Skip to content
Cyberside
← Home

Methodology

How authorized assessment works — without disclosing exploits.

A public description of architecture and process. No payloads, no weaponized PoCs — only what experts use to judge program quality.

Foundations

01

Rules of Engagement

Versioned RoE: host scope, time windows, allowed techniques, escalation contacts. Nothing runs outside RoE.

02

Attestation & ownership

Operators attest authorization before deep scans. RoE hash + target set land in the ledger.

03

Detection-only posture

Signals from nuclei/nmap/httpx/ffuf and ASVS layers — no malware generators and no DoS.

04

Evidence & reproducibility

Evidence ZIP packs, tool versions, env hash, CVSS 4.0 / EPSS / KEV, STIX and ATT&CK Navigator export.

Platform architecture (high level)

Layers: Doctrine → Mission OS → Recon/ASM → Assessment → Operator desk → Cyber intel → Reporting.

  1. 01

    Doctrine — RoE, kill-switch, RBAC, audit ledger, vault

  2. 02

    Mission OS — lifecycle, playbooks, queue, artifacts

  3. 03

    Recon / ASM — DNS, ports, crawl, attack surface

  4. 04

    Assessment — TLS, headers, nuclei, correlation, confidence

  5. 05

    Cyber intel — case files, IOC, entity graph, KEV

  6. 06

    Reporting — PDF/DOCX, dossier, remediation tickets

Open ScanServices