Infrastructure analysis
Complex applications depend on their infrastructure. We examine the environment your application relies on.
A secure application on insecure infrastructure is not secure. DNS, virtualisation, configuration, VPN, management interfaces, databases and test systems are all part of the attack surface. SektionEins examines the individual components and works with you on recommendations for hardening and securing your systems.
How we work
Every analysis starts the way a real attack starts: with a search for information that is already publicly available.
-
Reconnaissance
From open sources (open source intelligence, OSINT) we gather what an attacker can find out about you.
AI-assisted -
Map
AI orchestrates our tools: it drives port and service scans, analyses the results and decides which tool to point where next.
AI-assisted -
Manual testing
We test critical systems by hand: management interfaces, VPN access, databases and forgotten test systems.
-
Verify
Every finding is proven. Suspicious behaviour and bugs that cannot be exploited directly are marked as such in the report.
AI-assisted
Reconnaissance covers domains and subdomains, DNS records, certificate logs, IP ranges, the software in use, public code repositories and leaked credentials. We also look specifically for information disclosure: backups and configuration files on web servers, open directory listings, version details in banners and error messages, keys and passwords in repositories. AI links the scans with these findings, which gives a complete picture of the attack surface in a short time.
AI is a tool here, not a replacement. It speeds things up and connects the dots, but experienced people assess the findings.
Every penetration test that simulates a real attack from the outside starts with this reconnaissance. An attacker does not start with your application, but with everything they can find out about you.
What we look at
The framework is set by the chapters on information gathering, configuration and deployment, and transport layer security in the OWASP Web Security Testing Guide (WSTG). We go beyond the web application, though, and examine the whole environment:
Open ports and services: port scans across your IP ranges, identifying services and versions, known vulnerabilities in outdated software
TLS and certificates: protocol versions and cipher suites, key length and signature algorithm, certificate validity and host names, HSTS and redirects to HTTPS
DNS and domains: subdomains, zone transfers, dangling records that allow a subdomain takeover, SPF, DKIM and DMARC
Web server and platform: the servers, frameworks and versions in use, insecure defaults, permitted HTTP methods, security headers
Forgotten files: backups, old and unreferenced files, metafiles such as
robots.txt, file extensions that reveal source code or configurationManagement interfaces: administrative access to the application and the infrastructure, default passwords
VPN and network access: exposure, authentication, network segmentation
Databases: exposure to the outside, credentials, how they connect to the application
Cloud and virtualisation: cloud storage with overly broad permissions, configuration of hosts and virtual machines
Test and staging systems: easily forgotten, often holding real data with weaker protection
Hardening: server configuration, file permissions, services that are not needed
Together with you
Infrastructure grows over time, and not every setting can simply be changed. We discuss the findings with your administrators and develop hardening recommendations that can actually be put into practice.
Result
At the end there is always a report. Either brief and to the point, or a detailed report with a description of every vulnerability, a risk assessment and concrete remediation advice.