Comprehensive Vulnerability Assessment Needed
Budget: €250 – €750 EUR
I want a thorough vulnerability assessment performed on our entire stack—public-facing web applications, internal network infrastructure, and the cloud services we run on AWS and Azure. The engagement should mirror real-world attack techniques while remaining fully ethical and non-disruptive to production.
The assessment must dig deep into application logic flaws, misconfigurations, outdated dependencies, lateral-movement paths inside the network, and insecure cloud IAM or storage settings. Industry-standard tooling such as OWASP ZAP, Burp Suite, Nessus, Nmap, Metasploit, and AWS Inspector may be used alongside your own custom scripts; methodology should align with OWASP, NIST, and PTES guidance.
Deliverables
• A comprehensive report for each environment that lists every discovered vulnerability, its CVSS score, proof-of-concept evidence (screenshots, packet captures, or code snippets), and a clear explanation of business impact.
• Actionable remediation recommendations broken down into quick wins and long-term fixes, plus an executive summary suitable for senior management.
• Optional follow-up call or Q&A session to walk through the findings.
Acceptance Criteria
• Report is delivered in PDF within the agreed timeline.
• All findings are reproducible using the steps you provide.
• No critical outages or data loss occur during testing.
Access windows, test credentials, and any needed architecture diagrams will be provided once the scope and timeline are confirmed.
The assessment must dig deep into application logic flaws, misconfigurations, outdated dependencies, lateral-movement paths inside the network, and insecure cloud IAM or storage settings. Industry-standard tooling such as OWASP ZAP, Burp Suite, Nessus, Nmap, Metasploit, and AWS Inspector may be used alongside your own custom scripts; methodology should align with OWASP, NIST, and PTES guidance.
Deliverables
• A comprehensive report for each environment that lists every discovered vulnerability, its CVSS score, proof-of-concept evidence (screenshots, packet captures, or code snippets), and a clear explanation of business impact.
• Actionable remediation recommendations broken down into quick wins and long-term fixes, plus an executive summary suitable for senior management.
• Optional follow-up call or Q&A session to walk through the findings.
Acceptance Criteria
• Report is delivered in PDF within the agreed timeline.
• All findings are reproducible using the steps you provide.
• No critical outages or data loss occur during testing.
Access windows, test credentials, and any needed architecture diagrams will be provided once the scope and timeline are confirmed.