StingPoint Security

ASSESSMENT CATALOG

17 Assessment Methodologies

Evidence-based security assessments covering every major attack surface — from wireless and external exposure to AI systems, identity, supply chain, and containerized environments.

WASAPASAAVRAPSRASGCAWARACIRAAAPRADRACKSAAITADIRASCRAPESAEESAFNRAIRRAEMTA
WASA

Wireless Attack Surface Assessment

Passive · Active · RF Spectrum

The WASA maps every wireless signal radiating from your physical environment — identifying rogue access points, unauthorized Bluetooth devices, HID cloning risks, and misconfigured corporate SSIDs that an attacker within RF range could exploit. Unlike a standard wireless audit that only checks what you've whitelisted, StingPoint performs a full spectrum scan across 2.4 GHz, 5 GHz, and the Bluetooth bands.

Every device broadcasting inside your perimeter is catalogued: corporate, non-corporate, suspicious, and banned. High-value findings typically include rogue APs that have been operating for months without detection, consumer-grade routers plugged in by employees, and BLE peripherals vulnerable to keystroke injection.

What Gets Tested

  • Corporate SSID configuration validation and encryption cipher audit
  • Rogue access point detection across all broadcast bands
  • Non-corporate device enumeration (personal hotspots, IoT, shadow IT)
  • Suspicious and banned device identification (deauthentication tools, pineapples)
  • HID peripheral risk assessment (wireless keyboard/mouse cloning vectors)
  • Bluetooth enumeration and pairing exposure review
  • Evil twin and SSID spoofing feasibility analysis
Deliverables
Executive SummaryRisk-scored findings narrative for leadership
RF Asset InventoryFull wireless device catalog by category
Rogue AP RegisterUnauthorized APs with signal strength and location data
HID Risk ReportWireless peripheral cloning exposure per site
Remediation RoadmapPrioritized action list with control recommendations
Data WorkbookComplete scan dataset in structured Excel format
PASA

Public Attack Surface Assessment

Passive · OSINT · No Access Required

The PASA maps your organization's entire publicly visible attack surface using the same passive reconnaissance techniques an external attacker would use before launching a campaign. No credentials, no network access, no site visits required — everything is gathered from publicly available sources and open intelligence feeds.

Deliverables include a complete external asset inventory, subdomain enumeration, exposed service fingerprinting, SSL/TLS posture review, and lookalike domain detection. The PASA is typically the entry point for all StingPoint engagements because it establishes the baseline from which every other assessment draws context.

What Gets Mapped

  • Subdomain discovery and uncatalogued asset detection
  • Exposed port and service fingerprinting on external-facing infrastructure
  • SSL/TLS certificate chain validation and expiration risk
  • Email security posture (SPF, DKIM, DMARC configuration)
  • Lookalike and typosquat domain registration monitoring
  • Public code repository exposure (secrets, credentials, internal paths)
  • Technology stack fingerprinting for CVE correlation
Deliverables
Executive SummaryExposure narrative for leadership and board
External Asset InventoryAll internet-facing assets by risk tier
Email Posture ReportSPF/DKIM/DMARC configuration findings
Lookalike Domain RegisterActive and inactive lookalike registrations
Cert & Service FindingsExpiring certs, exposed services, version risks
Data WorkbookFull dataset in structured Excel format
AVRA

Advanced Vulnerability & Risk Assessment

Credentialed · Authenticated · Internal Scope

The AVRA goes beyond automated scanner output to deliver business-contextualized vulnerability findings. Using authenticated scanning combined with manual validation, every finding is triaged for exploitability in your specific environment — eliminating the false positives that cause internal teams to deprioritize real risk.

Risk scoring is mapped to business impact, not just CVSS base scores. A critical CVSS vulnerability on a development system with no network access gets scored differently than a medium CVSS finding on a system holding PII. That context is what makes the AVRA actionable rather than just comprehensive.

What Gets Assessed

  • Authenticated internal and external vulnerability scanning
  • Manual validation to eliminate false positives before delivery
  • Business-impact contextualization of all findings
  • Patch gap analysis against published CVE timelines
  • Compensating control identification for unpatched systems
  • Prioritized remediation roadmap with remediation difficulty ratings
Deliverables
Executive SummaryRisk narrative with business-impact context
Vulnerability RegisterValidated findings with business-risk scores
Patch Gap AnalysisCVE timeline vs. current patch state
Remediation RoadmapPrioritized action list by effort and impact
PSRA

Physical Security & Red Team Assessment

On-Site · Covert · Scenario-Based

The PSRA evaluates the physical layer of your security posture — the controls that prevent an attacker from walking through your door, tailgating into a restricted zone, or plugging a rogue device into an open network port. Most organizations have significant physical security gaps that would never appear in a network scan or a compliance questionnaire.

StingPoint conducts covert assessment scenarios designed to test actual employee behavior and physical access controls under realistic conditions — not staged walkthroughs.

Scenarios Evaluated

  • Tailgating and piggybacking entry resistance testing
  • Social engineering physical access pretexts (vendor, contractor, delivery)
  • Badge reader and access control system analysis
  • CCTV coverage gap mapping and blind spot identification
  • Rogue device implantation feasibility (drop USB, LAN tap)
  • Clean desk and document exposure assessment
  • Secure area boundary testing
Deliverables
Executive SummaryPhysical posture narrative for leadership
Entry Point AnalysisAccess control findings by location
Coverage Gap MapCCTV blind spots and monitoring deficiencies
Scenario ResultsDocumented outcomes of covert access attempts
Remediation RoadmapPhysical control improvement recommendations
SGCA

Security Governance & Controls Assessment

Compliance · CIS v8 · Framework Mapping

The SGCA evaluates your security program against the CIS Controls v8 framework — the most widely referenced benchmark used by auditors, insurers, and regulators to assess security program maturity. Every control is reviewed for documented policy, actual implementation evidence, and measurement capability.

The output is a structured gap register that maps your current state against each CIS v8 control group, identifies missing policy documentation, and produces the evidence package that auditors explicitly request during SOC 2, CMMC, and cyber insurance renewal reviews.

Framework Coverage

  • CIS Controls v8 full implementation group assessment
  • Policy documentation inventory and gap identification
  • Control measurement and evidence collection review
  • SOC 2 readiness mapping (Common Criteria)
  • CMMC Level 1 and Level 2 practice alignment
  • Cyber insurance questionnaire pre-population support
  • Executive security program maturity scorecard
Deliverables
CIS v8 Gap RegisterControl-by-control current state vs. target
Maturity ScorecardExecutive summary of program maturity level
Policy InventoryExisting vs. required policy documentation
Audit Evidence PackageStructured evidence for auditor review
RoadmapPrioritized remediation plan by control group
WARA

Web Application & API Risk Assessment

OWASP · Authenticated · Manual Testing

The WARA tests your web-facing applications for exploitable vulnerabilities using a combination of automated scanning and manual penetration testing against the OWASP Top 10 and the OWASP API Security Top 10. Automated tools find the known-signature findings — human operators find the logic flaws, privilege escalation paths, and broken access control scenarios that scanners miss.

Testing Coverage

  • OWASP Top 10 manual testing (injection, auth, access control, etc.)
  • OWASP API Security Top 10 endpoint assessment
  • Authenticated and unauthenticated session testing
  • Business logic flaw identification
  • API authentication and authorization bypass attempts
  • Sensitive data exposure and excessive response data review
  • Rate limiting and input validation enforcement testing
Deliverables
Executive SummaryApplication risk narrative for leadership
Findings RegisterValidated vulnerabilities with CVSS and business context
API InventoryEnumerated endpoints with exposure assessment
PoC EvidenceProof-of-concept documentation for confirmed findings
Remediation RoadmapDeveloper-ready fix guidance per finding
CIRA

Cloud Infrastructure & Risk Assessment

AWS · Azure · GCP · IAM · CIS Benchmarks

The CIRA audits cloud infrastructure against the CIS Cloud Benchmarks — evaluating IAM privilege creep, network security group configurations, storage bucket exposure, workload patch state, and logging coverage across AWS, Azure, and Google Cloud environments.

Cloud Controls Evaluated

  • IAM role and permission privilege creep analysis
  • Storage bucket and blob access control review
  • Network security group and firewall rule audit
  • Workload vulnerability and patch state review
  • Logging, monitoring, and alerting coverage validation
  • Secrets management and credential exposure review
  • CIS Cloud Benchmark v2 scoring by control category
Deliverables
Cloud Risk SummaryExecutive narrative on cloud posture
IAM Risk RegisterOver-privileged accounts and roles by risk tier
CIS ScorecardBenchmark scoring by control category
Network FindingsFirewall and NSG misconfiguration report
Remediation RoadmapPrioritized cloud hardening actions
AAPR

Azure Adversarial Posture Review

CIRA Add-On · Entra ID · No Active Exploitation
⬡ CIRA Add-On — Pairs with the Cloud Infrastructure & Risk Assessment for Azure/M365 environments

The AAPR performs a read-only adversarial configuration analysis of your Microsoft Entra ID tenant and AzureRM environment — mapping the exact permission chains, identity attack paths, and misconfiguration combinations that nation-state actors and ransomware operators actively exploit against Azure and M365. No offensive techniques are executed against the tenant. Access is via Graph API and AzureRM read permissions only.

Where CIRA validates infrastructure posture against CIS Benchmarks, the AAPR answers a different question: if an attacker compromises a single identity in your tenant, what can they reach, and how fast? The output includes kill chain coverage matrices, attack path narratives with current threat actor attribution, and a remediation priority register tiered by 7-day and 90-day windows.

What Gets Assessed

  • Service principal permission enumeration — Graph API, AppRole assignments, dangerous permission combinations
  • Privileged role audit — Global Administrator count, service principals in GA roles, break-glass account hygiene
  • Conditional Access gap analysis — phishing-resistant MFA enforcement, legacy authentication exposure
  • Managed Identity privilege mapping — VM-to-IMDS-to-subscription escalation paths
  • PIM configuration review — permanent vs. just-in-time privileged role assignments
  • Key Vault access control — secret, key, and certificate access by non-baseline principals
  • Attack path chaining — SP to tenant compromise, VM to IMDS to Key Vault to directory takeover
  • Stale account and hybrid identity sync gap identification
  • Kill chain coverage matrix mapped across Initial Access through Impact phases
Deliverables
Executive SummaryTenant compromise risk narrative for leadership
Tenant Health SnapshotMFA enforcement, CA policy status, GA count, legacy auth
Attack Path RegisterChained finding narratives with threat actor attribution
Kill Chain Coverage MatrixFinding-by-phase mapping: Initial Access through Impact
MITRE ATT&CK MappingTechnique IDs per finding with active adversary callouts
Remediation Priority Register7-day immediate and 90-day long-term action tiers
Affected Objects InventoryNamed principals, roles, and resources per finding
ADRA

Active Directory Risk Assessment

BloodHound · Attack Paths · Hybrid

The ADRA maps your on-premises Active Directory environment using the same adversarial toolset deployed by ransomware operators before lateral movement — BloodHound attack path graph analysis, Kerberos abuse path enumeration, delegation configuration review, and privileged group audit. Most enterprise AD environments have accumulated years of organic misconfiguration that has never been mapped from an attacker's perspective.

The ADRA surfaces the specific permission chains that lead from a standard domain user to Domain Admin or Enterprise Admin, including paths that bypass traditional security controls entirely. For hybrid environments, ADRA pairs directly with AAPR to provide end-to-end identity attack path coverage from on-premises AD through Entra ID.

What Gets Assessed

  • BloodHound attack path analysis — shortest paths from standard users to Domain Admin and Enterprise Admin
  • Kerberoastable service account enumeration and password strength exposure assessment
  • AS-REP roasting exposure — accounts without Kerberos pre-authentication required
  • Unconstrained and constrained delegation configuration review
  • DCSync rights enumeration — accounts with replication permissions outside domain controllers
  • AdminSDHolder abuse path and SDProp misconfiguration review
  • GPO write permission mapping — who can modify Group Policy Objects and to which OUs
  • Domain trust relationship audit and SID history abuse path review
  • Privileged group membership audit: Domain Admins, Enterprise Admins, Schema Admins, Account Operators
  • LAPS deployment gap identification and local admin password reuse exposure
  • KRBTGT account hygiene and Golden Ticket residual risk assessment
Deliverables
Executive SummaryIdentity risk narrative with business-impact context
BloodHound Attack Path RegisterChained privilege escalation paths by hop count and severity
Kerberos Abuse ReportKerberoastable and AS-REP roastable account inventory
Delegation Risk FindingsUnconstrained and constrained delegation exposure
DCSync Rights RegisterNon-DC accounts with replication privileges
GPO Risk MapWrite-access to Group Policy Objects by principal
Privileged Group InventoryFull membership audit of high-value AD groups
Remediation RoadmapPrioritized hardening actions by attack path severity
CKSA

Container & Kubernetes Security Assessment

K8s · CIS Benchmark · DevSecOps

The CKSA evaluates the security posture of containerized workload environments against the CIS Kubernetes Benchmark and NSA/CISA Kubernetes Hardening Guidance. Container and Kubernetes misconfigurations are among the fastest-growing attack surfaces in cloud environments — exposed dashboards, over-permissioned service accounts, secrets stored in environment variables, and absent network policy enforcement are routinely found in production clusters that have never been assessed.

The CKSA combines automated configuration scanning with manual review of cluster architecture, RBAC permission graphs, and workload security posture. Every finding is validated against actual cluster state — not just configuration files — and is accompanied by developer-ready remediation guidance. Natural pairing with CIRA and AAPR for full cloud attack surface coverage.

What Gets Assessed

  • Kubernetes cluster configuration validation against CIS Benchmark v1.9
  • RBAC role and ClusterRole permission review — over-privileged service accounts and wildcard verb grants
  • Secrets management audit — env var exposure, mounted secrets hygiene, external secrets operator configuration
  • Network policy enforcement — inter-pod communication segmentation and egress filtering coverage
  • Container image vulnerability scanning — base image CVE exposure and outdated layer identification
  • Pod Security Standards and Admission Controller enforcement review
  • Exposed attack surface detection — API server, dashboard, etcd, and kubelet access from outside the cluster
  • Privileged container and host path mount identification — escape vector enumeration
  • etcd access control and encryption at rest validation
  • Image registry access control — pull secret hygiene, unsigned image acceptance, registry exposure
  • Runtime security tool coverage review (Falco, Sysdig, Aqua, or equivalent)
Deliverables
Executive SummaryContainer environment risk narrative for leadership
CIS K8s Benchmark ScorecardControl-by-control current state with pass/fail/N/A
RBAC Risk RegisterOver-privileged roles and service accounts with blast radius assessment
Secrets Exposure ReportSecrets in env vars, configmaps, and improperly mounted volumes
Container Image FindingsCVE inventory by severity with base image recommendations
Network Policy Gap AnalysisMissing segmentation by namespace and workload
Escape Vector RegisterPrivileged containers and host path mounts enabling node breakout
Remediation RoadmapDeveloper-ready hardening actions prioritized by exploitability
AITA

Artificial Intelligence Threat Assessment

LLM · Prompt Injection · Model Security

The AITA is designed for organizations that have deployed LLMs, AI agents, copilots, or machine learning systems in production environments. AI systems introduce a new class of attack surface — prompt injection, training data extraction, model inversion, jailbreak escalation, and supply chain risks through third-party model providers.

StingPoint evaluates AI deployments against the OWASP LLM Top 10 and the MITRE ATLAS framework.

AI Attack Vectors Tested

  • Prompt injection and indirect prompt injection testing
  • Jailbreak and guardrail bypass attempts
  • Sensitive data exposure through model output
  • Training data extraction and memorization probing
  • Excessive agency and autonomous action risk review
  • Third-party model supply chain dependency assessment
  • OWASP LLM Top 10 and MITRE ATLAS mapping
Deliverables
AI Risk SummaryExecutive findings narrative for leadership
LLM Findings RegisterValidated vulnerabilities mapped to OWASP LLM Top 10
ATLAS MappingAttack technique coverage vs. MITRE ATLAS
Supply Chain ReviewThird-party model dependency risk assessment
Remediation RoadmapControl recommendations per AI attack category
DIRA

Dark Web Intelligence & Reconnaissance Assessment

OSINT · Credential Exposure · Underground Monitoring

The DIRA queries dark web markets, breach aggregation forums, Telegram channels, and criminal intelligence feeds to surface active exposure of your organization's credentials, internal data, and infrastructure details. Most credential exposures are discovered by attackers months before the targeted organization becomes aware — the DIRA closes that intelligence gap.

Intelligence Sources Queried

  • Dark web credential breach databases and combo list repositories
  • Criminal Telegram channels and underground forums
  • Stealer malware log aggregation feeds
  • Public code repositories (GitHub, GitLab, Pastebin) for secrets exposure
  • Threat actor infrastructure correlation to known campaign TTPs
  • Domain reputation and blacklist status monitoring
  • Lookalike infrastructure used in active phishing campaigns
Deliverables
Executive SummaryDark web exposure narrative
Credential Exposure ReportLeaked accounts with breach source attribution
Threat Intelligence BriefThreat actor references and campaign indicators
Secret Exposure RegisterAPI keys, tokens, and credentials in public repos
Remediation RoadmapCredential rotation priority list and action plan
Data WorkbookFull dataset in structured Excel format
SCRA

Supply Chain & Vendor Risk Assessment

Third-Party · SBOM · Vendor Access

The SCRA maps the security risk introduced through your third-party relationships — vendors with network or system access, software dependencies with known vulnerabilities, CI/CD pipeline integrations pulling from public registries, and OAuth applications granted broad permissions to your M365 or Google Workspace environment. Most organizations have no accurate inventory of external access grants or software supply chain exposure.

Third-party supply chain compromise drives nearly half of all breaches according to current threat intelligence. Vulnerability exploitation surpassed stolen credentials as the leading entry vector for the first time in 19 years. SCRA builds the inventory and attack surface map that turns those statistics into specific, prioritized findings for your environment — and produces the evidence package that cyber insurance underwriters now routinely request during renewals.

What Gets Assessed

  • Third-party vendor access inventory — VPN, RDP, API keys, SSO federation, and jump host access grants
  • Software Bill of Materials (SBOM) generation and CVE correlation for production dependencies
  • Open-source dependency risk — known-compromised packages, typosquatted packages, abandoned maintainers
  • CI/CD pipeline third-party integration audit — GitHub Actions, npm, PyPI, Docker Hub supply chain exposure
  • OAuth and API token scope review — third-party apps with overly broad permissions to M365, Google Workspace, or Salesforce
  • Contractor and MSP access privilege review — account hygiene, MFA enforcement, offboarding gaps
  • Vendor security posture correlation — public exposure of vendor infrastructure aligned to your access grants
  • Third-party data handling vs. actual access scope comparison
Deliverables
Executive SummarySupply chain risk narrative for leadership
Vendor Access InventoryAll third-party access grants by method, privilege level, and review date
SBOM with CVE CorrelationProduction dependency inventory with exploitability rating
Dependency Risk RegisterCompromised, abandoned, and typosquatted packages
CI/CD Supply Chain FindingsPipeline integration risks by severity
OAuth Scope ReportThird-party application permission overage findings
Contractor Access ReportMSP and contractor account hygiene findings
Remediation RoadmapPrioritized access reduction and dependency update actions
PESA

Phishing & Employee Security Awareness Assessment

Simulated · Multi-Vector · Department Telemetry

The PESA runs structured, multi-vector phishing simulations across your employee population — measuring click rates, credential submission rates, reporting behavior, and time-to-click by department and role. Simulation campaigns use actual threat actor templates sourced from current campaigns targeting your industry vertical.

Simulation Variables Measured

  • Click-through rate by department and role
  • Credential submission rate (landing page yield)
  • Reporting rate — employees who flagged the simulation
  • Time-to-click distribution across employee population
  • Multi-vector campaigns: email, SMS vishing, and voice scenarios
  • Campaign template selection based on active industry threat actor TTPs
Deliverables
Executive SummaryHuman layer risk narrative for leadership
Telemetry ReportClick, submit, and report rates by department
Risk Population MapHighest-risk employee segments for targeted training
Campaign EvidenceTemplates used, send timeline, response data
Training RecommendationsTargeted awareness program guidance per segment
EESA

Endpoint & EDR Security Assessment

EDR Validation · Policy Enforcement · Coverage Gaps

The EESA validates that your endpoint detection and response tools are actually enforcing the policies you've configured — not just installed. Testing includes simulated attack technique execution mapped to the MITRE ATT&CK framework to validate detection and response coverage, EDR policy configuration review, and endpoint hygiene assessment.

Validation Coverage

  • EDR policy configuration and enforcement review
  • MITRE ATT&CK technique simulation for detection validation
  • Coverage gap identification by attack phase
  • Managed vs. unmanaged device inventory reconciliation
  • Endpoint hygiene review (patch state, encryption, local admin audit)
  • Alert triage and escalation process review
Deliverables
EDR Effectiveness ReportDetection coverage validated against ATT&CK techniques
Coverage Gap RegisterTechniques not detected by current deployment
Endpoint Hygiene ReportPatch, encryption, and admin access findings
Remediation RoadmapPolicy and configuration improvement priorities
FNRA

Firewall & Network Architecture Risk Assessment

Architecture Review · Ruleset Audit · Segmentation

The FNRA audits your network perimeter controls and internal segmentation architecture — evaluating firewall ruleset hygiene, network segment isolation effectiveness, inter-VLAN routing controls, and traffic inspection coverage. Internal segmentation is evaluated against the assumption that perimeter defenses have already been bypassed.

Network Controls Reviewed

  • Firewall ruleset audit and policy hygiene review
  • Network segmentation and VLAN isolation effectiveness
  • Ingress and egress traffic filtering validation
  • Inter-segment lateral movement path analysis
  • Remote access and VPN configuration review
  • Network monitoring and traffic inspection coverage
  • DMZ architecture and public-facing service isolation review
Deliverables
Architecture Risk SummaryNetwork posture narrative for leadership
Ruleset Findings RegisterOverly permissive and stale firewall rules
Segmentation AnalysisLateral movement path findings by segment
VPN & Remote Access ReportRemote access configuration findings
Remediation RoadmapPrioritized network hardening actions
IRRA

Incident Response Readiness Assessment

Tabletop · Playbook Review · NIST CSF

The IRRA evaluates your organization's ability to detect, contain, and recover from a security incident before one actually occurs. Includes a structured tabletop exercise using a realistic breach scenario tailored to your industry vertical, a review of existing IR documentation, and an evaluation of detection-to-response timelines.

Readiness Components Evaluated

  • IR plan documentation review and gap analysis
  • Structured tabletop exercise with industry-specific breach scenario
  • Escalation chain and communication tree validation
  • Detection and alerting coverage review by attack phase
  • Backup and recovery procedure testing and documentation review
  • Forensic logging coverage (retention, completeness, availability)
  • NIST CSF Respond and Recover function mapping
Deliverables
IR Readiness ReportExecutive assessment of response capability
Tabletop SummaryExercise outcomes, decision gaps, and lessons identified
Playbook Gap RegisterMissing or incomplete response documentation
Detection Gap MapLogging and alerting coverage deficiencies
Remediation RoadmapIR program improvement priority list
EMTA

Email & Messaging Threat Assessment

BEC · Spoofing · Email Infrastructure

The EMTA evaluates your email infrastructure posture against the full spectrum of email-based attack techniques — from SPF/DKIM/DMARC configuration weaknesses that enable domain spoofing, to lookalike domain registrations designed to support BEC campaigns, to mail exchanger configurations that reveal internal routing architecture to external observers.

Email Attack Surface Reviewed

  • SPF record configuration and enforcement level assessment
  • DKIM selector enumeration and signing key validation
  • DMARC policy enforcement mode and reporting configuration
  • MX record architecture and email routing exposure
  • Lookalike and typosquat domain detection and activity monitoring
  • BEC pre-condition identification (executive email exposure, vendor relationship mapping)
  • Email gateway configuration and filtering effectiveness review
Deliverables
Email Posture SummaryExecutive narrative on email security posture
SPF/DKIM/DMARC ReportAnti-spoofing configuration findings
Lookalike Domain RegisterActive and registered lookalike domains
BEC Pre-Condition ReportTechnical conditions enabling BEC campaign targeting
Remediation RoadmapPrioritized email hardening actions

INITIATE AN ASSESSMENT

Ready to see what an attacker sees before they move?

Validate your technical control posture and map your external exposure before an attacker does it for you.

Select Assessment Target

Select the assessment(s) you are interested in initiating.

Organizational Profile

Help us map the regulatory and compliance parameters surrounding your workspace.

Engagement Context

What's driving this assessment initiative?