Cybersecurity service
Vulnerability Assessment and Penetration Testing (VAPT)
Vulnerability assessment combined with manual penetration testing across an agreed set of assets to identify real, verifiable security issues.
VAPT combines two activities. A vulnerability assessment identifies and catalogues weaknesses across a defined set of assets. Penetration testing then attempts to verify selected weaknesses to show what an attacker could realistically do.
Depending on the authorised scope, we combine manual testing and verification with automated tools such as Burp Suite, Nmap, Nuclei, OWASP ZAP, Nessus and SQLmap, and other suitable tools. Not every tool is used in every engagement.
Who it is for
- Businesses that want a broader view of the security of their applications and systems
- Teams asked by customers or partners about security testing
- Organisations that want a baseline before improving their security
What is in scope
- Web applications, APIs, hosts and network ranges listed in the written scope
- Discovery and enumeration of in-scope services
- Vulnerability identification and manual verification
- Controlled verification of selected issues, within the permitted techniques
How we work
- Define scope. We record the assets, exclusions, testing windows, permitted techniques, emergency contacts and stop conditions in writing, together with authorisation.
- Assess. We enumerate the in-scope attack surface and run assessment tools, then review the results by hand.
- Verify. Within the rules of engagement we verify selected issues to confirm impact.
- Report. We document verified findings and prioritised remediation recommendations.
What you receive
- A written report with an executive summary
- Verified findings with supporting evidence
- Severity where justified, potential impact and remediation recommendations
Limitations
- Only assets listed in the written scope are tested; see the VAPT scope page.
- Denial-of-service, phishing, destructive actions and other excluded activities are not performed unless separately authorised in writing.
- A security assessment reduces risk but cannot guarantee that every vulnerability will be found or that a system will remain secure.
- Retesting is optional and can be agreed separately; it is not automatically included.
What we need from you
- Written authorisation from the owner of every in-scope asset before testing starts
- Confirmed ownership or control of every in-scope asset
- Emergency contact details for the testing window
Frequently asked questions
What is the difference between a vulnerability assessment and a penetration test?
An assessment identifies weaknesses broadly. A penetration test verifies selected weaknesses to show real impact. VAPT includes both.
Can you test systems we do not own?
No. We only test assets the client owns or is authorised in writing to test.
Does the report give us a certification or compliance approval?
No. A report documents testing and findings. GreyNod Labs does not offer compliance certification.
Ready to talk about your project?
Tell us what you need and we will reply with next steps.


