Authorised offensive security

A penetration hacker breaks what other firms only scan

Breakpoint Labs is a manual testing practice. A penetration hacker on our team chains small findings into proven business impact, because that is the only way to show what an attacker would really do with your estate.

90%+ manual testing 0 junior bench 41h to domain admin, last red team
engagement.log · authorised scope
# scope signed, window open
$ enum --target ████████████
47 hosts, 12 services, 3 forgotten subdomains
$ chain --from ci-runner --to identity
[+] token in public job log
[+] role assumed → ██████
[+] secret read → backup operator
[!] domain administrator @ t+41h
scanner findings on this path: 0
The difference

What a penetration hacker does that a scanner cannot

Automated tools are useful, but they grade findings one at a time. An attacker does not. Therefore the gap between a scan and a real test is the gap between a list and a proof.

Automated scan

Finds items

  • Rates each issue in isolation, so a chain of three low findings scores as low.
  • Cannot reason about your business logic, because it does not know what the app is for.
  • Produces false positives your engineers then spend a week disproving.
  • Proves nothing, since it never demonstrates actual impact.

Manual engagement

Proves impact

  • Links findings into a path, so you see the route rather than the parts.
  • Abuses logic a tool cannot model, for example an approval step that trusts a client value.
  • Validates every finding by hand, therefore the report contains no noise.
  • Ends with reproducible evidence, so remediation can be verified.
Attack path diagram showing how a penetration hacker chains six findings into domain compromise

That is a real chain from an authorised engagement, redacted. Not one of those six steps is a vulnerability on its own. As a result the automated scan that ran the week before reported none of them.

Methodology

The phases behind every engagement

We follow the Penetration Testing Execution Standard and the OWASP testing guide, because a named methodology is what makes an engagement repeatable. Each phase below is manual-led where it matters.

pre-engagementPhase 01
Scope and authorisationWe agree the target list, the permitted techniques, the testing windows, and the escalation path. The system owner signs it, and nothing starts before that signature exists.
intelligencePhase 02
ReconnaissancePublic asset discovery, subdomain and service enumeration, credential exposure, and supply-chain surface. Most engagements find something the asset owner had forgotten was still reachable.
threat-modelPhase 03
ModellingWe rank the paths an attacker would actually take against your business, so effort goes where the impact is rather than where the tooling is easiest.
exploitationPhase 04
ChainingFindings get combined and proven. Each step is documented with the request, the response, and the artefact, therefore your engineers can reproduce it without guessing.
post-exploitPhase 05
Impact and cleanupWe establish what an attacker could reach, then remove every artefact we placed. In addition we log each action with a timestamp for your incident team.
reportingPhase 06
Report, debrief, retestFindings, business risk, and prioritised remediation, briefed live by the tester who ran it. Once you have applied the fixes, the retest is included.
Coverage

What a penetration hacker tests here

Scope is always agreed in writing first. These are the surfaces our engagements usually cover, although we shape each one around your threat model.

WEB / APIApplicationsAuthentication, session handling, access control, and the business logic behind the endpoints.
NETWORKInfrastructureExternal perimeter, internal estate, segmentation, and the lateral paths between them.
CLOUDIdentity and configurationRoles, trust relationships, key material, and the quiet privilege that accumulates over years.
BUILDPipeline and supply chainRunners, artefact stores, and secrets handling, that is, where modern breaches increasingly start.
RED TEAMAdversary simulationObjective-driven, full-scope, and measured against your detection and response capability.
PRIVATEExecutive exposurePersonal footprint, home network, and device hardening for founders and executives at real risk.
Evidence

A redacted finding, end to end

Client names stay confidential, so we publish the shape of the work instead. Below is finding four from an authorised retail engagement, exactly as the structure reaches the client.

finding-04.md · severity: critical
## summary
Build runner token permits assumption of an over-scoped role,
which in turn reads a vault path holding backup operator credentials.

## reproduction
1. retrieve token from public job log at ████████████
2. assume role ██████████ using that token
3. read secret at ████████
4. authenticate as backup operator
5. replay to domain controller

## business impact
Full control of the production identity plane.

## remediation
[1] scope the runner role to the artefact bucket only
[2] rotate the exposed token and enable log redaction
[3] remove backup operator from the vault path policy
verified on retest, zero downtime
41hfrom kickoff to domain administrator
3configuration changes closed the chain
0client findings retained after delivery
Commercials

Fees and scope

Fixed fee
from $25,000

Most engagements land between $35,000 and $120,000, depending on scope and depth.

We quote one fixed number after a technical scoping call, so there is no hourly billing and no change orders mid-project. However, if your budget is materially under $15,000, we are the wrong firm and we will say so directly.

Authorisation is the whole line

Every technique on this page is lawful only when the system owner has authorised it in writing. Without that document the same actions are a criminal offence, and in the United Kingdom that holds regardless of intent.

  • We do not access any account, device or system without documented consent.
  • Nor do we monitor individuals, or recover accounts that are not yours.
  • We do not trace or retaliate against an attacker. Report that to law enforcement.

Minimum engagement is $25,000. A range is fine, since it tells us what depth to scope.

A senior tester replies within one business day.

Common questions

Questions about hiring a penetration hacker

What is a penetration hacker?

It is a plain-language name for an authorised penetration tester. The role is to attack a system with the owner's written permission, prove what a real intruder could reach, and hand back the evidence and the fix. The permission is what separates the job from a crime.

How does a penetration hacker differ from a vulnerability scan?

A scan lists issues one by one, while a manual engagement links them. Because attackers combine small weaknesses, the chain is usually far more serious than any single item in it. We also validate every finding by hand, so the report carries no false positives.

Do you need credentials or access to our systems?

It depends on the goal. Black-box work starts with nothing, although grey-box testing with a low-privilege account usually finds more for the same budget. We agree that in the scoping call and record it in the rules of engagement.

Will testing break production?

We agree testing windows, blast-radius limits and an escalation contact before starting. Destructive techniques are excluded unless you explicitly ask for them in writing. In addition, we log every action so your team can correlate anything they see.

What does an engagement cost?

Engagements start at $25,000, and most land between $35,000 and $120,000. The fee is fixed after the scoping call, therefore it does not move during the project.

What do we receive at the end?

A findings report with reproducible chains, a business risk summary, prioritised remediation, a live debrief from the tester who ran it, and a retest once your fixes are in. Evidence is destroyed after delivery.