Capability 02

Penetration Testing & Technical Assurance

Human-led adversarial testing, augmented by Korrosiv.AI — our in-house AI-native pen testing engine. We find what automated scanners miss and replicate the techniques of real threat actors, giving you a true picture of your exposure before an attacker does.

What's included
  • External & internal penetration testing
  • Web application security testing
  • API security assessments
  • Red team engagements
  • Cloud configuration reviews
  • Assumed breach exercises
  • Technical security assurance
  • Vulnerability assessments
The challenge

Automated scanners find known problems. Attackers find the rest.

Vulnerability scanners are a starting point, not a finish line. Real-world attackers combine technical skill, creative thinking, and persistence to find paths through your environment that no tool would flag. A clean scan report is not the same as a secure organisation.

SALTT's offensive security services (OSS) capability approaches every engagement the way a motivated threat actor would — methodically, with business context in mind, and focused on what would actually cause you harm. Every finding comes with a risk-rated remediation plan your team can action.

 

External & Internal Penetration Testing

Network penetration testing from both external (internet-facing) and internal (assumed network access) perspectives. Identifies exploitable paths through your perimeter and internal environment.

Web Application Security Testing

Manual assessment of web applications against OWASP and industry standards, augmented by Korrosiv.AI — our AI-native testing engine that analyses 100% of responses and adapts payloads in real time.

API Security Testing

Targeted assessment of REST and GraphQL APIs, powered in part by Korrosiv.AI's purpose-built API testing capability. Identifies excessive data exposure, broken object-level authorisation, and injection flaws.

Red Team Engagements

Adversary simulation exercises that test your detection and response capability against realistic, multi-stage attack scenarios. Designed to challenge your blue team, not just find vulnerabilities.

Cloud Configuration Reviews

Assessment of AWS, Azure, and GCP environments against security best practices and CIS benchmarks. Identifies misconfigured services, excessive permissions, and insecure architecture patterns.

Assumed Breach Exercises

Starting from a foothold inside your environment, we test what an attacker could access, escalate, and exfiltrate. Focuses on detection gaps and lateral movement paths.

Technical Security Assurance

Independent technical review of security controls, architecture decisions, and implementation quality. Used to validate that built systems meet their security design intent before go-live.

Vulnerability Assessments

Structured, scoped assessments that identify and risk-rate known vulnerabilities across your environment. Delivered with prioritised remediation guidance — not just a raw CVE list.

What you gain

  • A clear, risk-rated picture of your exploitable vulnerabilities
  • Remediation guidance prioritised by business impact — not just severity score
  • Evidence for board reporting, compliance requirements, and cyber insurance
  • Validated detection and response capability against realistic attack scenarios
  • Independent assurance that security controls are working as intended
  • A trusted testing partner who understands your environment over time
Related Insights

Resources from our team

AI Security 05 May 2026
Copy Fail: Nine-Year-Old Linux Kernel Flaw Gives Any User Root in 732 Bytes

A nine-year-old logic flaw hiding in the Linux kernel's cryptographic subsystem has surfaced as one of the most impactful privilege escalati...

Read article →
Cybersecurity 24 Apr 2026
Claude Mythos Vendor Breach: Implications for Enterprise Exposure Management

Claude Mythos Vendor Breach: Implications for Enterprise Exposure Management A review of the reported Project Glasswing vendor breach and wh...

Read article →
Security 21 Apr 2026
AI Security Tools Expand: What It Means for Aussie Defenders

Two of the largest AI developers — OpenAI and Anthropic — both expanded their security-focused AI capabilities this week. For Australian sec...

Read article →

Ready to get started?

Our team works across Australia. Every engagement is led by experienced practitioners — not offshore subcontractors.

Get in Touch