  2. Phase 02

    Reconnaissance & Attack Surface Mapping

    Enumerate every reachable asset associated with the target — nothing tested is assumed.

    Activities

    • Passive OSINT, DNS, and certificate transparency review
    • Subdomain, port, and service enumeration
    • Technology fingerprinting and version inventory

    Deliverable

    Attack surface inventory with ownership mapping.

  3. Phase 03

    Automated Analysis

    Run structured tooling against the inventory to surface known-class issues at coverage.

    Activities

    • Authenticated and unauthenticated vulnerability scanning
    • TLS, header, and configuration compliance checks
    • Dependency and SBOM analysis for known CVEs

    Deliverable

    Raw findings queued for manual verification.

  4. Phase 04

    Manual Testing & Exploitation

    Verify every finding by hand and hunt for business-logic and chained issues automation cannot see.

    Activities

    • OWASP Top 10 and ASVS Level 2 test cases
    • Authentication, authorisation, and session boundary testing
    • Business logic, IDOR, race condition, and workflow abuse tests
    • Proof-of-concept exploitation within Rules of Engagement

    Deliverable

    Verified findings with reproduction steps and evidence.

  5. Phase 05

    Risk Scoring & Reporting

    Translate technical findings into decisions engineering and leadership can act on.

    Activities

    • CVSS 3.1 base, temporal, and environmental scoring
    • Business-impact statement per finding
    • Prioritised remediation guidance mapped to owners
    • Executive summary + full technical report (PDF)

    Deliverable

    Executive summary + technical report.

  6. Phase 06

    Retest & Handover

    Confirm fixes actually close the finding — not just the ticket.

    Activities

    • Free retest of remediated findings (plan-dependent)
    • Fix-verification notes appended to the report
    • Optional consultation on architectural follow-ups

    Deliverable

    Signed-off remediation report.

Ready to scope your engagement?

Share your targets and constraints — we'll come back with a fixed plan and timeline.