Security Assessment  ·  Offensive & Assurance Testing

Security Testing That Finds
What Scanners Miss

Manual penetration testing and maturity assessments from people who read the code, not just the CVE feed. One team covers pentest, OpenSAMM, threat modeling, Vulnix0-powered offensive testing, AquilaX code & infrastructure review, and phishing simulation — so you're not stitching reports together from five vendors.

Tested against: OWASP ASVS 4.0 · OWASP API Top 10 · PTES · NIST SP 800-115 · OWASP SAMM v2 · STRIDE · MITRE ATT&CK

Penetration Testing

Automated scanners flag the obvious stuff and stop there. Our testers — OSCP and CREST CRT certified — manually work through your applications, networks, APIs, and cloud infrastructure the way an attacker actually would, chaining together issues a scanner would score as low-severity on their own.

  • Web & mobile application testing (OWASP Top 10, OWASP ASVS)
  • External & internal network penetration testing
  • API security testing (REST, GraphQL, gRPC)
  • Cloud configuration & workload testing (AWS, Azure, GCP)
  • Wireless network and physical/red-team engagements on request
  • One free retest included within 30 days of the report

A typical single-application engagement runs 5–10 working days on-site or remote, and closes with a technical report plus a 45-minute walkthrough with your engineering team — not just a PDF dropped in your inbox.

report/findings/07-bola.jsonFinding
{
  "finding":    "Broken Object Level Authorization",
  "category":   "API5:2023 - OWASP API Security",
  "severity":   "High",
  "cvss":       8.1,
  "endpoint":   "GET /api/v1/invoices/{id}",
  "impact":     "Any authenticated user can view another tenant's invoices",
  "remediation":"Enforce tenant-scoped authorization checks server-side",
  "status":     "retested-fixed"
}
Business functionTypical starting score
Governance1.4 / 3
Design1.8 / 3
Implementation1.1 / 3
Verification0.9 / 3
Operations1.3 / 3

Lowest score, flagged first: Verification. Scores from a first-time assessment at a mid-sized SaaS client — most teams have never formally tested their own test coverage.

OpenSAMM Maturity Assessment

OpenSAMM (the OWASP Software Assurance Maturity Model) assesses how mature your software security practices are — not just your code. We review your organisation across five business functions: Governance, Design, Implementation, Verification, and Operations.

  • Interview-driven assessment against 15 SAMM security practices
  • Maturity scoring (0–3) per practice, benchmarked against industry peers
  • Gap analysis between current and target maturity levels
  • Prioritised, phased roadmap your teams can actually execute
  • Rerun annually to track movement — most clients gain 0.3–0.5 per function in year one

Threat Modeling

Before we try to break something, we model how it can break. Working from architecture diagrams and data flow, our analysts map trust boundaries and systematically enumerate threats using the STRIDE methodology — Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege.

  • Data flow diagram & trust boundary mapping
  • STRIDE-based threat enumeration per component
  • Attack tree construction for critical assets
  • Risk-ranked mitigations mapped to MITRE ATT&CK techniques
  • Ideal for new architecture reviews, major features, or M&A due diligence
User / Client TRUST BOUNDARY API Gateway Auth Service Database S T I

Offensive Security — Powered by Vulnix0

For continuous, attacker-perspective coverage between formal pentest cycles, we run assessments through Vulnix0, our dedicated offensive security platform. It keeps your attack surface under constant scrutiny rather than a once-a-year snapshot.

  • Dynamic Application Security Testing (DAST) of live web applications
  • Dark web & leaked-credential exposure monitoring
  • Continuous external attack surface discovery and scanning
  • Structured penetration testing engagements on demand
  • Findings correlated with OneFirewall's Crime Score threat intelligence

Scans run on a rolling weekly schedule by default; new critical findings page your team the same day rather than waiting for the next quarterly review.

Explore Vulnix0 →
vulnix0 · continuous-scanScan output
$ vulnix0 scan --target app.example.com --mode dast
[+] Crawling application surface ... 312 endpoints
[+] Dark web exposure check ... 2 credential matches found
[+] Active DAST pass ... complete

Findings:
  HIGH    Reflected XSS on /search?q=
  MEDIUM  Missing rate limiting on /api/login
  LOW     Verbose server banner disclosure
# synced with OneFirewall Crime Score engine
aquilax · repo scanScan output
$ aquilax scan --repo backend-api --scope sast,sca,secrets,iac
[+] SAST ................ 14 findings (2 high)
[+] SCA (dependencies) .. 6 vulnerable packages
[+] Secrets detection ... 1 exposed API key
[+] IaC review (Terraform) 3 misconfigured S3 buckets

Summary: 24 findings triaged, remediation PRs suggested

Code & Infrastructure Assessment — Powered by AquilaX

Developed in partnership with AquilaX LTD (UK), our code and infrastructure assessment reviews the software itself and the environment it runs in — before it ever reaches production.

  • Static Application Security Testing (SAST) across your codebase
  • Software Composition Analysis (SCA) for vulnerable dependencies
  • Secrets & credential leakage detection in source and history
  • Infrastructure-as-Code review (Terraform, CloudFormation, Kubernetes manifests)
  • Cloud & container configuration assessment

Plugs into your existing CI pipeline (GitHub Actions, GitLab CI, Jenkins) so findings show up as PR comments, not a separate portal nobody checks.

Explore AquilaX →

Phishing Simulation Campaigns

Technical controls can't stop every attack that targets people directly. Our phishing simulation campaigns test and train your workforce with realistic, controlled scenarios — safely, and with full reporting.

  • Realistic phishing & spear-phishing email templates, tailored to your sector
  • Credential-harvesting landing page simulations (no data ever stored)
  • Click-through, submission, and report-rate tracking per department
  • Just-in-time awareness training triggered on click, not a slide deck the following month
  • Executive & board-ready reporting with trend-over-time metrics
  • Quarterly cadence by default; monthly or continuous on request
Inbox preview
IT Support <it-helpdesk@onefirewaII-corp.com> Action required: password expires today

Hi,
Our records show your network password expires in a few hours. To avoid being locked out, please verify your account now.

🔗 verify-account.onefirewaII-corp.com

IT Helpdesk

Lookalike domain, urgency cue, and generic greeting — a typical Tier 1 template used in month-one campaigns.

How an Engagement Runs

Every assessment — whatever the discipline — follows the same disciplined lifecycle.

01

Scoping

Define targets, rules of engagement, and success criteria with your team.

02

Assessment

Manual testing, maturity interviews, threat modeling workshops, or campaign execution.

03

Risk Scoring

Every finding is triaged and scored — CVSS, SAMM maturity level, or risk rating.

04

Reporting

Executive summary plus technical detail, reproduction steps, and remediation guidance.

05

Retest & Roadmap

Verify fixes and track maturity improvement across subsequent engagements.

Questions We Get Asked

How long does a typical penetration test take?

A single web application or API usually takes 5–10 working days depending on scope and authentication complexity. Network and cloud engagements vary more with the number of in-scope hosts — we'll give you a firm day count during scoping, not a range.

Do you sign an NDA and agree rules of engagement before testing?

Yes, always. Every engagement starts with a mutual NDA and a signed rules-of-engagement document covering scope, testing windows, exclusions, and an emergency contact on both sides in case something needs to stop immediately.

Is retesting included, or is that a separate cost?

One retest of reported findings is included in every pentest and Vulnix0 engagement at no extra cost, as long as it's requested within 30 days of the final report. Retests outside that window are scoped separately.

Can this support our ISO 27001, SOC 2, or PCI DSS requirements?

Yes. Pentest reports are formatted to be handed directly to an auditor, and OpenSAMM assessments map cleanly onto ISO 27001 Annex A and SOC 2 CC-series controls. Tell us which framework you're working toward during scoping and we'll align terminology and evidence accordingly.

Do we need to be a OneFirewall Alliance member to book an assessment?

No. Security assessments are engaged separately from Alliance membership, though members do get priority scheduling and a discount on Vulnix0 and AquilaX continuous-monitoring subscriptions.

Ready to Assess Your Security Posture?

Tell us which discipline you need — pentest, OpenSAMM, threat modeling, Vulnix0 offensive testing, AquilaX code & infra review, or a phishing campaign — and we'll scope an engagement around it.

Speak with OneFirewall Organize a Proof of Value