ATALAIA
  1. Home
  2. Services
  3. Pentest
12Station 12 · Release & test

Pentest

Manual testing of a staging copy, scoped to what changed and what matters, with every finding retested once you fix it.

The life of one finding

From the moment it's found to the moment the SOC would catch it again. Nine days, no PDF.

  1. Day 1 · 10:40Found

    IDOR on /redeem: change the offer ID, get another user's voucher.

  2. Day 1 · 10:45Posted

    In the shared channel, with a request you can replay.

  3. Day 1 · 11:30Ticket

    Owner assigned, steps and a suggested fix attached.

  4. Day 3Fixed

    Ownership check moved into the service. PR merged.

  5. Day 4Retested

    The same request returns a 403. Ticket closed.

  6. Day 9Watched

    SOC rule: one user, many foreign offer IDs. Fires in 40 seconds.

Two weeks in staging

Pick a step, or let it play. Every line is what someone in the room actually says.

Step 1Scope from the line

What changed, what's exposed, what the threat model flagged.

ATALAIAWe test what changed: the redeem flow, the partner webhook, the admin panel.

DEV LEADThe staging copy is ready. Same build as prod, fake points.

Leaves the roomScope: redeem flow, partner webhook, admin

Step 2Test like an attacker

Manual, in staging, with your team on a channel.

ATALAIA 2Changing the offer ID on /redeem returns another user's voucher.

ATALAIAThat's an IDOR. It goes in the channel now, not in a PDF next month.

DEV LEADSeen. Who owns /redeem? Assigning it.

Leaves the roomTesting staging, team on a channel

Step 3File, don't publish

Tickets with steps and fixes, as they are found.

ATALAIATicket filed: steps, a request you can replay, and a suggested fix.

DEV LEADFix merged. Can you check it?

Leaves the room5 findings filed as tickets

Step 4Retest and hand over

Fixes verified; detections passed to the SOC.

ATALAIA 2Retest is green. The same request now returns a 403.

SOCCan we alert when one user asks for many other users' offers?

ATALAIAThat's the detection. The rule and its test are in the hand-over.

Leaves the roomRetest green, 2 detections to the SOC

  • ATALAIA
  • ATALAIA 2
  • DEV LEAD
  • SOC

Before and after

Before

A pentest that ends with a PDF is a cost. One that ends with merged fixes and new detections is a control.

  • Last year's findings are still open
  • The scope is the whole company every time
  • Findings never reach the SOC or the backlog
After
  • A scope built from your threat model and recent changes
  • Findings filed as tickets, with reproduction steps
  • Free retest of every fix
  • Detection ideas handed to your SOC

Typical shape: One to three weeks of testing, plus retest.

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.