Penetration Testing Services & Pricing

Diese Seite ist auch auf Deutsch verfügbar.


What is a penetration test?

How secure are your IT systems really? A penetration test shows where attackers would start - before it’s too late.

A penetration test (“pentest” for short) is a security analysis of one or more IT systems. An IT security expert (“pentester”) attempts to uncover as many vulnerabilities as possible in the time available. The tools and procedures used are the same as those used by real attackers. The result of a penetration test is a detailed report with the vulnerabilities found, sorted by severity, and recommended measures to eliminate them.

Vuln Scan vs. Pentest vs. Red Team

Why penetration testing?

  1. Every system has unknown vulnerabilities.
  2. Without testing, they remain undiscovered until an attacker exploits them.
  3. Penetration tests find these vulnerabilities so they can be fixed before attackers exploit them.

Penetration test procedure

Process penetration test

Commercial details

  • Penetration tests are always customized to the tested systems and requirements - there is no standard price.
  • Implementation in a time box: How many vulnerabilities can be found in the time available?

Typical price: from €4,200, most projects between €6,000 and €15,000

Specific services

Every IT system is different. A penetration test of the internal IT infrastructure, for example, requires a completely different approach and tools than a penetration test of a web application.

Active Directory Security Audit

Active Directory Audit, test and audit AD, ransomware defense, second line of defense

An Active Directory Audit is a white-box security assessment of your on-premises Active Directory that identifies misconfigurations, dangerous permissions, and attack paths leading to domain takeover, before an attacker or ransomware can exploit them.

The ransomware attacks with the biggest impact run through Active Directory: whoever takes over the domain controls every system and every file in the company. A single forgotten permission or an old misconfiguration is often all it takes. These are exactly the vulnerabilities this audit uncovers, before an attacker finds them.

Internal IT Infrastructure Penetration Test

Internal penetration test, test internal IT infrastructure, ransomware prevention

An Internal IT Infrastructure Penetration Test simulates an attacker who already has a foothold inside your network (for example after a phishing click) and tests whether they can move laterally and reach Domain Admin.

Someone on your team clicks the wrong email attachment, and an attacker is inside your network. What happens next depends on what they find there: does the attack stop at one machine, or do they move laterally and take over every system you run? This test answers that question before a real attacker does.

Cloud Infrastructure Security Audit

Cloud Infrastructure Audit, Azure, AWS configuration review, IAM, cloud security

A Cloud Infrastructure Audit is a read-only, white-box review of your Azure, AWS, or GCP environment that finds misconfigurations, over-privileged IAM roles, and exposed services before attackers do.

Cloud services offer enormous flexibility, but that flexibility comes with risk. Misconfigured storage buckets, overly permissive IAM roles, and exposed management interfaces are among the most common causes of cloud security incidents. A Cloud Infrastructure Audit reviews your cloud environment with a read-only account to identify exactly these issues before attackers do.

Supported platforms: Azure, AWS, and GCP. For Azure environments, cloud IAM misconfigurations are frequently intertwined with Entra ID role assignments and Conditional Access; both are often reviewed together.

Entra ID Security Audit

EntraID Audit, Azure AD / Microsoft Entra ID configuration review, identity management

An Entra ID Audit (formerly Azure AD) is a white-box review of your Microsoft Entra ID tenant that uncovers identity and access misconfigurations, weak Conditional Access policies, and privilege escalation paths.

EntraID (Microsoft Entra ID) is Microsoft’s central identity and access management (IAM) solution, especially in Microsoft 365 environments, and forms the basis for single sign-on (SSO) and access control. A misconfiguration can lead to unauthorized access to company resources or facilitate social engineering attacks. Therefore, this component must be thoroughly tested.

External IT Infrastructure Penetration Test

External penetration test, test external IT infrastructure and attack surface

An External IT Infrastructure Penetration Test assesses your internet-facing systems (servers, VPNs, mail, remote access) for exploitable vulnerabilities and exposure that an attacker could use to gain a foothold.

If your system is exposed to the internet, it could potentially be hacked by anyone. Okay, I exaggerate a bit, but I think you understand. Vulnerabilities in your external infrastructure can lead to very bad press and threaten your customers’ personal information. Regular external infrastructure penetration testing keeps that attack surface in check.

Web Application Penetration Test

Web Application Penetration Test, test web apps for vulnerabilities, OWASP

A Web Application Penetration Test is a manual security assessment of a web application and its APIs, focused on the OWASP Top 10: broken access control, injection, authentication flaws, and business logic vulnerabilities.

Your web application is reachable from the internet around the clock, for your customers and for attackers alike. A single access control flaw is often enough to expose other users’ data or take over the server. Those are exactly the flaws I find, before someone exploits them.

Typical project compositions

Projects are always scoped to your specific situation, but these are common starting points:

Internal security review An internal IT infrastructure pentest (includes Active Directory testing from an attacker’s perspective) is the core. For a deeper, white-box analysis of AD configuration, an Active Directory Audit is added on top.

Identity-focused (Microsoft stack) An Entra ID Audit combined with a Microsoft 365 Audit covers the full Microsoft identity and productivity environment, the most common combination for organizations running on Microsoft 365.

External exposure check An External IT Infrastructure Penetration Test assesses what’s visible from the internet. Often paired with an internal pentest for a complete picture of the attack surface.

Application security A Web Application Penetration Test focuses on a specific web application or API. This is standalone, a separate engagement from infrastructure testing.

Detection and response validation A Cyber Attack Simulation tests whether your team and tools actually catch an attacker. Typically run after establishing a security baseline through pentests and audits.

Don’t see exactly what you need? All projects are custom-scoped anyway, just get in touch.

New to pentesting or not sure how to scope? The Penetration Testing Buyer’s Guide covers what a pentest actually is, how to choose the right methodology, and how to avoid the most common mistakes.

Fastest way to an offer

Book appointment (opens in a new tab)

martin​@​vidrasec.com

+43 670 3081275

+43 670 3081275 (opens in a new tab)