A structured, evidence-based methodology.
Authorized, repeatable, and built around findings you can act on, with practical verification guidance where applicable.
Core principles
The non-negotiables every engagement runs by.
Authorization required
We do not conduct any testing without explicit written authorization from the asset owner. No exceptions.
Service-specific scope
Techniques and intrusiveness are defined by the selected service and written rules of engagement.
Evidence before conclusions
Confirmed findings are tied to source evidence and reproducible observations, not scanner output alone.
Human-owned judgement
Felix Gutierrez, founder of Prox Offensive, owns testing decisions, evidence validation, business-context judgement, and every report conclusion.
Human-owned, AI-assisted
AI helps organize evidence, structure notes, and surface first-pass patterns. It does not set scope, run unsupervised client testing, validate findings, or make final risk calls. Felix Gutierrez, founder of Prox Offensive, owns testing decisions, evidence validation, business-context judgement, and every report conclusion.
Client data stays local by default. A cloud-hosted AI service is used only when it offers a clear engagement benefit and the client has explicitly approved the specific data flow. AI output is treated as untrusted draft material: conclusions are checked against source evidence and live results, high-impact findings are manually revalidated, and ambiguous issues receive a clean second-pass review or an approved specialist opinion.
Service-specific testing
The External Exposure Audit Sprint uses passive reconnaissance and active, non-intrusive validation. Penetration Testing and Application Security Testing may include controlled active testing and proof-of-concept only within explicit written scope.
Passive Reconnaissance
DNS enumeration, certificate transparency, WHOIS, subdomain discovery, and technology fingerprinting. No direct interaction with target systems.
Active Validation
Port scanning, service identification, version detection, and configuration analysis. Direct but non-intrusive interaction with in-scope systems.
Vulnerability Identification
Analysis of exposed services, outdated software, misconfigurations, sensitive data exposure, and authentication weaknesses.
Prioritized Reporting
Findings categorized by business risk, with clear remediation guidance and evidence for each issue.
Techniques
Standard external reconnaissance, tuned to your scope.
- Passive DNS enumeration and certificate transparency analysis
- Subdomain discovery and attack-surface mapping
- Active port scanning (TCP top 1000 ports)
- Service fingerprinting and version detection
- SSL/TLS configuration review
- Security header analysis
Notification protocol
Validated critical findings are reported within 24 hours through the secure contact agreed at kickoff. Testing pauses if continued activity could increase risk.
Audit Sprint boundaries
The External Exposure Audit Sprint does not include:
- Internal network vulnerabilities
- Application-layer logic flaws (requires authenticated testing)
- Social engineering or phishing simulation
- Physical security assessment
- Source code review
- Wireless network testing
These exclusions apply only to the External Exposure Audit Sprint. Penetration Testing and Application Security Testing use separate written scopes. For other coverage, we can discuss expanded scope or recommend appropriate partners.
Data handling
The default boundary; engagement-specific requirements are agreed during scoping.
- Client data stays local by default
- No client data is sent to a cloud AI service unless the client has explicitly approved the specific data flow
- Any approved specialist access is disclosed before work begins
How we rate findings
Each finding is rated by practical impact, with evidence and a fix.
Immediate risk: exploitable exposure or critical misconfiguration.
Meaningful weakness that raises risk or fails compliance checks.
Hardening opportunity or information disclosure, low effort to fix.
Download an illustrative synthetic sample report showing the structure, evidence style, and remediation detail used in Prox Offensive reporting.
Ready to find out what's exposed?
Book a short call, tell us what you're running, and we'll scope the right engagement.
