SERVICES / PENETRATION TESTING

SERVICES / PENETRATION TESTING

Offensive Assessments

Offensive Assessments

The Problem & Our Approach

Most vulnerability scans tell you what software versions are running. A penetration test tells you what an attacker could actually do with that information. There is a significant difference between the two.. and most organizations don’t discover it until after an incident.

Thorium’s penetration tests are conducted by practitioners who spent their careers conducting offensive security operations at the Department of Defense level, where the consequences of a missed finding were never theoretical. We brought that standard to the private sector. We go beyond automated tooling: we think through attack chains the way real adversaries do, validate exploitability with hands-on testing, and document exactly what a determined threat actor could accomplish in your environment from initial access to full compromise.

The result isn’t a list of software versions and CVE numbers. It’s a clear, evidence-backed picture of your actual exposure.. and a prioritized roadmap for closing it.

01

Recon

02

Initial Access

03

Execution

04

Persistence

05

Lateral Movement

06

Data Access

Re-Test

01

Recon

06

Data Access

04

Persistence

02

Initial Access

Re-Test

05

Lateral Movement

03

Execution

EXTERNAL PRESENCE

External Penetration Test

Internet-facing infrastructure, firewall and VPN exposure, publicly accessible services, DNS enumeration, credential harvesting attempts, and exploitation of externally reachable vulnerabilities. Every exposed entry point is mapped from an attacker’s vantage point, then validated through safe exploitation so you see exactly what an outsider could reach.

PERIMETER

FIREWALL

VPN

DNS RECON

OSINT

EXPLOITATION

INTERNAL NETWORK

Internal Penetration Test

Network segmentation effectiveness, lateral movement paths, unauthenticated access opportunities, internal service exposure, and exploitation of trust relationships between systems and network segments. We simulate a breached foothold or malicious insider to show how far an attacker could pivot once inside the perimeter.

RECON

PIVOTING

SEGMENTATION

TRUST ABUSE

AD ENUM

CREDENTIALED ACCESS

Authenticated Penetration Test

Privilege escalation from standard user to administrator, access to sensitive data and critical systems, weak permission configurations, credential reuse opportunities, and domain compromise pathways. Starting from legitimate low-level access, we chart the realistic route to full domain control.

PRIV ESC

AD ATTACKS

CRED REUSE

RBAC FLAWS

DATA ACCESS

DA

WEB LAYER / OWASP

Web Application Penetration Test

Injection vulnerabilities, authentication and session management weaknesses, access control failures, sensitive data exposure, business logic flaws, and OWASP Top 10 coverage across all application functionality. Both authenticated and unauthenticated roles are tested to surface flaws automated scanners routinely miss.

OWASP TOP 10

INJECTION

BROKEN AUTH & ACCESS

MOBILE CLIENTS

Mobile Application Penetration Test

Local data storage security, authentication and authorization controls, API communication security, certificate validation, reverse engineering exposure, and platform-specific vulnerability coverage for iOS and Android. We assess the app, its backend APIs, and the device-side artifacts it leaves behind.

iOS & ANDROID

DATA STORAGE

API & CERT PINNING

CLOUD INFRASTRUCTURE

Cloud Service Penetration Test

IAM permission misconfigurations, exposed storage and compute resources, metadata service exploitation, cross-account access opportunities, serverless function vulnerabilities, and insecure API gateway configurations. Findings are mapped to AWS, Azure, and GCP best practices with concrete remediation steps.

IAM MISCONFIG

STORAGE EXPOSURE

SERVERLESS & API GATEWAY

RF / WIRELESS

Wireless Penetration Test

Wireless encryption and authentication weaknesses, rogue access point susceptibility, evil twin attack exposure, guest network segmentation failures, unauthorized device detection, and credential capture opportunities against poorly configured wireless infrastructure. On-site testing confirms whether an attacker in your parking lot could reach the corporate network.

WPA2 / WPA3

ROGUE / EVIL TWIN

GUEST SEGMENTATION

PHYSICAL ACCESS

Physical Penetration Test

Physical access control bypass, tailgating and piggybacking susceptibility, server room and wiring closet access, sensitive data visible in common areas, unattended workstation exposure, and social engineering of on-site personnel. We test the human and physical layers that technical controls alone cannot protect.

ACCESS BYPASS

TAILGATING

SOCIAL ENGINEERING

NIST CSF

NIST CSF

OWASP

OWASP

PTES

PTES

OSSTMM

OSSTMM

FFIEC

FFIEC

CMMC

CMMC







Ready to see what an attacker would find?

Ready to see what an attacker would find?

We scope every engagement individually. Tell us about your environment and we’ll respond within one business day.

We scope every engagement individually. Tell us about your environment and we’ll respond within one business day.

Thorium Information Security, LLC.

Hayden, Idaho, USA

Hayden, Idaho, USA

(208) 352-2877

(208) 352-2877

Sales@ThoriumInfosec.com

Sales@ThoriumInfosec.com

Copyright © 2026 Thorium Information Security LLC. All rights reserved.

Copyright © 2026 Thorium Information Security LLC. All rights reserved.