Skip to content
Services

EHT starts from the adversarial objective, not from the URL.

The investigation starts from the critical asset that must not be compromised and correlates every route capable of reaching it — technical, identity, business-rule and process routes.

Plans · Engagement Depth

Three tiers, one philosophy: Anticipate attacks before they impact your business

Each plan evolves in methodology, scope, and retest duration — not in volume of promises. Compare and choose by the threat model you need to cover.

Diamond

Complete

Critical & Regulated Environments

MethodologyOWASP ASVS L3 + Advanced Security Analysis
RetestsUnlimited / 6 months
Timeline4–6 weeks
  • Full OWASP ASVS Level 3 coverage
  • Business-oriented threat modeling
  • Deep business logic and fraud analysis
  • Unlimited retests for 6 months
  • Executive + technical reports
  • Dedicated security consultant
  • Source-code-assisted analysis
  • Compliance mapping (PCI-DSS, ISO 27001)
AI Add-on Full AI security assessment (LLM, RAG, agents)
What it is

Manual offensive validation conducted by offensive security specialists — not an automated checklist scan.

Who it's for

Startups validating launch, companies in compliance, and banks in critical exposure.

What you get

Report with evidence, CVSS severity, remediation roadmap, and included retests.

How we attack · A REAL EXCERPT

Not a theoretical test
It's that log that will hit your SIEM

Every engagement generates reproducible evidence: payload, request, target response, proof of impact. This is an excerpt from a real Gold session (sanitized).

▶ ENGAGEMENT · LIVE TRACECWE-89 · OWASP A03:2021
# 14:32:07 — Reconhecimento da superfície de aplicação
$ berghem-recon --target app.cliente.com.br --depth 3
[+] 142 endpoints · 8 com input dinâmico · 3 com auth quebrada

# 14:47:21 — Identificada lógica de autorização por parâmetro de URL
$ curl -s "https://app.cliente.com.br/api/v2/orders?account_id=1043"
{ "status": "ok", "items": [ { "id": 88291, "value": 14580.00 } ] }

# 14:48:02 — IDOR confirmado: troca account_id devolve dados de terceiros
$ curl -s "https://app.cliente.com.br/api/v2/orders?account_id=1042"
{ "status": "ok", "items": [ { "id": 88112, "value": 9230.50, "owner": "outro_cliente" } ] }

# 14:51:14 — Severidade: ALTA · CVSS 8.1 · Exploração: trivial · Escopo: PII + transações
[✓] Evidência capturada · ticket BRG-2826 aberto · cliente notificado em <15min
Methodology · 6 PHASES

From NDA signing to final report, every step is mapped

We combine OWASP, NIST SP 800-115, and PTES with our offensive expertise — no magic black-box, no elastic scope.

01

Pre-engagement

Scope, rules of engagement, written authorization, windows and contacts.

02

Reconnaissance

Attack surface: assets, subdomains, integrations, leaks.

03

Enumeration

Technologies, versions, endpoints, authentication flows and data.

04

Exploitation

Manual validation, vector chaining, proof of impact.

05

Post-exploitation

Lateral movement and escalation within the authorized perimeter.

06

Report

Prioritized findings, evidence, executive and technical roadmap.

Coverage · DEPTH MATRIX

Everything each plan tests, side by side

No fine print. What is marked is executed and documented in the final report.

Test AreaSilverGoldDiamond
OWASP Top 10 (Web)
OWASP API Security Top 10
OWASP ASVS Level 2
OWASP ASVS Level 3 (full)
STRIDE Threat Modeling
Business Logic Analysis
Transactional Fraud Detection
Source-code-assisted analysis
PCI-DSS / ISO 27001 Mapping
AI / LLM Security Add-on
Retests1 in 30 days2 in 90 daysUnlimited / 6 months
Included Partial / scoped Not included
COMPLEMENTARY

Pentest and EHT start in different places.

They are complementary approaches. The difference lies in the starting point, the methodology and the success criteria.

Pentest

Starts from an asset, application, API or infrastructure.

  • Question: where can this environment be compromised?
  • Evidence: vulnerability, exploitation and impact.

Berghem EHT

Starts from the adversarial objective and the business-critical asset.

  • Question: what can an adversary reach, and through which combinations?
  • Evidence: the chain of conditions leading to impact.
FRAMEWORK

CORE: from the critical asset to the evidence.

Berghem structures business-driven missions across four connected dimensions.

C

Core business

Money, data, identity, critical operations, trust and secrets.

O

Orchestration

Specialists, agents, models, tooling and authorized sources.

R

Routes

Technology, identities, rules, processes, controls and context.

E

Evidence

Logged actions, understandable impact, reproduction and recommendation.

CONTROL

Sufficient evidence, controlled impact.

The mission ends when the evidence criterion is met or when a boundary requires human intervention.

Deliverables

  • Route and hypothesis map.
  • Reproducible proofs.
  • Technical and business impact.
  • Recommendations and retest.

Rules of engagement

  • Permitted and blocked actions.
  • Segregated identities.
  • Time and volume limits.
  • Approval and stop conditions.

Not Sure Which Plan to Choose?

Our security consultants will assess your environment, compliance requirements, and risk profile to recommend the ideal plan for your organization.

Talk to a Specialist