NeoBit/ Pen Testing
Offensive security

Penetration testing

Advanced penetration tests find vulnerabilities in your systems and applications before hackers do - and enable timely fixes and changes so that attackers cannot bring down your business. After the test you get a clear picture of the risk and concrete steps toward greater security.

Web applications Mobile applications Infrastructure Internal network APIs and services
Penetration testing (pentest) for companies in BiH | NeoBit offensive team Ethical, controlled attack
Black · Grey · White
All types of testing
2 reports
Executive and technical
OWASP
Recognized methodologies
Re-test
Verification after fixes
How we work

From agreement to re-verification

A structured, transparent process following recognized methodologies (OWASP, PTES) - no surprises and no risk to your business.

01 · Scope and agreement

We define the targets, type of access and rules - written authorization and clear boundaries for the test.

02 · Reconnaissance and mapping

We gather information and map the attack surface - all entry points and weaknesses.

03 · Exploitation

We exploit vulnerabilities in a controlled and safe way to prove the real impact on your business.

04 · Report and re-test

We deliver a report with priorities and fixes, then re-verify that everything has been resolved.

What we check

We cover the entire attack surface

From web applications following the OWASP methodology to infrastructure, access rights and the cloud - these are the areas included in the test, depending on the agreed scope.

Web applications (OWASP Top 10)

  • Injection - SQL, NoSQL, command, LDAP
  • Broken access control and privileges (IDOR)
  • Authentication and session management
  • Cross-Site Scripting (XSS) and CSRF
  • Security misconfiguration
  • Cryptographic failures and sensitive data
  • SSRF and vulnerable components
  • Business logic flaws

API testing

  • REST and GraphQL endpoints
  • Authorization (BOLA / object-level privileges)
  • Excessive data exposure
  • Mass assignment and input validation
  • Rate limiting and resource abuse
  • Token security (JWT, OAuth)

Infrastructure and network

  • External and internal perimeter
  • Open ports and exposed services
  • Unpatched vulnerabilities (patch level)
  • Segmentation and lateral movement
  • VPN, RDP and remote access
  • Default and weak passwords

Active Directory and access rights

  • Privilege escalation
  • Principle of least privilege
  • Poor ACLs and Kerberos attacks
  • Segregation of duties
  • Review of administrator accounts and groups

Cloud and configuration

  • Microsoft 365, Azure and AWS settings
  • IAM, roles and access rights
  • Publicly exposed storage (buckets)
  • Security groups and firewall rules
  • Hardening per CIS recommendations
  • Logging, monitoring and backups

Mobile applications

  • Secure data storage on the device
  • Communication protection (TLS, pinning)
  • Resistance to reverse engineering
  • Backend API security
  • Permissions and data leakage
Types of testing

A penetration test tailored to your industry and business

Black box

Without any information or access - we look at your system through the eyes of an external attacker.

Grey box

With a user account and partial information - simulating an attack from the inside or from a compromised user.

White box / Internal

Full insight and access from the internal network - the most thorough check of all layers.

Reports

Clear for management, precise for the team

Every test ends with two reports - one for decision-makers, the other for those who do the fixing.

Executive summary

An overview of the risk in business language - risk level, potential impact and recommendations, without technical jargon. Ideal for management and decisions about investing in security.

Detailed technical report

Every vulnerability with proof (PoC), reproduction steps, a severity rating (CVSS) and concrete remediation guidance - everything your team needs to resolve the issue quickly.

Request a pen test

Tell us what we are testing

Fill in the basic details about the scope - we will get back to you with a proposal, timeline and quote. Simple and with no obligation.

We respond within 24 hours · No obligation · Your data remains confidential

Areas of testing

Types of penetration tests we perform

Every system has a different attack surface, so each test is tailored to you. These are the engagements we carry out most often, either standalone or combined within a single project.

Web application pentest

We test web applications, portals and APIs following the OWASP methodology: from injection and access control to flaws in business logic that automated scanners cannot see. Web applications are the most common entry point for attackers because they are publicly exposed 24/7.

Learn more: web application penetration testing

Network and infrastructure pentest

We examine the external perimeter and the internal network: exposed services, unpatched systems, weak protocols and opportunities for lateral movement. We pay particular attention to the SMB protocol, which remains one of the most common ways ransomware spreads through business networks.

Learn more: SMB vulnerabilities in a pentest

WiFi pentest

We test wireless networks for weak authentication methods, flaws in WPA2/WPA3 configuration and rogue access points (evil twin). We also verify whether the guest network is genuinely separated from the corporate one or is merely a different SSID in name only.

Learn more: WiFi penetration testing

Active Directory pentest

We simulate an attacker who is already inside the network and attempting to take over the domain: Kerberoasting, privilege escalation, misconfigured ACLs and overly broad administrative rights. AD is the heart of most business networks, which also makes it the most valuable target for attackers.

Learn more: Active Directory penetration testing

Social engineering

We test the human factor with controlled phishing campaigns and manipulation scenarios tailored to your business. The results show how prepared your employees really are for an attack, without singling out individuals and with a clear focus on education.

Learn more: social engineering attacks

Not sure where to start?

If you are unsure which type of test makes sense for your risk profile and budget, describe your environment through the form. We will propose a scope that covers what is genuinely critical, without unnecessary items.

Request a free scoping assessment

Standards we follow

Methodology: OWASP, PTES and OSSTMM

A pentest without a methodology is improvisation. We work according to recognised frameworks that guarantee every step is covered, the results are repeatable and you can compare them with future tests.

OWASP

For web applications and APIs we use the OWASP Testing Guide, and we treat the OWASP Top 10 as the minimum level of coverage: from authentication and access control to business logic. This makes it clear what was tested, not merely what was found.

PTES

The Penetration Testing Execution Standard defines seven phases of an engagement, from scoping and information gathering to exploitation and reporting. PTES is the backbone of every test we run and the reason the process holds no surprises.

OSSTMM

OSSTMM measures security rather than merely describing it: the outcome of the test is a comparable metric, useful for tracking progress year over year and for conversations with management. We explained what this looks like in practice in our article on the OSSTMM methodology.

Deliverables

What you get in the report

A pentest is only worth as much as you can actually fix based on the report. That is why our report is not a list of tools and scans, but a document from which management understands the risk and the technical team knows exactly what to fix, how, and in what order. Every report we deliver contains:

  • Executive summary: the overall risk level and the potential business impact, written in the language of decision makers, free of jargon.
  • A list of all findings with CVSS scores: each vulnerability rated by severity and likelihood of exploitation, within the context of your environment.
  • Proof of concept (PoC): screenshots and steps demonstrating that the vulnerability is genuinely exploitable, not theoretical.
  • Reproduction steps: your team or an external partner can independently repeat and verify every finding.
  • Specific remediation instructions: what to change, where, and with what priority, instead of generic advice such as "update your software".
  • Strategic recommendations: recurring systemic causes (e.g. password management, segmentation, patching processes) and how to resolve them permanently.
  • Retest and confirmation: once you apply the fixes, we verify the findings again and issue a certificate confirming that the testing was performed.

You can present the testing certificate to business partners, insurers or auditors as evidence that you take security verification seriously; increasingly, this is also a contractual or regulatory requirement.

Planning

How long a pentest takes and how much it costs

Duration depends on the scope: the number of targets, the depth of the test and the type of access (black, grey or white box). For a typical small or medium business, the indicative ranges look like this:

Type of testIndicative durationWhat affects the scope most
Web application5 to 10 working daysNumber of features, user roles and forms
External network3 to 5 working daysNumber of public IP addresses and exposed services
Internal network and Active Directory5 to 10 working daysDomain size, number of workstations and servers
WiFi2 to 4 working daysNumber of locations and wireless networks
Social engineering3 to 5 working daysNumber of employees and agreed scenarios

Add 2 to 4 days for preparing the report and the retest after remediation. Timelines are always agreed in advance, including the time windows in which testing is permitted (e.g. outside business hours for production systems).

Pricing is not calculated per item but per day of expert work (man days), which is why no universal price list exists. The more targets and the deeper the test, the more days of work it takes. We broke down all the factors that push the price up or down in our article on how much penetration testing costs. The scoping assessment and the quote are free of charge and carry no obligation.

A common misconception

A pentest is not a vulnerability scan

A vulnerability scanner is an automated tool: it quickly finds known flaws, but it cannot distinguish theoretical risk from genuinely exploitable risk, it generates false positives and it misses errors in business logic. A pentest is performed by a human: vulnerabilities are chained into an attack path, the real impact on your data and business is demonstrated, and the noise is removed from the report.

One does not replace the other. Scanning is hygiene that should run continuously, while a pentest is a deep, manual assessment carried out once or twice a year. If someone delivers a "pentest" that is merely a scanner export, you have paid for the wrong service. How to recognise that is covered in our comparison of pentest vs vulnerability scanning.

FAQ

Frequently asked questions

Is a pentest safe for production systems?

Yes. Before we start, the rules of engagement are agreed in writing: what may be tested, in which time windows, and which techniques are excluded (e.g. DoS attacks). Exploitation is carried out in a controlled manner, and we report critical findings immediately rather than waiting for the end of the test.

How often should a penetration test be performed?

At least once a year, and after every major change: a new application, migration to the cloud, network mergers or infrastructure changes. Regulations and standards such as ISO 27001, NIS2 and PCI DSS expect or directly require regular testing.

We have a firewall and antivirus. Do we still need a pentest?

Yes, because a pentest does not check whether you have protection in place, but whether it actually works. Most successful attacks do not break through the firewall; they exploit misconfiguration, weak passwords, application flaws or the human factor, and those are precisely the areas a pentest covers.

What happens if you find a critical vulnerability?

We notify you immediately, together with an interim measure that lets you reduce the risk the same day. The full description, proof and permanent fix follow in the report, and once you apply it, a retest confirms that the vulnerability is genuinely closed.

Is our data safe during the test?

Yes. We sign an NDA before starting, access only the agreed targets, and never take sensitive data out of your environment; a minimal sample is sufficient as proof. The report is delivered encrypted and is available only to the people you designate.

Related guides

Under attack? WhatsApp