Skip to content
FORTIS AEGIS ADVISORYCyber intelligence
Pentest Advanced

Find critical vulnerabilities before the attack.

We test Web, Mobile iOS and Android applications, APIs, AI solutions, Cloud, infrastructure and other digital surfaces to identify exploitable flaws and guide remediation of the risks that matter most.

01Risk-aligned scope
02Manual and controlled validation
03Clear evidence of impact
04Prioritized fixes and retesting
What we tested

Technologies evaluated and testing methodologies used.

The scope is adapted to the organization's environment and risk. Below are the main surfaces evaluated and the methodologies that guide each test.

AI
Priority area

AI, LLMs and agents

What we tested: prompt injection, data leakage, insecure outputs, excessive agent and tool permissions, RAG, font poisoning and integration abuse.

MethodologiesOWASP GenAI Red Teaming Guide
WEB

Web Applications

What we tested: authentication, sessions, authorization, injections, XSS, SSRF, file uploads, business logic, components and data protection.

MethodologiesOWASP WSTG · PTES
APP

Mobile iOS and Android

What we tested: local storage, encryption, network communication, certificates, deep links, platform controls, tampering, reverse engineering, and APIs.

MethodologiesOWASP MASTG
API

APIs and integrations

What we tested: REST, GraphQL, SOAP and gRPC APIs, authorization by object and function, tokens, rate limiting, sensitive flows, data exposure and injections.

MethodologiesOWASP WSTG — API Testing · PTES
CLD

Cloud

What we tested: AWS, Azure and Google Cloud environments, IAM, privileges, storage, secrets, networks, exposed services, metadata, logs and serverless.

MethodologiesCSA Cloud Penetration Testing Playbook · NIST SP 800-115
INF

Infrastructure

What we tested: external perimeters, internal networks, servers, VPNs, Active Directory, services, credentials, segmentation, lateral movement and privileges.

MethodologiesPTES · NIST SP 800-115 · OSSTMM
How it works

Scope, execution and remediation validation.

Each assessment begins with a clear definition of the scope, technical context, assets involved, testing objectives and rules of engagement.

Execution follows previously established operational limits, security criteria and communication channels, reducing risks to availability and business continuity.

At the end, findings are technically validated and documented with evidence and remediation recommendations. When applicable, remediation is retested to confirm that the vulnerability has been effectively eliminated.

01

Scope and context

We align assets, objectives, restrictions, criticality and success criteria.

02

Mapping

We identify technologies, exposed surfaces and points relevant to testing.

03

Controlled tests

We validate vulnerabilities with manual techniques and expert-led automation.

04

Impact analysis

We relate technical evidence to real risk to data, systems and operations.

05

Report and retest

We deliver prioritized recommendations and confirm the effectiveness of corrections.

Beyond the scanner

Automation finds signals. Experts prove the risk.

Tools are important for expanding coverage, but they do not alone understand context, impact and business logic.

  • Manual validation of findings
  • Fault combination in realistic scenarios
  • Reduction of false positives
  • Recommendations linked to the cause of the problem
Deliverables

A report that guides remediation.

The results are organized for technical teams, those responsible for risk and leaders who need to define priorities.

  • Executive summaryRisks, impacts and priorities presented in clear decision-making language.
  • Detailed technical reportEvidence, reproduction steps, affected assets and classification of findings.
  • Remediation planPractical recommendations ordered by criticality and impact.
  • Presentation meetingDiscussion of results with technical teams and interested parties.
  • Retesting correctionsNew validation to confirm that vulnerabilities have been addressed.
Start with the real risk

Discover and fix vulnerabilities before they become an incident.

Speak with Fortis Aegis to define the Pentest type, scope and depth appropriate for your environment.

Plan my Pentest