Method
What a penetration test is
What a real pentest is: authorised exploitation, reproducible PoC and a human gate. When not to hire Rekon.
A penetration test is not a CVE inventory. It is an authorised attack: someone tries to get in, chains what they find and shows how far it goes. What remains is a report your team can reproduce. A pentest may find no exploitable path. Its quality depends on scope, testing and evidence, not on forcing an exploit.
Straight answers
How is a pentest different from a scanner?
- The scanner lists known weaknesses. The pentest answers what an attacker can achieve with what was found: it exploits under authorisation, chains findings and documents the path. Validation may be limited for safety; the report should explain what was demonstrated and what remained untested.
Who authorizes each intrusive action?
- A person. Agents propose paths and accelerate reconnaissance; they do not sign and they do not fire exploitation alone. Every intrusive action passes a logged human gate. The report is signed by whoever supervised.
When should you NOT hire Rekon?
- If you need Big Four letterhead, we are not the provider. If you want a scanner PDF, neither. If nobody on your side will remediate, the report becomes an anxiety document. If continuity is critical, we agree on the environment, windows, limits and stop conditions; we do not guarantee zero risk. And if you need a turnaround published on the web, we will not put one: the window is fixed in the contract.
Time to test your doors?
Tell us what needs validating. We answer with proposed scope, not a brochure.