Services

Infrastructure analysis

Complex applications depend on their infrastructure. We examine the environment your application relies on.

A secure application on insecure infrastructure is not secure. DNS, virtualisation, configuration, VPN, management interfaces, databases and test systems are all part of the attack surface. SektionEins examines the individual components and works with you on recommendations for hardening and securing your systems.

How we work

Every analysis starts the way a real attack starts: with a search for information that is already publicly available.

  1. Reconnaissance

    From open sources (open source intelligence, OSINT) we gather what an attacker can find out about you.

    AI-assisted
  2. Map

    AI orchestrates our tools: it drives port and service scans, analyses the results and decides which tool to point where next.

    AI-assisted
  3. Manual testing

    We test critical systems by hand: management interfaces, VPN access, databases and forgotten test systems.

  4. Verify

    Every finding is proven. Suspicious behaviour and bugs that cannot be exploited directly are marked as such in the report.

    AI-assisted

Reconnaissance covers domains and subdomains, DNS records, certificate logs, IP ranges, the software in use, public code repositories and leaked credentials. We also look specifically for information disclosure: backups and configuration files on web servers, open directory listings, version details in banners and error messages, keys and passwords in repositories. AI links the scans with these findings, which gives a complete picture of the attack surface in a short time.

AI is a tool here, not a replacement. It speeds things up and connects the dots, but experienced people assess the findings.

Every penetration test that simulates a real attack from the outside starts with this reconnaissance. An attacker does not start with your application, but with everything they can find out about you.

What we look at

The framework is set by the chapters on information gathering, configuration and deployment, and transport layer security in the OWASP Web Security Testing Guide (WSTG). We go beyond the web application, though, and examine the whole environment:

  • Open ports and services: port scans across your IP ranges, identifying services and versions, known vulnerabilities in outdated software

  • TLS and certificates: protocol versions and cipher suites, key length and signature algorithm, certificate validity and host names, HSTS and redirects to HTTPS

  • DNS and domains: subdomains, zone transfers, dangling records that allow a subdomain takeover, SPF, DKIM and DMARC

  • Web server and platform: the servers, frameworks and versions in use, insecure defaults, permitted HTTP methods, security headers

  • Forgotten files: backups, old and unreferenced files, metafiles such as robots.txt, file extensions that reveal source code or configuration

  • Management interfaces: administrative access to the application and the infrastructure, default passwords

  • VPN and network access: exposure, authentication, network segmentation

  • Databases: exposure to the outside, credentials, how they connect to the application

  • Cloud and virtualisation: cloud storage with overly broad permissions, configuration of hosts and virtual machines

  • Test and staging systems: easily forgotten, often holding real data with weaker protection

  • Hardening: server configuration, file permissions, services that are not needed

Together with you

Infrastructure grows over time, and not every setting can simply be changed. We discuss the findings with your administrators and develop hardening recommendations that can actually be put into practice.

Result

At the end there is always a report. Either brief and to the point, or a detailed report with a description of every vulnerability, a risk assessment and concrete remediation advice.

Let us talk about your application.

Reach us by e-mail, phone or the contact form. PGP-encrypted on request.