Methodology

The Alacrinet Methodology, Phase by Phase.

Six phases. Manual at every step. Every finding chained from first foothold to business impact.

File · Phase 1.

Phase 1. Recon

What it is. Passive and active discovery of the target attack surface.

How we do it. OSINT, certificate transparency, DNS enumeration, public code search, employee mapping, third-party exposure analysis. The objective is not data collection. The objective is a working theory of where an adversary would start.

Standards. Information-gathering follows OWASP WSTG and the discovery activities in NIST SP 800-115.

Operator note. Recon is where the engagement is won or lost. By the end of it we already know which door we are going through.

File · Phase 2.

Phase 2. Enumeration

What it is. Authenticated and unauthenticated mapping of the in-scope environment.

How we do it. Service and endpoint enumeration, role and trust-boundary discovery, technology fingerprinting, authentication-flow analysis, identity-graph mapping for cloud and Active Directory environments.

Standards. Enumeration follows OWASP WSTG and the information-gathering phase of NIST SP 800-115.

Operator note. Enumeration is where junior testers get bored. It is also where the actual attack path becomes visible to anyone who is still paying attention.

File · Phase 3.

Phase 3. Exploitation

What it is. Manual exploitation of validated weaknesses to prove impact.

How we do it. Every exploit is hand-built or hand-adapted against the specific environment. Scanner-only findings do not enter the report. Each successful exploit is documented with a written chain of intent: what the operator believed, what they tested, what fell out.

Standards. Every technique is mapped to MITRE ATT&CK so your detection team can reconcile it against their own coverage.

Operator Note OPR · STANDARD-OF-WORK
“If we cannot reproduce a finding by hand, you will not see it in the report. A theoretical vuln is not a finding.”
Bailey Besheer, Managing Director of Cybersecurity Services

File · Phase 4.

Phase 4. Post-Exploitation

What it is. Lateral movement, privilege escalation, and impact demonstration.

How we do it. From the first foothold, the operator pivots to demonstrate realistic business impact: domain compromise, customer-data access, payment-flow tampering, regulated-data exfiltration. We stop at the point where the impact is proven, not at the point where the attack would stop.

Standards. Lateral movement, privilege escalation, and impact actions are mapped to MITRE ATT&CK tactics and techniques.

Operator note. The point of post-exploitation is not to own the domain. It is to show the board what owning the domain would cost them.

File · Phase 5.

Phase 5. Reporting

What it is. Executive summary, technical report, and remediation guidance.

How we do it. Every finding carries a CVSS score, a written attack-path narrative, and a prioritized remediation step. The report is structured so the CISO can act on the first ten pages and the engineering lead can act on the next forty.

Standards. Every finding is scored with CVSS v4.0 alongside the written attack-path narrative.

Operator Note OPR · STANDARD-OF-WORK
“A report a CISO has to translate before showing the board is a report that failed in the writing.”
Bailey Besheer, Managing Director of Cybersecurity Services

File · Phase 6.

Phase 6. Retest

What it is. Unlimited remediation validation as fixes land.

How we do it. Retests are unlimited and untimed. Each retest produces a written delta document. See /unlimited-remediation-validation for the full policy.

Operator note. Retest is where most vendors charge again. We do not, because remediation is the point of the engagement.

Talk to an Operator

Ready to See Your Environment the Way Attackers Do?

Real operators. Real attack paths. Real business impact. Talk to us about your security goals.