// SERVICES

Offensive security services

Every Sentinel Point Systems engagement is scoped to your environment, your threat model, and your compliance obligations. We do not deliver a templated checklist of services pulled from a shelf.

Below is the full set of services we deliver. Most engagements combine two or more, sequenced to surface the highest-impact findings first. If you are not sure which combination fits your situation, schedule a scoping call and we will help you decide. We will tell you honestly when a service does not apply.

[ 01 ] EXTERNAL

External Penetration Testing

Identify what an internet-facing threat actor would discover and exploit against your perimeter.

An external penetration test simulates the perspective of a remote threat actor with no prior access. We assess everything an opportunistic or targeted threat actor could see and reach from the public internet, then attempt to gain initial access.

// WHAT WE TEST

  • Exposed services, ports, and protocols across your perimeter
  • Internet-facing web applications and login portals (M365, Citrix, VPN)
  • Password spraying and credential stuffing against authentication surfaces
  • Unpatched edge devices, VPN appliances, and firewalls
  • Sensitive information exposed via OSINT and reconnaissance
  • Email security posture (SPF, DKIM, DMARC) and phishing potential

// DELIVERABLES

Executive summary with risk narrative, full technical findings with CVSS scoring and reproduction steps, and prioritized remediation guidance. Post-assessment debrief call and retest of remediated findings included.

// WHO NEEDS THIS

Any organization with internet-facing infrastructure. Required by PCI-DSS (Requirement 11.3.1), expected by SOC 2 and ISO 27001 auditors, and a baseline for cyber insurance.

./read-the-full-breakdown →
[ 02 ] INTERNAL

Internal Network Penetration Testing

Assumed-breach assessment. What can a threat actor do once they have a foothold inside your network?

An internal penetration test simulates a compromised endpoint, malicious insider, or post-phishing scenario. We start with low-privilege access and demonstrate the realistic paths to domain takeover, sensitive data, and business-critical systems.

// WHAT WE TEST

  • Active Directory misconfigurations: Kerberoasting, AS-REP roasting, unconstrained delegation
  • AD Certificate Services abuse (ESC1 through ESC8)
  • NTLM relay, LLMNR/NBT-NS poisoning, and credential capture
  • BloodHound-driven attack path analysis to Domain Admin and Tier 0 assets
  • Lateral movement, privilege escalation, and persistence techniques
  • Sensitive data discovery in file shares, databases, and ticketing systems
  • EDR detection coverage during real-world threat actor tradecraft

// DELIVERABLES

Attack chain diagrams showing realistic paths from initial foothold to high-value targets, prioritized findings with remediation guidance, and executive narrative connecting technical detail to business risk.

// WHO NEEDS THIS

Any organization running Active Directory or a corporate network. Especially valuable for organizations preparing for compliance audits, validating EDR investments, or building an internal detection program.

./read-the-full-breakdown →
[ 03 ] WEB APP

Web Application Security Testing

OWASP-aligned assessment of your custom applications, with depth scanners cannot reach.

Web application testing focuses on the layers a network pentest cannot reach: business logic, authentication flows, authorization decisions, and application-specific vulnerabilities. Our work follows the OWASP Testing Guide and ASVS, applied with the depth real-world threat actors bring.

// WHAT WE TEST

  • OWASP Top 10 coverage: injection, authentication, sensitive data exposure, XXE, broken access control, SSRF, deserialization, and more
  • Business logic abuse and workflow bypass scenarios
  • Session management, JWT and token handling, OAuth and SSO flows
  • Role-based and attribute-based authorization weaknesses (IDOR)
  • Client-side risks: DOM XSS, CSP bypass, modern SPA-specific attacks
  • API endpoints invoked by the application
  • File upload, file processing, and import/export pipelines

// DELIVERABLES

Findings with full reproduction steps, screenshots, request and response captures, CVSS scoring, and clear remediation guidance for engineering teams. Retest of remediated findings included.

// WHO NEEDS THIS

Any organization that builds, customizes, or operates custom web applications, especially those processing sensitive data or supporting customer transactions.

./read-the-full-breakdown →
[ 04 ] API

API Penetration Testing

REST, GraphQL, and gRPC. Where most modern attacks now actually happen.

Modern applications expose far more API surface than UI surface. Most automated scanners are blind to API-specific vulnerabilities. Our assessments cover the full OWASP API Security Top 10 and the API-specific attack patterns that scanners miss.

// WHAT WE TEST

  • Broken Object Level Authorization (BOLA / IDOR) at scale
  • Broken Object Property Level Authorization (mass assignment, excessive data exposure)
  • Broken authentication and session handling for APIs
  • Authorization bypass, vertical and horizontal escalation
  • Rate limiting and resource consumption abuse
  • GraphQL-specific risks: introspection, query depth, batching attacks
  • Server-side request forgery (SSRF) via API parameters
  • Unsafe consumption of upstream APIs

// DELIVERABLES

API-focused findings with reproduction steps via curl or Postman collections, plus architectural recommendations where applicable.

// WHO NEEDS THIS

Any organization with public, partner, or internal-facing APIs supporting mobile apps, single-page apps, partner integrations, or service-to-service communication.

./read-the-full-breakdown →
[ 05 ] CLOUD

Cloud Security Assessment

AWS, Azure, and GCP. Where identity is the new perimeter.

Cloud environments shift the attack surface from network to identity and configuration. Our cloud assessments identify the misconfigurations, privilege paths, and identity-based attack chains a threat actor would actually exploit, not just the noise from a CSPM tool.

// WHAT WE TEST

  • IAM privilege paths: AWS IAM, Azure RBAC, GCP IAM policies
  • Identity-based attack chains using PMapper, AzureHound, ROADtools, and equivalent
  • Misconfigured storage: S3, Azure Blob, GCS buckets and access policies
  • Secrets exposed in IaC, container images, function code, and metadata services
  • Cross-account and cross-tenant trust relationships
  • Container and Kubernetes security: pod escapes, RBAC, network policies
  • CI/CD pipeline access paths into cloud environments

// DELIVERABLES

Attack path narratives showing realistic privilege escalation through your cloud environment, prioritized remediation guidance, and IaC snippets where applicable.

// WHO NEEDS THIS

Any organization operating workloads on AWS, Azure, GCP, or running Kubernetes. Especially valuable post-migration, pre-audit, or when adopting new cloud services.

./read-the-full-breakdown →
[ 06 ] RED TEAM

Adversary Simulation

Objective-driven, MITRE ATT&CK-aligned engagements emulating real threat actors.

An adversary simulation engagement is goal-oriented and stealth-focused. Rather than enumerating vulnerabilities, we model a specific threat group relevant to your industry and execute their tradecraft end-to-end. The outcome shows whether your detection, response, and defensive controls would actually catch a real attack.

// WHAT WE TEST

  • Initial access through phishing, exposed services, or supply chain pathways
  • Command and control with operator-grade frameworks (Sliver, Havoc, Cobalt Strike)
  • Defense evasion and operational security techniques
  • Lateral movement, persistence, and privilege escalation
  • Actions on objectives: data exfiltration simulation, ransomware deployment validation, business disruption testing
  • Purple team mode: collaborative testing to validate and improve detections

// DELIVERABLES

Adversary emulation narrative aligned to MITRE ATT&CK, detection coverage gaps, recommended detections and playbook improvements, and a post-engagement debrief with your SOC and IR teams.

// WHO NEEDS THIS

Mature security programs ready to validate detection and response, organizations preparing for high-stakes audits, or teams that want a realistic test of how a real attack would play out.

./read-the-full-breakdown →
// NEXT STEP

Not sure which service fits?

Schedule a scoping call and we will help you figure it out. No upsell, no pressure. If you do not need a service, we will tell you.