Skip to content
CISO Marketplace Services

Practice 01 · Offense

Find the path before an attacker does.

Penetration testing, red teaming and adversary emulation run by operators, not scanners. We prove what an attacker can reach, show you how, and help you verify the fix.

attack-path.graph objective reached
Illustrative attack path: exposed VPN and a phished user lead to a workstation, then Kerberoasting and a file server, ending at Domain Admin.Exposed VPNT1133Phished userT1566WorkstationT1059KerberoastT1558File serverT1021Domain AdminT1078
Illustrative. Each engagement report maps the real path to MITRE ATT&CK.

The escalation ladder

Match the test to your maturity.

Each step assumes the one before it. Start where your program is today; we'll tell you honestly if you are not ready for the next rung.

  1. Rung 1

    Penetration Testing

    Comprehensive penetration testing service including network, application, and infrastructure security assessment. Includes detailed reporting and remediation guidance.

    From

    $8K

    Tiers →
  2. Rung 2

    Red Team Assessment

    Advanced adversary simulation to test your security controls

    From

    $25K

    Tiers →
  3. Rung 3

    Purple Team Assessment Program

    Collaborative security assessment combining red team attacks with blue team defense to improve detection and response capabilities in real-time.

    From

    $45K

    Tiers →

Services

Every offensive engagement we run.

Starting prices come from our live catalog. Your proposal fixes the tier and price before anything is signed.

01 / 05

Penetration testing

Scoped, manual testing of a defined attack surface, with every finding reproduced and evidenced.

Penetration Testing

Comprehensive penetration testing service including network, application, and infrastructure security assessment. Includes detailed reporting and remediation guidance.

From $8K

Internal Network Assessment

Comprehensive onsite evaluation of internal network infrastructure and security controls

From $20K

Active Directory Security Assessment

Comprehensive security assessment of Active Directory infrastructure, focusing on privilege escalation, lateral movement, and domain compromise scenarios.

From $40K

Web Application Security Assessment

In-depth testing of web applications for security vulnerabilities

From $8K

API Security Assessment

Comprehensive testing of API endpoints and integrations

From $12K

Mobile Application Security Assessment

Comprehensive security testing of iOS and Android applications

From $10K

Cloud Security Assessment

Security evaluation of cloud infrastructure and configurations

From $12K

Wireless Infrastructure Attack Assessment

Advanced wireless security testing including WiFi, Bluetooth, RF, and cellular network attack simulation and vulnerability assessment.

From $10K

Compliance Penetration Test

Startups and smaller companies often need a real penetration test for an audit or a customer contract, not a multi-week offensive campaign. This is a fixed-scope, human-led test of one application or external perimeter with a report auditors accept, a retest of fixed findings and an attestation letter — the entry point to the Penetration Testing and Red Team services.

From $5.5K

04 / 05

Continuous exposure

Testing that runs as a program rather than a one-off event: PTaaS, attack surface management and CTEM.

Penetration Testing as a Service (PTaaS) Subscription

An annual subscription that replaces the once-a-year pentest: a baseline test, then testing of new features and releases through the year, unlimited retests, findings delivered into your ticketing system and a standing attestation letter that is always current. It is the recurring form of the Penetration Testing service and the delivery model behind the PTaaS pillar of the program.

From $2K / mo

Continuous Threat Exposure Management (CTEM) Program

A packaged CTEM program: continuous attack-surface discovery, threat-led validation (incl. pen test/red team), exposure prioritization, and measurable remediation — replacing point-in-time vuln scanning.

Scoped per engagement

Attack Surface Management Program

Continuous discovery, monitoring, and assessment of your organization's external attack surface and digital footprint. Our ongoing service provides real-time visibility into internet-exposed assets, shadow IT, misconfigurations, and newly emerging vulnerabilities, enabling proactive risk reduction before attackers can exploit these weaknesses.

From $7.5K / mo

Vulnerability Management as a Service

Most organizations own a scanner and still carry a backlog nobody triages. We run authenticated internal and external scanning, prioritize by exploitability and business context rather than CVSS alone, open and track remediation tickets with your IT team or MSP, verify fixes and report the trend leadership and auditors want to see.

From $1.5K / mo

Coverage

Mapped to how adversaries actually operate.

Red team and adversary emulation engagements are planned and reported against MITRE ATT&CK, so your detection team can see exactly which techniques were used and which were caught.

TA0043

Reconnaissance

TA0001

Initial Access

TA0002

Execution

TA0003

Persistence

TA0004

Privilege Escalation

TA0005

Defense Evasion

TA0006

Credential Access

TA0007

Discovery

TA0008

Lateral Movement

TA0009

Collection

TA0011

Command & Control

TA0010

Exfiltration

The deliverable

A report your engineers can act on and your board can read.

  • Executive summary: business risk in plain language, with the attack narrative.
  • Technical findings: severity, affected assets, evidence, reproduction steps.
  • Framework mapping: ATT&CK techniques, CWE, and the compliance control affected.
  • Prioritized remediation: what to fix first, and the fix itself, not just the problem.
  • Debrief: a walkthrough with your technical team and, if you want it, leadership.
finding / EXT-07Critical

Unauthenticated file read on VPN appliance exposes session tokens

CWE-22 · ATT&CK T1190

Impact

Session tokens for active users can be read remotely, giving an authenticated foothold on the internal network without credentials.

Evidence

$ curl -sk https://vpn.target/…/../../session
HTTP/1.1 200 OK
session=9f2c…e71a  user=j.doe  ✓ valid

Remediation

Apply the vendor patch, invalidate all active sessions, and restrict the management interface to the admin network.

Sample finding, illustrative

How we operate

The standard we hold ourselves to.

Operators, not scanners

Automated tools find candidates. People find the chain: the misconfiguration plus the reused password plus the trust relationship that ends at domain admin.

Every finding reproduced

Nothing reaches your report without evidence and steps your engineers can replay. No scanner output pasted into a PDF.

Criticals don't wait

An exploitable critical is escalated to your named contact when it is confirmed, not at the end of the engagement.

Safe by design

Written rules of engagement, agreed out-of-bounds systems, and a stop-work channel you control for the whole engagement.

Process

How an engagement runs.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

FAQ

Questions buyers ask us.

What's the difference between a penetration test and a red team?

A penetration test finds as many exploitable weaknesses as possible in a defined scope. A red team pursues an objective (data, access, a crown jewel) the way a real adversary would, and measures whether your people and tooling detect and respond. Most organizations start with penetration testing and move to red and purple teaming as their detection matures.

Will testing disrupt production?

Rules of engagement are agreed in writing before any testing: in-scope and out-of-bounds systems, testing windows, and a stop-work contact. Destructive techniques are excluded unless you explicitly authorize them.

Do you test for compliance (PCI DSS, SOC 2, HIPAA, ISO 27001)?

Yes. The Compliance Penetration Test is scoped to the requirement your auditor will check, and the report is written to be handed to them.

How is pricing set?

Each service has published tiers with a starting price. Your proposal fixes the tier, scope and price before anything is signed. There are no hourly surprises.

Can testing run continuously instead of once a year?

Yes. PTaaS and the Red Team Subscription run as a program, so new assets and changes are tested as they ship rather than at the next annual test.

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor