Enterprise Penetration Test
- Home
- Projects
Project Overview
A large enterprise (confidential) commissioned a penetration test spanning its web applications, APIs and cloud estate. The goal was not a compliance tick-box but a realistic picture of what an attacker could actually achieve, delivered as OWASP-aligned, CVSS-rated findings the team could act on. I mapped a broad and sprawling attack surface, reviewed cloud configuration across the provider footprint, and probed third-party and API exposure. Where individual issues combined into something exploitable, I built proof-of-concept exploit chains to demonstrate real impact rather than theoretical risk. Everything was tested safely against production, and the engagement closed with a prioritized report and a free retest to confirm the fixes held.
Challenges
- Cover a broad, sprawling attack surface across web, API and cloud within a fixed window.
- Surface cloud misconfigurations hidden across a large, multi-account provider footprint.
- Assess third-party integrations and API endpoints that widened exposure beyond the perimeter.
- Test safely against live production systems without disrupting day-to-day business operations.
- Help the team cut through the noise and prioritize remediation by real-world risk.
Approach
- Ran collaborative scoping and threat modeling to focus effort on what mattered most.
- Performed OWASP-aligned testing across the web applications and their API endpoints.
- Reviewed cloud configuration and identity across AWS, Azure and GCP for weaknesses.
- Built proof-of-concept exploit chains to demonstrate genuine, end-to-end impact.
- Delivered a prioritized, CVSS-rated report and a free retest to verify remediation.