ASSESSMENT CATALOG
17 Assessment Methodologies
Evidence-based security assessments covering every major attack surface — from wireless and external exposure to AI systems, identity, supply chain, and containerized environments.
Wireless Attack Surface Assessment
The WASA maps every wireless signal radiating from your physical environment — identifying rogue access points, unauthorized Bluetooth devices, HID cloning risks, and misconfigured corporate SSIDs that an attacker within RF range could exploit. Unlike a standard wireless audit that only checks what you've whitelisted, StingPoint performs a full spectrum scan across 2.4 GHz, 5 GHz, and the Bluetooth bands.
Every device broadcasting inside your perimeter is catalogued: corporate, non-corporate, suspicious, and banned. High-value findings typically include rogue APs that have been operating for months without detection, consumer-grade routers plugged in by employees, and BLE peripherals vulnerable to keystroke injection.
What Gets Tested
- Corporate SSID configuration validation and encryption cipher audit
- Rogue access point detection across all broadcast bands
- Non-corporate device enumeration (personal hotspots, IoT, shadow IT)
- Suspicious and banned device identification (deauthentication tools, pineapples)
- HID peripheral risk assessment (wireless keyboard/mouse cloning vectors)
- Bluetooth enumeration and pairing exposure review
- Evil twin and SSID spoofing feasibility analysis
Public Attack Surface Assessment
The PASA maps your organization's entire publicly visible attack surface using the same passive reconnaissance techniques an external attacker would use before launching a campaign. No credentials, no network access, no site visits required — everything is gathered from publicly available sources and open intelligence feeds.
Deliverables include a complete external asset inventory, subdomain enumeration, exposed service fingerprinting, SSL/TLS posture review, and lookalike domain detection. The PASA is typically the entry point for all StingPoint engagements because it establishes the baseline from which every other assessment draws context.
What Gets Mapped
- Subdomain discovery and uncatalogued asset detection
- Exposed port and service fingerprinting on external-facing infrastructure
- SSL/TLS certificate chain validation and expiration risk
- Email security posture (SPF, DKIM, DMARC configuration)
- Lookalike and typosquat domain registration monitoring
- Public code repository exposure (secrets, credentials, internal paths)
- Technology stack fingerprinting for CVE correlation
Advanced Vulnerability & Risk Assessment
The AVRA goes beyond automated scanner output to deliver business-contextualized vulnerability findings. Using authenticated scanning combined with manual validation, every finding is triaged for exploitability in your specific environment — eliminating the false positives that cause internal teams to deprioritize real risk.
Risk scoring is mapped to business impact, not just CVSS base scores. A critical CVSS vulnerability on a development system with no network access gets scored differently than a medium CVSS finding on a system holding PII. That context is what makes the AVRA actionable rather than just comprehensive.
What Gets Assessed
- Authenticated internal and external vulnerability scanning
- Manual validation to eliminate false positives before delivery
- Business-impact contextualization of all findings
- Patch gap analysis against published CVE timelines
- Compensating control identification for unpatched systems
- Prioritized remediation roadmap with remediation difficulty ratings
Physical Security & Red Team Assessment
The PSRA evaluates the physical layer of your security posture — the controls that prevent an attacker from walking through your door, tailgating into a restricted zone, or plugging a rogue device into an open network port. Most organizations have significant physical security gaps that would never appear in a network scan or a compliance questionnaire.
StingPoint conducts covert assessment scenarios designed to test actual employee behavior and physical access controls under realistic conditions — not staged walkthroughs.
Scenarios Evaluated
- Tailgating and piggybacking entry resistance testing
- Social engineering physical access pretexts (vendor, contractor, delivery)
- Badge reader and access control system analysis
- CCTV coverage gap mapping and blind spot identification
- Rogue device implantation feasibility (drop USB, LAN tap)
- Clean desk and document exposure assessment
- Secure area boundary testing
Security Governance & Controls Assessment
The SGCA evaluates your security program against the CIS Controls v8 framework — the most widely referenced benchmark used by auditors, insurers, and regulators to assess security program maturity. Every control is reviewed for documented policy, actual implementation evidence, and measurement capability.
The output is a structured gap register that maps your current state against each CIS v8 control group, identifies missing policy documentation, and produces the evidence package that auditors explicitly request during SOC 2, CMMC, and cyber insurance renewal reviews.
Framework Coverage
- CIS Controls v8 full implementation group assessment
- Policy documentation inventory and gap identification
- Control measurement and evidence collection review
- SOC 2 readiness mapping (Common Criteria)
- CMMC Level 1 and Level 2 practice alignment
- Cyber insurance questionnaire pre-population support
- Executive security program maturity scorecard
Web Application & API Risk Assessment
The WARA tests your web-facing applications for exploitable vulnerabilities using a combination of automated scanning and manual penetration testing against the OWASP Top 10 and the OWASP API Security Top 10. Automated tools find the known-signature findings — human operators find the logic flaws, privilege escalation paths, and broken access control scenarios that scanners miss.
Testing Coverage
- OWASP Top 10 manual testing (injection, auth, access control, etc.)
- OWASP API Security Top 10 endpoint assessment
- Authenticated and unauthenticated session testing
- Business logic flaw identification
- API authentication and authorization bypass attempts
- Sensitive data exposure and excessive response data review
- Rate limiting and input validation enforcement testing
Cloud Infrastructure & Risk Assessment
The CIRA audits cloud infrastructure against the CIS Cloud Benchmarks — evaluating IAM privilege creep, network security group configurations, storage bucket exposure, workload patch state, and logging coverage across AWS, Azure, and Google Cloud environments.
Cloud Controls Evaluated
- IAM role and permission privilege creep analysis
- Storage bucket and blob access control review
- Network security group and firewall rule audit
- Workload vulnerability and patch state review
- Logging, monitoring, and alerting coverage validation
- Secrets management and credential exposure review
- CIS Cloud Benchmark v2 scoring by control category
Azure Adversarial Posture Review
The AAPR performs a read-only adversarial configuration analysis of your Microsoft Entra ID tenant and AzureRM environment — mapping the exact permission chains, identity attack paths, and misconfiguration combinations that nation-state actors and ransomware operators actively exploit against Azure and M365. No offensive techniques are executed against the tenant. Access is via Graph API and AzureRM read permissions only.
Where CIRA validates infrastructure posture against CIS Benchmarks, the AAPR answers a different question: if an attacker compromises a single identity in your tenant, what can they reach, and how fast? The output includes kill chain coverage matrices, attack path narratives with current threat actor attribution, and a remediation priority register tiered by 7-day and 90-day windows.
What Gets Assessed
- Service principal permission enumeration — Graph API, AppRole assignments, dangerous permission combinations
- Privileged role audit — Global Administrator count, service principals in GA roles, break-glass account hygiene
- Conditional Access gap analysis — phishing-resistant MFA enforcement, legacy authentication exposure
- Managed Identity privilege mapping — VM-to-IMDS-to-subscription escalation paths
- PIM configuration review — permanent vs. just-in-time privileged role assignments
- Key Vault access control — secret, key, and certificate access by non-baseline principals
- Attack path chaining — SP to tenant compromise, VM to IMDS to Key Vault to directory takeover
- Stale account and hybrid identity sync gap identification
- Kill chain coverage matrix mapped across Initial Access through Impact phases
Active Directory Risk Assessment
The ADRA maps your on-premises Active Directory environment using the same adversarial toolset deployed by ransomware operators before lateral movement — BloodHound attack path graph analysis, Kerberos abuse path enumeration, delegation configuration review, and privileged group audit. Most enterprise AD environments have accumulated years of organic misconfiguration that has never been mapped from an attacker's perspective.
The ADRA surfaces the specific permission chains that lead from a standard domain user to Domain Admin or Enterprise Admin, including paths that bypass traditional security controls entirely. For hybrid environments, ADRA pairs directly with AAPR to provide end-to-end identity attack path coverage from on-premises AD through Entra ID.
What Gets Assessed
- BloodHound attack path analysis — shortest paths from standard users to Domain Admin and Enterprise Admin
- Kerberoastable service account enumeration and password strength exposure assessment
- AS-REP roasting exposure — accounts without Kerberos pre-authentication required
- Unconstrained and constrained delegation configuration review
- DCSync rights enumeration — accounts with replication permissions outside domain controllers
- AdminSDHolder abuse path and SDProp misconfiguration review
- GPO write permission mapping — who can modify Group Policy Objects and to which OUs
- Domain trust relationship audit and SID history abuse path review
- Privileged group membership audit: Domain Admins, Enterprise Admins, Schema Admins, Account Operators
- LAPS deployment gap identification and local admin password reuse exposure
- KRBTGT account hygiene and Golden Ticket residual risk assessment
Container & Kubernetes Security Assessment
The CKSA evaluates the security posture of containerized workload environments against the CIS Kubernetes Benchmark and NSA/CISA Kubernetes Hardening Guidance. Container and Kubernetes misconfigurations are among the fastest-growing attack surfaces in cloud environments — exposed dashboards, over-permissioned service accounts, secrets stored in environment variables, and absent network policy enforcement are routinely found in production clusters that have never been assessed.
The CKSA combines automated configuration scanning with manual review of cluster architecture, RBAC permission graphs, and workload security posture. Every finding is validated against actual cluster state — not just configuration files — and is accompanied by developer-ready remediation guidance. Natural pairing with CIRA and AAPR for full cloud attack surface coverage.
What Gets Assessed
- Kubernetes cluster configuration validation against CIS Benchmark v1.9
- RBAC role and ClusterRole permission review — over-privileged service accounts and wildcard verb grants
- Secrets management audit — env var exposure, mounted secrets hygiene, external secrets operator configuration
- Network policy enforcement — inter-pod communication segmentation and egress filtering coverage
- Container image vulnerability scanning — base image CVE exposure and outdated layer identification
- Pod Security Standards and Admission Controller enforcement review
- Exposed attack surface detection — API server, dashboard, etcd, and kubelet access from outside the cluster
- Privileged container and host path mount identification — escape vector enumeration
- etcd access control and encryption at rest validation
- Image registry access control — pull secret hygiene, unsigned image acceptance, registry exposure
- Runtime security tool coverage review (Falco, Sysdig, Aqua, or equivalent)
Artificial Intelligence Threat Assessment
The AITA is designed for organizations that have deployed LLMs, AI agents, copilots, or machine learning systems in production environments. AI systems introduce a new class of attack surface — prompt injection, training data extraction, model inversion, jailbreak escalation, and supply chain risks through third-party model providers.
StingPoint evaluates AI deployments against the OWASP LLM Top 10 and the MITRE ATLAS framework.
AI Attack Vectors Tested
- Prompt injection and indirect prompt injection testing
- Jailbreak and guardrail bypass attempts
- Sensitive data exposure through model output
- Training data extraction and memorization probing
- Excessive agency and autonomous action risk review
- Third-party model supply chain dependency assessment
- OWASP LLM Top 10 and MITRE ATLAS mapping
Dark Web Intelligence & Reconnaissance Assessment
The DIRA queries dark web markets, breach aggregation forums, Telegram channels, and criminal intelligence feeds to surface active exposure of your organization's credentials, internal data, and infrastructure details. Most credential exposures are discovered by attackers months before the targeted organization becomes aware — the DIRA closes that intelligence gap.
Intelligence Sources Queried
- Dark web credential breach databases and combo list repositories
- Criminal Telegram channels and underground forums
- Stealer malware log aggregation feeds
- Public code repositories (GitHub, GitLab, Pastebin) for secrets exposure
- Threat actor infrastructure correlation to known campaign TTPs
- Domain reputation and blacklist status monitoring
- Lookalike infrastructure used in active phishing campaigns
Supply Chain & Vendor Risk Assessment
The SCRA maps the security risk introduced through your third-party relationships — vendors with network or system access, software dependencies with known vulnerabilities, CI/CD pipeline integrations pulling from public registries, and OAuth applications granted broad permissions to your M365 or Google Workspace environment. Most organizations have no accurate inventory of external access grants or software supply chain exposure.
Third-party supply chain compromise drives nearly half of all breaches according to current threat intelligence. Vulnerability exploitation surpassed stolen credentials as the leading entry vector for the first time in 19 years. SCRA builds the inventory and attack surface map that turns those statistics into specific, prioritized findings for your environment — and produces the evidence package that cyber insurance underwriters now routinely request during renewals.
What Gets Assessed
- Third-party vendor access inventory — VPN, RDP, API keys, SSO federation, and jump host access grants
- Software Bill of Materials (SBOM) generation and CVE correlation for production dependencies
- Open-source dependency risk — known-compromised packages, typosquatted packages, abandoned maintainers
- CI/CD pipeline third-party integration audit — GitHub Actions, npm, PyPI, Docker Hub supply chain exposure
- OAuth and API token scope review — third-party apps with overly broad permissions to M365, Google Workspace, or Salesforce
- Contractor and MSP access privilege review — account hygiene, MFA enforcement, offboarding gaps
- Vendor security posture correlation — public exposure of vendor infrastructure aligned to your access grants
- Third-party data handling vs. actual access scope comparison
Phishing & Employee Security Awareness Assessment
The PESA runs structured, multi-vector phishing simulations across your employee population — measuring click rates, credential submission rates, reporting behavior, and time-to-click by department and role. Simulation campaigns use actual threat actor templates sourced from current campaigns targeting your industry vertical.
Simulation Variables Measured
- Click-through rate by department and role
- Credential submission rate (landing page yield)
- Reporting rate — employees who flagged the simulation
- Time-to-click distribution across employee population
- Multi-vector campaigns: email, SMS vishing, and voice scenarios
- Campaign template selection based on active industry threat actor TTPs
Endpoint & EDR Security Assessment
The EESA validates that your endpoint detection and response tools are actually enforcing the policies you've configured — not just installed. Testing includes simulated attack technique execution mapped to the MITRE ATT&CK framework to validate detection and response coverage, EDR policy configuration review, and endpoint hygiene assessment.
Validation Coverage
- EDR policy configuration and enforcement review
- MITRE ATT&CK technique simulation for detection validation
- Coverage gap identification by attack phase
- Managed vs. unmanaged device inventory reconciliation
- Endpoint hygiene review (patch state, encryption, local admin audit)
- Alert triage and escalation process review
Firewall & Network Architecture Risk Assessment
The FNRA audits your network perimeter controls and internal segmentation architecture — evaluating firewall ruleset hygiene, network segment isolation effectiveness, inter-VLAN routing controls, and traffic inspection coverage. Internal segmentation is evaluated against the assumption that perimeter defenses have already been bypassed.
Network Controls Reviewed
- Firewall ruleset audit and policy hygiene review
- Network segmentation and VLAN isolation effectiveness
- Ingress and egress traffic filtering validation
- Inter-segment lateral movement path analysis
- Remote access and VPN configuration review
- Network monitoring and traffic inspection coverage
- DMZ architecture and public-facing service isolation review
Incident Response Readiness Assessment
The IRRA evaluates your organization's ability to detect, contain, and recover from a security incident before one actually occurs. Includes a structured tabletop exercise using a realistic breach scenario tailored to your industry vertical, a review of existing IR documentation, and an evaluation of detection-to-response timelines.
Readiness Components Evaluated
- IR plan documentation review and gap analysis
- Structured tabletop exercise with industry-specific breach scenario
- Escalation chain and communication tree validation
- Detection and alerting coverage review by attack phase
- Backup and recovery procedure testing and documentation review
- Forensic logging coverage (retention, completeness, availability)
- NIST CSF Respond and Recover function mapping
Email & Messaging Threat Assessment
The EMTA evaluates your email infrastructure posture against the full spectrum of email-based attack techniques — from SPF/DKIM/DMARC configuration weaknesses that enable domain spoofing, to lookalike domain registrations designed to support BEC campaigns, to mail exchanger configurations that reveal internal routing architecture to external observers.
Email Attack Surface Reviewed
- SPF record configuration and enforcement level assessment
- DKIM selector enumeration and signing key validation
- DMARC policy enforcement mode and reporting configuration
- MX record architecture and email routing exposure
- Lookalike and typosquat domain detection and activity monitoring
- BEC pre-condition identification (executive email exposure, vendor relationship mapping)
- Email gateway configuration and filtering effectiveness review
INITIATE AN ASSESSMENT
Ready to see what an attacker sees before they move?
Validate your technical control posture and map your external exposure before an attacker does it for you.
