Penetration testing

  • Home
  • Penetration testing

Detect vulnerabilities before a real attacker does

We’ll test your applications and networks for vulnerabilities and tell you what the consequences of an exploit might be.

18+ years of experience among the founders · Certified specialists—CEH, OSCP, and others · Projects for large companies and SMEs · Professional liability insurance

Areas of testing

Every IT environment is different. That’s why we tailor the scope of the test to your systems, risks, and desired outcome.

For example, we can test:

  • web applications and APIs,
  • internal and external networks,
  • wireless networks,
  • mobile app,
  • IoT devices,
  • end devices and client applications,
  • physical security,
  • resistance to social engineering.

 

Penetration test of a web application

We’ll examine the application from an attacker’s perspective and try to find ways they could gain access to other users’ accounts, features, or sensitive data. Based on the scope of work, we’ll select appropriate methodologies (OWASP WSTG, ASVVS, API Security, PTES). We’ll examine the login process, user permissions, communication with the API, and whether individual application features can be exploited in unexpected ways.

We use automated scanners as a tool, not as a substitute for a tester’s work. We manually verify their results and also focus on errors in the application’s logic, which automated tools generally fail to detect.

Our testers also have experience in software development. As a result, they can explain to developers not only what is wrong, but also where the problem originates and how it can be fixed.

Price starting at 40,000 CZK, excluding VAT

 
 

Penetration Test of a Vibe-Coded Application

Tools that use generative AI significantly speed up development. At the same time, however, they can introduce vulnerabilities, inadequate access control, insecure APIs, or errors in application logic into the application.

We’ll test an app created using AI or so-called “vibe coding.”

We will focus primarily on:

  • protection of user and sensitive data,
  • authentication and authorization,
  • API and external service security,
  • libraries and dependencies used,
  • potential for practical misuse.

We’ll go over the results with you and recommend which issues to address first.

 

Internal and External Penetration Testing

Internal penetration test

In an internal test, we assume that an attacker has already penetrated the network or gained access to an account or device. We verify where the attacker can go from that point and what damage they can cause within the network.

The test may include servers, workstations, Active Directory, shared folders, or user permission settings. We focus primarily on determining whether a single compromised account or computer opens a path to other systems and sensitive data.

External Penetration Test

For an external test, we start with the internet—the same place where a typical attacker would begin. We’ll see what information about your organization we can uncover and which systems or services are publicly accessible. Then we’ll test whether we can use them to gain further access.

These may include, for example, servers, VPNs, remote access systems, web services, or other devices accessible via the Internet.

The test can be performed remotely via VPN, using a computer connected to your network, or on-site at your location.

Price starting at 50,000 CZK, excluding VAT

WiFi penetration test

When it comes to Wi-Fi networks, we’ll look not only at their settings but also at where they provide access. We’ll examine both corporate and guest networks, access point security, and the possibility of unauthorized connections.

In particular, we will verify the following:

  • separation of the visitor network from the internal infrastructure,
  • the possibility of obtaining or misusing login credentials,
  • the presence of unauthorized access points,
  • the possibility of gaining access to internal systems and data via Wi-Fi.

We can supplement manual testing withby Ktutorialsy. That’s enough her plug into an outlet and after a few days of testing you’ll get a clear report. Kukaczka will check the settings automatically wireless devices and free hotspots.

Price starting at 35,000 CZK, excluding VAT

What will you get from us?

Once the test is complete, you will receive a report with the results and any vulnerabilities found. We will then present the findings to you and walk you through the key findings.

You can request a retest, during which we will verify whether the vulnerabilities have been resolved.

How does the test work?

  1. We’ll Define the Goal and Scope
    We’ll clarify what we’ll be testing and to what extent.
  2. We’ll set the rules
    We’ll agree on a timeline, approaches, points of contact, and the scope of testing.
  3. We will conduct a test
    We will perform manual testing and, in some cases, use automated tools as well.
  4. We’ll Share the Results
    We’ll prepare a clear report and present the results to you.

Why Choose Sec4good?

We present the results in a clear and understandable way

We won’t just give you a list of vulnerabilities; we can explain their practical implications to management and developers and suggest appropriate remedies.

We manually verify the findings

We use automated scanners as a support tool.

We conduct our testing according to clear rules

We determine the scope and limits of the testing in advance. We have professional liability insurance, and we handle client information confidentially.

Black-box, grey-box or white-box?

The chosen approach determines how much information and access the tester has available before the test begins. The appropriate approach depends on the testing objective, the type of system, and the desired level of detail.

Black-box test

The tester will not receive any internal information or access credentials. The test simulates the perspective of an external attacker.

Black-box testing best demonstrates how an attacker with no knowledge of an organization’s environment would target it. Because the tester must first gather all the information on their own, black-box testing tends to be the most time-consuming and costly.

Grey-box test

The tester has only limited information at their disposal—usually the login credentials for a user account. For example, they can verify whether the user can access data belonging to others, higher-level permissions, or parts of the system that should not be available to them.

A gray-box attack is often used to simulate a situation in which an attacker has compromised an employee’s account or has already gained access to the network.

White-box test

In a white-box test, the tester has access to detailed information about the environment, including network maps and passwords. Therefore, the tester does not need to spend time on initial reconnaissance and can focus directly on the selected system and various attack vectors. Similarly, when it comes to applications, we can examine the source code. Thanks to our many years of development experience, we can quickly identify vulnerabilities and propose adjustments to CI/CD to enhance security.

This option is suitable when the goal is to test a specific application, network, or part of the infrastructure as thoroughly as possible.

We will recommend the appropriate option based on your environment and testing objectives.