Prox OffensiveInformation Security
How we work

A structured, evidence-based methodology.

Authorized, repeatable, and built around findings you can act on, with practical verification guidance where applicable.

Core principles

The non-negotiables every engagement runs by.

Authorization required

We do not conduct any testing without explicit written authorization from the asset owner. No exceptions.

Service-specific scope

Techniques and intrusiveness are defined by the selected service and written rules of engagement.

Evidence before conclusions

Confirmed findings are tied to source evidence and reproducible observations, not scanner output alone.

Human-owned judgement

Felix Gutierrez, founder of Prox Offensive, owns testing decisions, evidence validation, business-context judgement, and every report conclusion.

Human-owned, AI-assisted

AI helps organize evidence, structure notes, and surface first-pass patterns. It does not set scope, run unsupervised client testing, validate findings, or make final risk calls. Felix Gutierrez, founder of Prox Offensive, owns testing decisions, evidence validation, business-context judgement, and every report conclusion.

Client data stays local by default. A cloud-hosted AI service is used only when it offers a clear engagement benefit and the client has explicitly approved the specific data flow. AI output is treated as untrusted draft material: conclusions are checked against source evidence and live results, high-impact findings are manually revalidated, and ambiguous issues receive a clean second-pass review or an approved specialist opinion.

Service-specific testing

The External Exposure Audit Sprint uses passive reconnaissance and active, non-intrusive validation. Penetration Testing and Application Security Testing may include controlled active testing and proof-of-concept only within explicit written scope.

1

Passive Reconnaissance

DNS enumeration, certificate transparency, WHOIS, subdomain discovery, and technology fingerprinting. No direct interaction with target systems.

2

Active Validation

Port scanning, service identification, version detection, and configuration analysis. Direct but non-intrusive interaction with in-scope systems.

3

Vulnerability Identification

Analysis of exposed services, outdated software, misconfigurations, sensitive data exposure, and authentication weaknesses.

4

Prioritized Reporting

Findings categorized by business risk, with clear remediation guidance and evidence for each issue.

Techniques

Standard external reconnaissance, tuned to your scope.

  • Passive DNS enumeration and certificate transparency analysis
  • Subdomain discovery and attack-surface mapping
  • Active port scanning (TCP top 1000 ports)
  • Service fingerprinting and version detection
  • SSL/TLS configuration review
  • Security header analysis

Notification protocol

Validated critical findings are reported within 24 hours through the secure contact agreed at kickoff. Testing pauses if continued activity could increase risk.

Audit Sprint boundaries

The External Exposure Audit Sprint does not include:

  • Internal network vulnerabilities
  • Application-layer logic flaws (requires authenticated testing)
  • Social engineering or phishing simulation
  • Physical security assessment
  • Source code review
  • Wireless network testing

These exclusions apply only to the External Exposure Audit Sprint. Penetration Testing and Application Security Testing use separate written scopes. For other coverage, we can discuss expanded scope or recommend appropriate partners.

Data handling

The default boundary; engagement-specific requirements are agreed during scoping.

  • Client data stays local by default
  • No client data is sent to a cloud AI service unless the client has explicitly approved the specific data flow
  • Any approved specialist access is disclosed before work begins

How we rate findings

Each finding is rated by practical impact, with evidence and a fix.

High

Immediate risk: exploitable exposure or critical misconfiguration.

Medium

Meaningful weakness that raises risk or fails compliance checks.

Low

Hardening opportunity or information disclosure, low effort to fix.

Download an illustrative synthetic sample report showing the structure, evidence style, and remediation detail used in Prox Offensive reporting.

Ready to find out what's exposed?

Book a short call, tell us what you're running, and we'll scope the right engagement.