What I test
Kerberoasting and AS-REP roasting, ACL and delegation abuse, ADCS misconfiguration, credential relaying, and the lateral movement paths that turn one workstation into domain admin.
- Full attack-path mapping with BloodHound
- Kerberos and ADCS abuse testing
- Tiering and delegation review
- Prioritised remediation with retest
Perimeter and internal infrastructure tested the way an attacker would approach it: enumeration, public exploit work, service and token abuse, and escalation to SYSTEM or root.
- External perimeter and exposed services
- Internal network from an assumed-breach position
- Segmentation and pivot testing
- Evidence-backed findings, not scanner output
Objective-based engagements measuring what your detection stack actually catches. Delivered against production EDR estates, with detection gaps fed back to the SOC.
- Objective-driven adversary simulation
- EDR coverage measurement
- Detection engineering feedback to the blue team
- Purple-team replay of every finding
Authenticated application testing against OWASP Top 10 and ASVS, including the API layer underneath and the Android and iOS clients on top.
- Web application and business-logic testing
- REST and GraphQL API testing
- Android and iOS application review
- Source-assisted where code is available
Continuous discovery of what you have exposed, validation of what actually matters, and the exploitability analysis that separates a real risk from a scanner ticket.
- External asset discovery
- Vulnerability validation and exploitability analysis
- CVE triage and advisories
- Remediation tracking to closure
Fixes verified rather than assumed. Every finding retested against the original reproduction steps, with a clear pass or fail.
- Retest of every prior finding
- Regression check on adjacent paths
- Updated report and closure evidence
How an engagement runs
-
1
Scope
A short call to agree targets, rules of engagement, timing windows and what a successful engagement looks like. Written scope before anything starts.
-
2
Test
The engagement itself. Critical findings are reported the moment they are confirmed rather than held back for the report.
-
3
Report
Findings with reproduction steps, business impact, and remediation that names the specific change to make. Written to be handed to an engineer, not filed.
-
4
Retest
Fixes verified against the original steps once you have deployed them.
Proof of work
47 Proving Grounds boxes documented end to end, and security acknowledgements from SentinelOne, Spartoo, Jio Platform, ABB, Navient, ExtraHop Networks, Lenskart, GoFrugal, SimplyCook, the Government of India and MUFG Americas.
Frequently asked
What kind of security testing does Nitesh Gupta offer?
Active Directory security assessments, internal and external network penetration testing, red team and EDR evasion engagements, web, API and mobile application testing, and attack surface management. Retesting is included.
Do you work with clients outside India?
Yes. Engagements have covered national and international subsidiaries of enterprise groups, and remote testing is standard for external and assumed-breach work.
What do I receive at the end of an engagement?
A report with reproduction steps, business impact and specific remediation for every finding, plus a retest once fixes are deployed. Critical findings are raised during the engagement, not held until the end.
How is this different from a vulnerability scan?
A scanner reports what might be wrong. An engagement confirms what is actually exploitable, chains it to show real impact, and tells you which of the hundred scanner tickets matter.
How do I request a quote?
Email [email protected] with rough scope: how many hosts or applications, whether internal or external, and your timing. A scope and quote follows.
Start a conversation
Send rough scope: how many hosts or applications, internal or external, and your timing. A written scope and quote follows.