Phase 1: Scoping and Quoting
Every engagement begins with scoping, defining exactly what systems, applications, and users are in scope. Grid32 offers an online quote builder that lets you define your scope and receive a price without a sales call. We review and issue a Statement of Work typically within one business day.
Phase 2: Pre-Test Coordination
After the SOW is executed, we schedule the engagement and exchange technical prerequisites. For internal tests: VPN or on-site access. For web app tests: test account credentials. We confirm rules of engagement, what's in scope, emergency contacts, and any systems requiring special handling.
Phase 3: Reconnaissance
Our engineers gather information about the target using both passive techniques (OSINT, DNS, certificate transparency logs) and active techniques (network scanning, service enumeration). The goal: develop a comprehensive map of the attack surface before exploitation begins.
Phase 4: Scanning and Enumeration
We systematically probe all in-scope systems to identify running services, versions, and configurations, producing a detailed inventory and initial identification of exploitable weaknesses.
Phase 5: Exploitation and Privilege Escalation
Our engineers attempt to exploit discovered vulnerabilities, chain issues together, escalate privileges, and move laterally through the environment. Every successful exploitation is documented with evidence. We never cause damage or data loss, the goal is proof of impact.
Phase 6: Reporting
All findings are compiled into a comprehensive report, every vulnerability ranked by severity with evidence, business impact assessment, and specific remediation guidance. Reports are reviewed internally before delivery.
Phase 7: Debrief and Remediation Support
We walk through findings with your team, answer questions, and help prioritize your response. Many clients return for a follow-up assessment after remediation to verify that issues have been resolved.
Frequently Asked Questions
What are the phases of a penetration test?
A typical engagement moves through scoping and quoting, pre-test coordination, reconnaissance, scanning and enumeration, exploitation and privilege escalation, reporting, and a debrief with remediation support. Each phase builds toward proving real attack paths and helping you close them.
What happens before testing begins?
Before testing, Grid32 confirms scope, executes agreements, and coordinates timing, contacts, and any credentials or access. This pre-test coordination avoids surprises and keeps the engagement from disrupting operations.
What happens after a penetration test?
After testing, Grid32 delivers a detailed report and an attestation, then holds a debrief to walk through findings and remediation priorities. Post-remediation verification is available to confirm that fixes resolved the issues.
The process is straightforward. The results are actionable.
Start your engagement with an online quote, no sales calls, no pressure.
Build Your Quote →