Winnipeg Penetration Testing

Operator-Driven Penetration Testing.

Adversary-simulated engagements mapped to MITRE ATT&CK and OWASP. Every finding is manually verified, chained where relevant, and ranked by real business impact.

Methodology

Assess. Exploit. Harden. Validate.

Every offensive engagement runs the same four-phase cycle, mapped against MITRE ATT&CK and the OWASP Testing Guide, regardless of scope size.

01

Assess

Reconnaissance and enumeration of the in-scope environment: infrastructure, applications, identities, and third-party exposure.

02

Exploit

Hands-on exploitation of identified weaknesses to confirm real impact, chained where possible to demonstrate realistic attack paths.

03

Harden

Findings delivered with prioritized, actionable remediation guidance, ranked by business impact, not just CVSS score.

04

Validate

Complimentary retest once fixes are in place, so you have proof the gap is actually closed.

Penetration Testing

External, internal, or full-scope.

Certified against OSCP, CPTS, and CRTO standards. No client passwords or access required to begin an external engagement.

External network

Vulnerability scanning and hands-on exploitation
OSINT and account enumeration
Breached-credential intelligence
Service and port enumeration
Login-portal attacks (web / O365 / VPN)
MFA bypass testing
Third-party leak enumeration (S3, GitHub)
Free remediation retest included

Internal network

Active Directory security evaluation
Shared-resource discovery
Password attacks
Lateral movement
Kerberos attacks (including Kerberoasting)
MITM attack paths
Hash cracking
Free remediation retest included

Full Scope Network

End-to-end external + internal methodology
OSINT and MFA bypass from the outside
Active Directory compromise and lateral movement
Full breach-impact demonstration
Free remediation retest included
Frequently Asked Questions+
How long does a network penetration test take?+

Most external engagements run one to two weeks depending on scope. Internal and full-scope engagements typically take two to three weeks since they involve deeper enumeration inside your environment. You'll get a specific timeline during scoping, before any contract is signed.

Will testing disrupt our business or cause downtime?+

The goal is zero disruption to production systems. Rules of engagement are set in writing before testing starts, including blackout windows around anything business-critical. If a specific test carries any risk of instability, we flag it and get explicit sign-off before running it.

What access or information do you need from us to get started?+

For external testing, none. We start from the same position as an outside attacker: your public domain and IP ranges. Internal and full-scope testing needs either physical or remote access to your network, which we'll coordinate with your IT team during scoping.

Will this trigger our security alerts or our MSSP/SOC?+

It might, and that's useful information either way. If your monitoring catches us, that tells you your detection is working. If it doesn't, that's a finding too. We can coordinate timing with your security team in advance if you'd rather they know a test is in progress.

What's the difference between external, internal, and full-scope, and which one do I need?+

External tests what's reachable from the open internet: your website, VPN, email security, exposed services. Internal simulates what happens if an attacker, or a compromised employee account, is already inside your network. Full-scope combines both to show the complete path from outside access to internal compromise. If you've never had a test before, external is the standard starting point.

What do we get at the end?+

A written report with an executive summary for leadership, technical detail for whoever's fixing things, and every finding ranked by actual business impact rather than raw severity score. You can request a redacted sample report before committing to anything.

Do you retest once we've fixed the issues?+

Yes, a retest is included at no extra cost until findings are resolved. We're not going to charge you twice to confirm your own fix worked.

Is a penetration test the same as a vulnerability scan?+

No. A vulnerability scan flags known issues automatically and stops there. A penetration test goes further: confirming which findings are actually exploitable, chaining smaller issues into a real attack path, and showing you the actual business impact rather than a list of CVEs.

Web Application & API

OWASP Top 10, mapped to your actual stack.

Automated scanning surfaces the obvious. Testing tailored to your language and framework finds what it misses.

Full site and API mapping
Authentication bypass & session attacks
Directory traversal
File upload & remote code execution
Injection testing, both automated and hands-on (XSS, SQLi)
Business logic abuse
Frequently Asked Questions+
Do you test our live production site, or do we need a staging environment?+

Either works. Production testing shows your real exposure, but we scope carefully around anything that could affect real users or data, for example avoiding destructive actions on a live database. If you'd rather isolate testing entirely, a staging environment that mirrors production is also fine.

Will testing slow down or break our site for real users?+

We scope and rate-limit testing specifically to avoid this. Anything with a risk of performance impact, like heavier automated scanning, gets scheduled during low-traffic windows if needed.

Do you need our source code, or is this black-box testing?+

Neither is required, but either helps. Black-box testing (no source access) shows exactly what an outside attacker sees. If you give us source access or API documentation, we can dig deeper into logic flaws that black-box testing alone might miss. We'll recommend the right approach during scoping.

Do you test authenticated areas of the app?+

Yes, if you want that in scope. You'll provide test accounts at different privilege levels (standard user, admin, etc.) so we can check for authorization issues like one user accessing another user's data.

We release new code every week. Doesn't that make the test outdated immediately?+

A point-in-time test still covers your core architecture and logic, which doesn't change every release. For applications with frequent deployments, EASE's continuous external monitoring is a better fit to catch new exposure as it appears, alongside a periodic deeper penetration test.

What methodology do you follow?+

OWASP Top 10 as a baseline, plus manual testing tailored to your actual language and framework: authentication and session handling, injection, file upload and remote code execution paths, business logic abuse, and directory traversal. Automated scanning catches the obvious; the manual work is where the real findings come from.

Do you test mobile apps too?+

If your mobile app talks to the same API, that's in scope. Dedicated native mobile app testing (iOS/Android binary analysis) can be scoped as an add-on, ask during your consultation.

Wireless & IoT

Corporate wireless, validated.

WPA2/3-Enterprise validation, rogue AP detection, and segmentation verification for mixed corporate, guest, and IoT environments.

WPA2/WPA3-Enterprise validation
Rogue access point detection
PMKID capture and offline cracking
Evil-twin and captive portal resilience
Guest and corporate segmentation verification
IoT and OT scope on request
Frequently Asked Questions+
Do you need to be on-site for wireless testing?+

For most wireless assessments, yes. Physical proximity is part of how these attacks actually work (handshake capture, rogue access points, evil twin attacks), so we coordinate a visit during scoping.

Will this disrupt our office Wi-Fi during business hours?+

We schedule around your operating hours where possible and flag anything with a risk of disrupting connectivity in advance. Deauthentication-based tests, for example, are scoped and timed carefully since they can briefly interrupt connected devices.

Can you test remote employees' home networks?+

That's outside the scope of a standard wireless assessment, which focuses on infrastructure you control: office networks, guest networks, and any company-managed access points. Remote worker security is typically better addressed through endpoint and identity controls.

Are our IoT devices included, like cameras and badge readers?+

They can be, if you want them in scope. IoT and OT segments often sit on flat, unsegmented networks, which is exactly the kind of exposure worth testing. Let us know what's in your environment during scoping and we'll build it into the assessment.

Do you need our Wi-Fi password to test?+

Not for the core assessment. We test from an outside attacker's position first: no credentials, just proximity. If you also want your WPA2-Enterprise setup or internal segmentation tested more deeply, that's a separate, credentialed phase we can scope in.

Social Engineering

Test the human layer.

Targeted phishing, vishing, and pretext-based campaigns aligned to your actual threat model. Not compliance-checkbox awareness bait.

Targeted spear-phishing campaigns
Voice-based (vishing) pretexting
Credential harvesting and MFA-bypass simulation
Payload delivery and EDR evasion testing
Physical pretexting
Detailed metrics and recommended training paths
Frequently Asked Questions+
Will our employees know this is a test?+

No, and that's the point. The value of a social engineering assessment is measuring real, unprompted behavior. Leadership is looped in beforehand for authorization, but the test only works if it's a surprise to the people being tested.

What happens to an employee who falls for it? Are they going to get in trouble?+

That's your call, not ours, but we'd steer you away from it. The goal is to measure and improve your organization's resilience, not punish individuals for a mistake almost anyone could make under the right pretext. Most clients use the results for targeted training instead of disciplinary action.

Do you tell us right away if someone falls for it, or only in the final report?+

If someone hands over live credentials or clicks something that could represent immediate risk, we flag it to your designated point of contact right away. Lower-risk findings, like someone opening a tracked email, go into the full report at the end.

Can we exclude certain people or departments?+

Yes. Scope is entirely up to you, whether that's excluding specific individuals, focusing on one department, or covering the whole organization.

Is this just phishing, or does it include physical tests too?+

Both, if you want. Standard engagements usually include phishing and pretext phone calls (vishing). Physical testing, like badge cloning or attempting to walk into your office, is available as an add-on and scoped separately since it carries its own legal and safety considerations.

How do you keep this legal?+

Everything is scoped and authorized in writing before we start, including a get-out-of-jail letter your team can use if a test is ever questioned in the moment. We don't impersonate law enforcement, emergency services, or anyone else that would cross a legal line.

Flagship Offering

External Attack Surface Evaluation

The reconnaissance phase of an external penetration test, delivered continuously, with zero active exploitation and zero disruption.

DNS and subdomain mapping, email authentication posture (DMARC/DKIM/SPF), leaked credential monitoring, shadow IT discovery, third-party exposure tracking, and employee intelligence, run continuously, not as a one-time snapshot.

[+] passive reconnaissance only
[+] zero touch on production
[+] alerts on new exposure as it appears

Ready to get hacked?