Home / Solutions / Pentest and Red Team

Offensive security

Pentest and Red Team

We test like an attacker. We prioritize like part of your team.

Manual pentests of web applications, APIs, mobile, cloud and infrastructure to find exploitable vulnerabilities and understand the business impact of each one. Findings come prioritized, with remediation guidance and retesting.

What is a pentest?

A pentest, or penetration test, is an authorized assessment in which specialists try to exploit vulnerabilities in the systems defined in scope. The result shows how each flaw could be used, what the impact is and what to fix first. At Taura, tests are manual, supported by tools, and the report serves both the technical team and the board.

Pentest or Red Team?

A pentest investigates the vulnerabilities of the systems in scope. A Red Team simulates an attack with a defined goal, such as reaching sensitive data, and shows how the company prevents, detects and responds. Techniques, limits and success criteria are agreed before starting.

OWASP WSTGOWASP ASVSOWASP MASVSPTESNIST SP 800-115MITRE ATT&CK
Context

When to put your security to the test

A customer or partner asked for evidenceThe report and the attestation letter document what was tested and how findings were handled.
A product or integration is going liveTesting flows and permissions before launch costs less than fixing them later.
The environment changedNew features, migrations or architecture changes open paths worth a new round.
A standard requires testingThe scope is designed around what the standard or contract requires.
You want to know how your team reactsIn a Red Team engagement, the focus is on measuring prevention, detection and response.
Scope

What the test can cover

Web applications and APIsAuthentication, authorization, integrations, business rules and transactional flows, in REST or GraphQL.
Mobile appsLocal storage, communication, embedded credentials and backend interaction, on Android and iOS.
CloudIdentities, permissions and exposures in AWS, Azure and Google Cloud.
InfrastructureInternal and external network, Active Directory, VPN and segmentation.
Red TeamSimulations with a defined goal. Social engineering only when agreed and authorized.
AI applicationsAuthorization, integrations and data exposure in systems that use language models.
Method

How the test works

ScopeWe define systems, access, windows and goals.
UnderstandingWe map flows and possible exploitation paths.
ExecutionManual testing with supporting tools and references such as OWASP WSTG, MASVS and NIST SP 800-115.
Immediate noticeCritical findings are reported through the agreed channel, without waiting for the report.
ReportEvidence, severity, impact and recommendations, with an executive summary.
RetestWe validate the fixes and record the result.
FAQ

Frequently asked questions

How often should you run a pentest?

It depends on changes in the environment and the requirements that apply to the company. The most common approach is a periodic round, with extra tests after launches, migrations or architecture changes. Rules such as those of the Central Bank of Brazil and PCI DSS set their own frequencies.

Does a pentest replace a vulnerability scanner?

No, they complement each other. A scanner finds known issues at scale. A pentest investigates and validates exploitation paths, including business logic flaws and chained vulnerabilities that automated tools tend to miss.

Can the test affect production?

It can, which is why planning comes first. We agree on limits, windows, contact channels and how to stop the test if needed. The choice between production and staging depends on how similar the environments are and on the goal of the test.

What is in the report?

An executive summary to support decisions and technical detail on each finding, with evidence, severity, impact and a remediation recommendation. After the retest, we record the final status and issue the attestation letter.

Does the attestation letter prove the company is secure?

It documents the scope, period and results of the test. It does not guarantee the absence of vulnerabilities, nor does it replace audits, certifications or day-to-day controls.

Leave your details and a Taura expert will get in touch to talk about what your business needs.

How can we help?
How did you hear about Taura? optional
WhatsApp