StingPoint Programmatic Tiers
Programmatic cybersecurity offerings structured as continuous evaluation cycles to align threat validation with organization maturity.
Ghost Recon
Zero-access required. Maps external boundary exposures exactly what an outside attacker already scans.
Sentinel
Validates active security enforcement controls across perimeter targets, configurations, and core endpoints.
Vanguard
Full-program coverage — testing every primary digital interface, operational boundary, and human vector.
Operator Zero
Complete consulting deployment catalog. Comprehensive mapping across all vectors with zero blind spots.
Specialty Add-On Packages
Skyfall
For cloud-native and containerized environments. Auditing IAM privilege creep, Kubernetes configuration drift, and cloud perimeter rules.
Codebreaker
Engineered for SaaS properties and application builders. Fuzzing service logic, exposed APIs, autonomous models, and dependency chains.
Social Vector
Human layer perimeter analysis auditing social susceptibility, phishing loops, and adjacent physical gaps.
Audit Armor
Audit readiness generation. Compiling structural data packages for compliance reviews, framework mappings, and insurance renewals.
Identity Strike
Full-spectrum identity attack path coverage from on-premises Active Directory through Entra ID — mapping every hop from standard user to Domain Admin to tenant takeover.
AAPR
Azure Adversarial Posture Review. Read-only Entra ID identity attack path analysis — service principals, managed identities, PIM gaps, kill chain mapping.
Package Architecture Deep Dives
Ghost Recon is StingPoint's entry-level engagement and the natural first step for any organization that has never had a formal security assessment. It requires nothing from the client beyond a list of corporate domains — no network access, no agent installation, no site visit. Every assessment in this package is passive or intelligence-driven, meaning it can be initiated immediately and delivers findings within days of kickoff.
Sentinel expands Ghost Recon's external intelligence picture into a full internal controls validation. Where Ghost Recon answers what attackers already know, Sentinel answers whether the defenses you've built would actually stop them. This tier adds vulnerability scanning with business-contextualized risk scoring, firewall and network architecture review, endpoint EDR coverage validation, and a CIS v8 governance gap assessment.
Vanguard is StingPoint's flagship package and the most comprehensive security program available short of the full fourteen-assessment catalog. It covers every major attack surface — external perimeter, wireless, dark web, email, endpoints, network, cloud, web applications, physical security, governance, human layer, and incident response — producing a complete, scored baseline across the entire security program.
Operator Zero is the full StingPoint assessment program — all fourteen engagements, every attack surface, zero exclusions. It includes everything in Vanguard plus the Artificial Intelligence Threat Assessment (AITA), making it the appropriate package for any organization that has deployed LLMs, AI agents, or machine learning systems in production environments where a compromise would carry business or regulatory consequences.
Recommended Programmatic Annual Cadence
| Quarter | Engagement | Focus Area | Strategic Deliverable Output |
|---|---|---|---|
| Q1 | Ghost Recon | Refresh external boundaries posture — domains, dark web, wireless, email | Updated exposure baseline, credential rotation trigger list |
| Q2 | Skyfall or Codebreaker | Deep-dive tracking on highest-risk domain (cloud environment or software file layer) | Domain-specific security findings registry with prioritized mitigation roadmap |
| Q3 | Social Vector or Audit Armor | Human layer performance review or framework compliance evidence alignment cycle | Phishing baseline penetration update metrics or audit-ready evidence package assets |
| Q4 | Vanguard or Operator Zero | Full spectrum assessment sweep for end-of-year leadership performance audits | Complete risk posture profile report, board-ready executive dashboard summary, trend analysis |
Commercial Package Specifications & Sell Sheets
Ghost Recon
Zero access required. Maps what attackers already see — in days, not weeks.
- No network access, no agent installs, no site visit required — engagement starts immediately.
- Findings delivered within 72 hours of kickoff on the PASA and DIRA components.
- Every engagement includes executive summary, risk-scored findings, and remediation roadmap.
- DIRA consistently surfaces credential exposures clients didn't know existed.
Ideal For: First-time security assessment. Cyber insurance application or renewal. Any organization that wants to understand their external exposure before committing to a full program.
Included Deliverables: Executive summary · External asset inventory · Dark web exposure report · Email security posture · Lookalike domain register · Remediation roadmap.
Sentinel
Validates your controls — not just your documentation.
- Covers external exposure AND internal control validation in a single engagement.
- SGCA produces the CIS v8 gap matrix that auditors and insurers are directly asking for.
- EESA and FNRA validate that deployed tools are actually enforcing policy — not just installed.
Ideal For: Organizations preparing for SOC 2, CMMC, or cyber insurance renewal. Companies that have deployed security tools and want to validate coverage.
Vanguard
Full-program coverage. Every major attack surface. One engagement.
Operator Zero
The complete catalog. Every assessment. No blind spots.
Specialty Add-On Sheets
Skyfall
Validates IAM configurations, network boundary posture, and workload exposures.
- Covers the three primary cloud breach vectors: over-privileged IAM permissions, firewall configurations, and unpatched workloads.
- CIS Cloud Benchmark scoring delivers a defensible compliance posture baseline.
Ideal For: Cloud-native startups, SaaS firms, and migrated properties.
Included Deliverables: Cloud risk summary · IAM risk register · CIS benchmark scorecard · Network architecture findings · Patch risk register.
Codebreaker
Tests web apps, APIs, and AI models for exploitable security vulnerabilities.
- The only specialty package that wraps AI threat assessment checks into code review lines.
- WARA tests beyond basic automated scripts: handling manual session manipulation and business logic abuse.
Ideal For: SaaS operations, development units, and software groups where the product interface represents the primary vector of systemic business risk.
Social Vector
Evaluates the full human perimeter — phishing, physical boundaries, and underground intelligence leaks.
- Ties all four human-layer vectors together inside a single coordinated assessment engagement.
- PESA delivers structured statistical telemetry sorted granularly by company department and operational roles.
Audit Armor
Compiles the technical evidence packages and gap registers that auditors explicitly review.
INITIATE AN ASSESSMENT
Ready to see what an attacker sees before they move?
Validate your technical control posture and map your external exposure before an attacker does it for you.
