Approach

How I approach
a target

Every engagement runs on the same disciplined offensive method — the way a real adversary would move, but scoped, controlled, and documented at every step. Here's exactly how I work through a target.


The method

From first look to closed finding

STEP 01

Map before I move

Passive recon, OSINT, subdomain enumeration and tech fingerprinting — a complete picture of the attack surface before anything is touched, and before the rules of engagement are locked in.

STEP 02

Model the attack

I prioritise entry vectors the way an attacker weighs effort against payoff — chasing the paths that actually lead somewhere, not the ones that are easy to type into a scanner.

STEP 03

Demonstrate, don't disrupt

Exploitation goes exactly as far as it needs to demonstrate impact — no further. No unnecessary lateral movement, no touching real data, every action documented as it happens.

The playbook

Inside a target, step by step

orvantis — engagement-method.md
PHASE 1: SCOPE & RULES OF ENGAGEMENT
Agree the target, the boundaries, and what "done" looks like — in writing — before
a single packet is sent. Nothing outside the agreed scope gets touched. Ever.

PHASE 2: PASSIVE RECONNAISSANCE
OSINT, subdomain enumeration, technology fingerprinting — building a complete picture
of the attack surface without alerting the target or generating noise.

PHASE 3: CONTROLLED EXPLOITATION
Exploit only to the extent needed to demonstrate impact. No lateral movement beyond
what's agreed. No exfiltration of real data. Documented at every step.

PHASE 4: REPORTING
Every finding written up with a working proof-of-concept, exact reproduction steps,
business impact, and a fix a developer can actually act on — in plain language.

PHASE 5: RETEST
Included — once you ship the fix, I verify it. Findings close when the risk is
genuinely gone — not when the ticket is marked resolved.

Why it works

Discipline is the difference

01 / SAFE

Contained by design

Everything happens inside an agreed scope, with impact demonstrated in the smallest way that proves the point. You're never surprised by what I did.

02 / REAL

Attacker-realistic

I chase the paths a motivated attacker actually would — chained weaknesses and logic flaws, not a list of low-severity noise nobody will ever exploit.

03 / USEFUL

Written to be fixed

Reports are built for the people who have to act on them — clear severity, a working PoC, and remediation a developer can follow without a translator.

Found something in your own product?

Let's confirm it and lock it down.

If you suspect a vulnerability in something you own or run, I can validate it, establish the real impact, and help you close it — discreetly and properly. It stays between us.

Talk it through with me

Want this run against your systems?

Same rigor, your target. Independent, evidence-based, and never softened.

Start a conversation View services