The Alacrinet Methodology, Phase by Phase.
Six phases. Manual at every step. Every finding chained from first foothold to business impact.
Six phases. Manual at every step. Every finding chained from first foothold to business impact.
File · Phase 1.
What it is. Passive and active discovery of the target attack surface.
How we do it. OSINT, certificate transparency, DNS enumeration, public code search, employee mapping, third-party exposure analysis. The objective is not data collection. The objective is a working theory of where an adversary would start.
Standards. Information-gathering follows OWASP WSTG and the discovery activities in NIST SP 800-115.
Operator note. Recon is where the engagement is won or lost. By the end of it we already know which door we are going through.
File · Phase 2.
What it is. Authenticated and unauthenticated mapping of the in-scope environment.
How we do it. Service and endpoint enumeration, role and trust-boundary discovery, technology fingerprinting, authentication-flow analysis, identity-graph mapping for cloud and Active Directory environments.
Standards. Enumeration follows OWASP WSTG and the information-gathering phase of NIST SP 800-115.
Operator note. Enumeration is where junior testers get bored. It is also where the actual attack path becomes visible to anyone who is still paying attention.
File · Phase 3.
What it is. Manual exploitation of validated weaknesses to prove impact.
How we do it. Every exploit is hand-built or hand-adapted against the specific environment. Scanner-only findings do not enter the report. Each successful exploit is documented with a written chain of intent: what the operator believed, what they tested, what fell out.
Standards. Every technique is mapped to MITRE ATT&CK so your detection team can reconcile it against their own coverage.
“If we cannot reproduce a finding by hand, you will not see it in the report. A theoretical vuln is not a finding.”
File · Phase 4.
What it is. Lateral movement, privilege escalation, and impact demonstration.
How we do it. From the first foothold, the operator pivots to demonstrate realistic business impact: domain compromise, customer-data access, payment-flow tampering, regulated-data exfiltration. We stop at the point where the impact is proven, not at the point where the attack would stop.
Standards. Lateral movement, privilege escalation, and impact actions are mapped to MITRE ATT&CK tactics and techniques.
Operator note. The point of post-exploitation is not to own the domain. It is to show the board what owning the domain would cost them.
File · Phase 5.
What it is. Executive summary, technical report, and remediation guidance.
How we do it. Every finding carries a CVSS score, a written attack-path narrative, and a prioritized remediation step. The report is structured so the CISO can act on the first ten pages and the engineering lead can act on the next forty.
Standards. Every finding is scored with CVSS v4.0 alongside the written attack-path narrative.
“A report a CISO has to translate before showing the board is a report that failed in the writing.”
File · Phase 6.
What it is. Unlimited remediation validation as fixes land.
How we do it. Retests are unlimited and untimed. Each retest produces a written delta document. See /unlimited-remediation-validation for the full policy.
Operator note. Retest is where most vendors charge again. We do not, because remediation is the point of the engagement.
Talk to an Operator
Real operators. Real attack paths. Real business impact. Talk to us about your security goals.