Configuration & Architecture Review
The first level of analysis covers the review of the platform's configuration: we verify that the main components are configured in line with vendor best practice and industry standards. In particular:
- SAFE structure and management: correct segregation, naming conventions and access logic
- Permission model: how roles and privileges are assigned to users and groups, with particular attention to excessive permissions and configurations that do not comply with the principle of least privilege
- Core features: automatic credential rotation, session recording, dual control, one-time passwords — active and correctly configured
SSO & Identity Integration Review
If the platform is integrated with a Single Sign-On system (SAML 2.0, OIDC, AD/LDAP), we verify its implementation against the relevant standards: validation of the authentication flows, session management and the robustness of the trust chain between the systems involved.
Network Penetration Test
We assess the reachability and exposure of critical components — starting with the PAM platform: mapping exposed ports and services, identifying known vulnerabilities, verifying segmentation and firewall policies. The question we answer is a single one: can an attacker, external or internal, reach the critical components of the system? Our point of view here is twofold — cyber and systems/infrastructure: we put to the test what we design and manage every day as our core business.
What's new
LLM Penetration Test
More and more often, bots and AI agents interface with PAM systems to request access, manage SAFEs or interact with the platform's APIs. For this scenario we run a dedicated LLM Penetration Test: we verify whether these components can be manipulated through prompt injection, jailbreaks or abuse of authorisation flows in order to gain unauthorised access or bypass the platform's controls. We know AI agents from the inside, because we build them: we know where to look.
Report & Remediation Plan
At the end of the engagement we produce a detailed report of the findings, classified by risk level — critical, high, medium, low. For each finding we provide practical remediation guidance: the goal is to support the technical team in fixing the vulnerabilities and improving the overall security posture of the platform.
Beyond the assessment
Prevention and analysis
- Vulnerability Assessment & Penetration Test with customised reporting
- Web application security
- Reverse engineering and code review (vulnerabilities, backdoors, malicious code)
- Log management, data analysis and correlation; Identity Management & Access Control
Incident response
- Handling of malware and data breaches, with analysis of the entry vector and remote connections
- Clean-up of the information system and fixing of the exploited vulnerability
- Response under custom SLAs, even within 24h of the call