Methodology
How authorized assessment works — without disclosing exploits.
A public description of architecture and process. No payloads, no weaponized PoCs — only what experts use to judge program quality.
Foundations
01
Rules of Engagement
Versioned RoE: host scope, time windows, allowed techniques, escalation contacts. Nothing runs outside RoE.
02
Attestation & ownership
Operators attest authorization before deep scans. RoE hash + target set land in the ledger.
03
Detection-only posture
Signals from nuclei/nmap/httpx/ffuf and ASVS layers — no malware generators and no DoS.
04
Evidence & reproducibility
Evidence ZIP packs, tool versions, env hash, CVSS 4.0 / EPSS / KEV, STIX and ATT&CK Navigator export.
Platform architecture (high level)
Layers: Doctrine → Mission OS → Recon/ASM → Assessment → Operator desk → Cyber intel → Reporting.
01
Doctrine — RoE, kill-switch, RBAC, audit ledger, vault
02
Mission OS — lifecycle, playbooks, queue, artifacts
03
Recon / ASM — DNS, ports, crawl, attack surface
04
Assessment — TLS, headers, nuclei, correlation, confidence
05
Cyber intel — case files, IOC, entity graph, KEV
06
Reporting — PDF/DOCX, dossier, remediation tickets