Penetration Testing & Offensive Security

07 - Offensive Security

Penetration Testing &
Offensive Security

Practical security testing for applications, networks, cloud and identity. RTCS tests web applications, APIs, external and internal networks, Active Directory, Microsoft 365, Entra ID, cloud environments, mobile applications and wireless networks. We identify exploitable weaknesses, assess business impact and provide clear remediation advice your team can act on.

  • Web application and API penetration testing (REST and GraphQL)
  • External and internal network penetration testing
  • Active Directory attack path and privilege escalation testing
  • Entra ID and Microsoft 365 security testing
  • Cloud penetration testing across Azure, AWS and Google Cloud
  • Mobile application security testing (Android and iOS)
  • Wireless security testing
  • Risk-rated findings with evidence, business impact and remediation
  • Optional retesting to confirm fixes
Discuss This Service
Testing Scope
Web Apps - APIs - External - Internal - Active Directory - Entra ID - M365 - Cloud - Mobile - Wireless
Methodology
OWASP - PTES - OSSTMM - NIST SP 800-115 - MITRE ATT&CK TTP mapping
Engagement Types
Black box - Grey box - White box - Red team - Purple team
Deliverables
Executive summary - risk-rated findings - evidence - remediation roadmap - debrief - optional retest
Essential Eight OWASP PTES MITRE ATT&CK NIST 800-115
9
Testing Disciplines
100%
Manual, Attacker-Focused
CVSS
Risk-Rated Findings
AU
Onshore Delivery
01 / Context

Find the weaknesses before attackers do.

Penetration testing is a controlled assessment that simulates how an attacker may attempt to compromise a system, application, network or cloud environment. The purpose is to understand what can be exploited, what access could be gained, what data may be exposed and what should be fixed first.

A penetration test can identify weak authentication, broken access controls, insecure APIs, exposed services, cloud misconfigurations, Active Directory attack paths, excessive privileges and sensitive data exposure.

02 / Why It Matters

Automated tools miss the things attackers actually use.

Security issues are introduced through new applications, cloud deployments, infrastructure changes, third-party integrations and identity changes. Automated scanners find some known vulnerabilities, but they miss business logic flaws, authorisation issues, privilege escalation paths and chained attack scenarios.

A penetration test answers the questions that matter

Q1

Can an attacker access sensitive data?

Q2

Can users access functions or records they shouldn't?

Q3

Are APIs enforcing authentication and authorisation correctly?

Q4

Are internet-facing systems exposed to attack?

Q5

Can a standard internal user escalate privileges?

Q6

Are Microsoft 365, Entra ID and cloud controls secure?

Q7

Can weaknesses be chained together to increase impact?

03 / Testing Services

Testing across the surfaces that actually get attacked.

Web Application Testing

Authentication, session management, access control, injection, XSS, file uploads, SSRF, business logic flaws, password reset weaknesses, MFA bypass and sensitive data exposure.

API Penetration Testing

REST and GraphQL APIs - authentication, authorisation, BOLA, token handling, input validation, excessive data exposure, mass assignment, rate limiting and business logic.

External Network Testing

Internet-facing infrastructure - VPNs, remote access, firewalls, web servers, mail gateways, exposed ports, public services and management interfaces.

Internal Network Testing

What happens if an attacker, insider or compromised device is on the corporate network - host discovery, segmentation, privilege escalation, lateral movement and misconfiguration.

Active Directory Testing

Practical attack paths across users, groups, permissions, trusts, service accounts and GPOs - Kerberoasting, AS-REP roasting, delegation, local admin and attack-path mapping to crown jewels.

Entra ID & Microsoft 365

MFA, Conditional Access, privileged roles, PIM, legacy auth, enterprise apps and consent, SharePoint, Teams, guest access, external sharing, mailbox controls and audit logging.

Cloud Penetration Testing

Azure, AWS and Google Cloud - identity and access, public exposure, storage access, security groups, keys and secrets, privilege escalation, serverless, containers, logging and monitoring.

Mobile Application Testing

Android and iOS - insecure local storage, weak authentication handling, insecure API communication, sensitive data exposure, certificate validation and backend API weaknesses.

Wireless Security Testing

Corporate and guest wireless - encryption review, authentication controls, guest isolation, segmentation, rogue access point checks and signal exposure observations.

04 / What We Test For

Tailored to scope. Broad in coverage.

Broken access controls Weak authentication Session management flaws Injection vulnerabilities Cross-site scripting Server-side request forgery Insecure file uploads Business logic flaws Sensitive data exposure API authorisation weaknesses Security misconfiguration Vulnerable components Weak encryption / TLS Privilege escalation paths Lateral movement paths Active Directory attack paths Entra ID & M365 control gaps Cloud misconfiguration Exposed admin interfaces Logging & monitoring gaps
05 / Deliverables

Deliverables

For Technical Teams

  • Scope and methodology
  • Risk-rated findings with CVSS
  • Technical evidence
  • Affected assets and endpoints
  • Reproduction steps where appropriate
  • Remediation guidance
  • Optional retest results

For Risk & Leadership

  • Executive summary
  • Business impact explanation
  • Prioritised action plan
  • Debrief session with your team
  • Trend and posture insights
  • Clear mapping to scope and assumptions
  • Plain-English risk narrative
06 / Sample Report

What you actually receive.

Reports are written for technical teams and leadership - plain English, evidence-backed, with risk-rated findings, business impact and remediation guidance. Stylised preview below in the RTCS report format.

Confidential
Under NDA
Penetration Test Report
External Network
Security
Assessment
Client: ACME Corp Pty Ltd
Engagement: Q2 2026 · Ref RTCS-0426
Perth, WA · rtcs.au Attack. Assess. Advise.
External Network Assessment · Confidential
Finding 01
Exposed Administrative Interface
Critical CVSS 9.8 · CWE-284
Recommendation
AssetSeverity
Critical
High
Low
RTCS · Confidential 03
07 / How It Compares

How It Compares

Vulnerability Scanning

Checks known assets for known weaknesses. Provides breadth. Good as a starting point - never a deliverable on its own.

Penetration Testing

Validates exploitability, tests access controls, identifies business logic flaws and assesses how weaknesses chain together. Provides depth and practical validation.

08 / When To Test

When organisations engage RTCS for testing.

Before launching a new app or API After major infrastructure changes After moving to the cloud Before onboarding enterprise customers Audit and compliance requirements Annual security testing After an incident or remediation program To assess AD, M365 or Entra ID controls Pre-production validation

Scope to Retest

A practical, staged engagement that finds exploitable weaknesses, validates real-world impact, and gives your team a clear path to remediation.

01
Scope

Confirm systems, applications, accounts, testing windows, exclusions and rules of engagement.

02
Discover

Identify exposed services, functionality, user roles, APIs, permissions, technologies and possible attack paths.

03
Test

Perform manual security testing using attacker-focused techniques, supported by controlled tools where appropriate.

04
Validate

Confirm whether findings are exploitable, remove false positives and assess likely business impact.

05
Report

Provide a clear report with evidence, severity ratings, affected assets, business impact and remediation guidance.

06
Retest

Where included, retest remediated findings and confirm whether the issues have been resolved.

09 / Who It's For

Who this service is for.

  • Run public web applications or APIs
  • Handle customer, employee, financial or sensitive data
  • Need independent security assurance
  • Need to test cloud, network or identity controls
  • Need to assess Active Directory security
  • Need to review Microsoft 365 or Entra ID security
  • Want clear evidence of risk and remediation actions

Penetration testing gives your organisation a clear view of exploitable weaknesses and the practical steps needed to reduce risk - across applications, APIs, networks, Active Directory, Microsoft 365, Entra ID, cloud, mobile and wireless.

Common Questions

What is penetration testing?

Penetration testing is a controlled security assessment that identifies exploitable weaknesses in applications, networks, cloud environments and identity platforms.

Do you provide a report?

Yes. RTCS provides a clear report with findings, evidence, risk ratings, affected assets and remediation guidance.

Can you retest after fixes are applied?

Yes. Retesting can be included to confirm whether identified issues have been remediated.

Do you test APIs?

Yes. RTCS tests REST and GraphQL APIs, including authentication, authorisation, input validation, object level access controls, rate limiting and business logic.

Do you test Active Directory?

Yes. RTCS tests Active Directory for privilege escalation paths, weak permissions, credential exposure, lateral movement opportunities and misconfigurations.

Do you test Microsoft 365 and Entra ID?

Yes. RTCS can assess Microsoft 365 and Entra ID controls, including MFA, Conditional Access, privileged roles, app consent, guest access, external sharing and security logging.

Do you test cloud environments?

Yes. RTCS can assess Azure, AWS and Google Cloud environments where included in scope.

Available across Australia.

RTCS provides penetration testing for Australian organisations, including Perth-based teams and organisations operating nationally. For city-specific context, see cyber security services across Australia or cyber security services in Perth.