Comprehensive Ethical Hacking Assessment
Budget: ₹600 – ₹1,500 INR
My environment needs a full-spectrum penetration test that zeroes in on two key fronts—network security and application security—without limiting you to any single device or codebase. Think of it as a “white-box” free-roam: map the entire attack surface, exploit what you can, document everything, and then distill clear, prioritized fixes.
Scope
• Network Security: firewalls, routers, VPN endpoints, cloud VPCs, Wi-Fi, and any exposed services.
• Application Security: public-facing web apps, internal portals, APIs, and mobile back-ends.
No prior asset list will be supplied; the first task is discovery. Physical security testing is out of scope for now, but note any overlap or pivot that becomes apparent.
Deliverables
• Executive-level summary (plain language, risk ratings).
• Technical report detailing each finding, PoC steps, screenshots, and CVSS or OWASP scores.
• Remediation roadmap ordered by impact and effort.
• One debrief call to walk through results and answer follow-up questions.
Acceptance Criteria
The engagement is complete when every finding is reproducible from your write-up, recommended fixes are actionable, false-positives are removed, and the debrief session is held.
Tooling is your choice—Nmap, Burp Suite, Metasploit, Nessus, custom scripts—so long as output is well documented and logs are available on request.
Timeline and milestones can be adjusted once you size up the estate; propose your methodology and estimated hours in your bid.
Scope
• Network Security: firewalls, routers, VPN endpoints, cloud VPCs, Wi-Fi, and any exposed services.
• Application Security: public-facing web apps, internal portals, APIs, and mobile back-ends.
No prior asset list will be supplied; the first task is discovery. Physical security testing is out of scope for now, but note any overlap or pivot that becomes apparent.
Deliverables
• Executive-level summary (plain language, risk ratings).
• Technical report detailing each finding, PoC steps, screenshots, and CVSS or OWASP scores.
• Remediation roadmap ordered by impact and effort.
• One debrief call to walk through results and answer follow-up questions.
Acceptance Criteria
The engagement is complete when every finding is reproducible from your write-up, recommended fixes are actionable, false-positives are removed, and the debrief session is held.
Tooling is your choice—Nmap, Burp Suite, Metasploit, Nessus, custom scripts—so long as output is well documented and logs are available on request.
Timeline and milestones can be adjusted once you size up the estate; propose your methodology and estimated hours in your bid.