PENETRATION TESTING

With our high-ethical, professional certified team and methodology based on NIST SP800-115, we offer a full range of cost-effective services to identify your cyber risks in application, infrastructure, and mobile platforms to meet the requirements of your organisation.

Our Services

What we test

Web Application Penetration Testing

Assess the security level of the application such as web, APIs, thick client, low-code platform, in-house developed or licensed application.

Learn more

Mobile Application Penetration Test

Perform the test on mobile app over Android and iOS with static analysis, dynamic analysis, and network analysis. Our methodology will include APIs and backend system to the scope if necessary.

Learn more

AI Penetration Test

Test AI and LLM applications against the OWASP Top 10 for LLM — prompt injection, RAG, and agent abuse.

Learn more

Infrastructure Penetration Test

Examine the current state of your infrastructure to evaluate your security controls, and to identify the ways attackers might infiltrate, compromise and exploit your digital assets.

Learn more

Vulnerability Assessment

Run a VA scan with our selected well-known and trusted tools to find out what the vulnerabilities the target have and suggest ways to mitigate it.

Learn more

PCI DSS Penetration Test

Based-on NIST SP800-115 methodology, we could offer services convering PCI DSS requirement 11 including application, network, and segmentation test. Our deliverables are developed to address what the QSA needs.

Learn more

ASV Scan

Perform vulnerability scan by the approved scanning vendors with our team support to address the issues after getting the ASV scan results.

Learn more

IoT Penetration Test

Assess, analyse and reverse-engineer the smart devices to identify the vulnerabilities.

Learn more

Cloud Security Assessment

Secure your cloud environments with our testing and configuration reviews focusing on Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP).

Learn more

Wireless Network Penetration Test

Perform the security assessment on the wireless infrastructure including the implementation, protocols, authentication and authorisation.

Learn more

Secure Code Review

Read the source directly with SAST tooling and manual expert analysis to reach logic black-box testing can't — insecure crypto, missing authorization, unsafe deserialization.

Learn more

Every assessment is shaped around your systems, goals, and constraints — nothing here is fixed.

Talk to us

With our high-ethical, professional certified team and methodology based on NIST SP800-115, we offer a full range of cost-effective services to identify your cyber risks in application, infrastructure, and mobile platforms.

Services

  • Web Application Penetration Testing — Assess security of web apps, APIs, thick clients, low-code platforms, in-house or licensed applications.
  • Infrastructure Penetration Test — Examine infrastructure security controls and identify attack infiltration methods.
  • Mobile Application Penetration Test — Test Android and iOS apps with static, dynamic, and network analysis.
  • Wireless Network Penetration Test — Security assessment of wireless infrastructure, protocols, and authentication mechanisms.
  • IoT Penetration Test — Assess, analyze, and reverse-engineer smart devices for vulnerabilities.
  • Cloud Security Assessment — Test AWS, Azure, and GCP environments with configuration reviews.
  • PCI DSS Penetration Test — Based on NIST SP800-115, covering PCI DSS requirement 11.
  • ASV Scan Support — Coordination and remediation support for the Approved Scanning Vendor scans PCI DSS requires.
  • Vulnerability Assessment — Comprehensive VA scanning with mitigation recommendations.

How we work

Our methodology follows NIST SP800-115, aligned with the Penetration Testing Execution Standard (PTES) and OSSTMM, and mapped to the compliance and testing requirements that apply to you (PCI DSS, ISO 27001, OWASP). Every engagement runs through the same phases, so you always know where the project stands and what arrives next.

  1. Preparation — We set the protocol with you: objectives, scope, and testing scenario (black-box, gray-box, or white-box), plus the rules of engagement — testing windows, escalation contacts, and safety limits for production. You get a proposal with a fixed timeline and no open-ended billing.
  2. Reconnaissance & information gathering — Active and passive discovery to map the attack surface: exposed services, leaked credentials, and the entry points an attacker would look for first.
  3. Exploitation & initial compromise — We validate exploitable vulnerabilities by safely gaining an initial foothold, confirming real impact rather than flagging theoretical risk. Every reported issue is verified by hand, not lifted from a scanner.
  4. Privilege elevation & lateral movement — From that foothold we escalate privileges and move laterally to show how far a real attacker could reach toward the agreed objective.
  5. Reporting & retest — Findings are rated by severity (Critical, High, Medium, Low) with reproduction steps and remediation, an executive summary for management, and a retest to verify the fixes once your team has remediated.

Pentest vs Red Team vs Purple Team

Not sure which assessment fits? This is the comparison we walk clients through on the first call.

Penetration TestRed TeamPurple Team
ObjectiveFind and validate as many vulnerabilities as possible in a defined scopeTest detection and response against a realistic, goal-driven attackImprove detection by running attack techniques side by side with your defenders
ScopeAgreed list of applications, hosts, or networksThe organisation — people, process, and technologySelected techniques mapped to your monitoring coverage
DurationDays to a few weeksWeeks to monthsWorkshop-style, days per iteration
DeliverableFindings with severity, reproduction steps, and remediation guidanceAttack narrative, detection gaps, response timelineTuned detection rules and a coverage matrix
Who it's forTeams that need assurance on specific systems, or compliance evidenceOrganisations with a SOC that want to measure real readinessBlue teams that want to level up detection quickly

A conventional pentest answers "what can be broken here?" — if you want to know "would we notice an attacker at all?", look at our Red Teaming service.

What you get

Every report contains, at minimum:

  • Executive summary — business-level risk picture, suitable for management and auditors.
  • Findings with severity ratings — each vulnerability scored with CVSS, so remediation can be prioritised objectively.
  • Reproduction steps — exact requests, payloads, and screenshots; your engineers should never need to guess how we got in.
  • Remediation guidance — practical fixes, not a copy-paste of scanner boilerplate.
  • Retest verification — findings are re-checked after your fixes and the report is updated to reflect closed items.

We have delivered zero blank pentest reports in the company's history — every engagement so far has surfaced real, validated findings. If a QSA or auditor is involved, the report is structured so it can be handed over as-is.

Team credentials

Testing is performed by our in-house team holding industry certifications including OSCP, OSCE, CREST CRT, CREST CPSA, and GIAC GREM — credentials earned through rigorous, hands-on examination. The same team presents its research at international venues and has served 180+ clients across finance, enterprise, and critical sectors. See the full list of certifications the team holds.

Standards & compliance

Our methodology follows NIST SP800-115 (Technical Guide to Information Security Testing and Assessment). For payment-card environments we provide PCI DSS penetration tests covering requirement 11, scoped and reported the way QSAs expect, plus ASV scan coordination and remediation support until the approved vendor's scan passes. If your audit needs specific evidence formats, tell us during scoping — aligning the report costs nothing at that stage.

Last reviewed: 11 Jul 2026

Request a sample report

Frequently asked questions

What is penetration testing?

A penetration test is an authorised, simulated attack on your applications, infrastructure, or mobile platforms that finds and validates real vulnerabilities the way an actual attacker would. Unlike an automated scan, every finding is verified by hand, so you get proof of impact rather than a list of theoretical risks. Our methodology follows NIST SP800-115.

How is a penetration test different from a vulnerability assessment?

A vulnerability assessment enumerates and prioritises known weaknesses across a broad estate, usually through authenticated scanning with manual validation. A penetration test goes further: it exploits those weaknesses to prove which ones an attacker can actually chain together to reach sensitive data. An assessment tells you what could be wrong; a pentest proves what is.

Should I choose black-box or gray-box testing?

Black-box starts with no prior knowledge, simulating an external attacker who begins with only an IP range or URL. Gray-box grants some access up front — typically a standard user account — to simulate a malicious insider or an attacker who already has a foothold, and it reaches parts of a system black-box testing may never touch. Many clients scope both. We agree the scenario with you during scoping.

How long does a penetration test take, and how is it priced?

It depends on scope — the number of applications, hosts, or IP addresses in the engagement. A typical test runs from a few days to a few weeks. We fix the scope, timeline, and cost with you up front in the proposal, with no open-ended billing.

Do you retest after we fix the findings?

Yes. Once your team has remediated, we retest the findings and update the report to reflect closed items, so you can show auditors and stakeholders that issues were actually fixed — not just reported.

What standards and certifications does your team hold?

Our methodology follows NIST SP800-115, aligned with PTES and OSSTMM. For payment-card environments we run PCI DSS penetration tests covering requirement 11, plus coordination and remediation support for the ASV scans an approved vendor performs. Testing is performed by an in-house team holding OSCP, OSCE, CREST CRT, CREST CPSA, and GIAC GREM.

Engineering involves thinking about how things can be made to work, but for our work, we think and prove about how things can be made to fail.

Our certified and experienced penetration testers with high-ethical discipline will simulate ways to get into the enterprise and compromise systems or services in order to achieve the goals set in each project like malicious actors. The deliverables will demonstrate found vulnerabilities and the ways to exploit those. The test will illustrate attack paths, and how to defeat the protection mechanism. Incognito Lab could undertake assessment at a multi-scale perspective and complexity depends on the requirement. From the largest national penetration testing project to the services offer to foreign clients, we believe in our team, our quality and would like you to engage with us.
logologo

INCOGNITO LAB CO., LTD.

38 Soi Petchakasem 30, Pak Khlong Phasi Charoen, Phasi Charoen, Bangkok 10160

©2026 Incognito Lab Co., Ltd. All rights reserved

Terms & ConditionsPrivacy Policy