Popular searches
Hamburger Menu
//

Pentests for your systems

From web applications to IT infrastructure to production networks. We simulate targeted attacks on your systems – with over 100 completed penetration tests under our belt.

Illustration: 3 Personen und Hund in relaxter Bürosituation, davor Ritter, der mit Schild einen Drachen abwehrt.
//

Ethical hacking reveals what the security that exists on paper is actually worth

Firewalls, patches, policies: many companies believe they're well protected. Until someone actually tests it. That's when it becomes clear that misconfigured systems, forgotten access points, or untested interfaces are real entry points that remain invisible during normal operations.

Ethical hacking does exactly that: we think like attackers, act like attackers, and in the end don't hand you a list of attacks – but a clear action plan.

//

Tailored pentests for every use case

From web apps to critical OT networks: every environment has its own vulnerabilities. That's why we don't offer off-the-shelf pentests, but targeted simulations tailored to your systems.

//

Security requires an honest outside perspective

Those who defend their own network know their weaknesses the least. You made the decisions yourself and long since convinced yourself your assumptions were correct – why would you question them? It's something we notice again and again in pentests: only an independent outside perspective reveals what has long since become routine from the inside.

//

Why codecentric as your penetration testing provider?

//

Our expertise

//

Use case: vulnerability in a third-party software library

Background

Many web applications use third-party software libraries to avoid developing every feature from scratch. If such a library is used on a publicly accessible website and contains a known vulnerability, it creates a potential entry point – accessible to any internet user.

Attack scenario

An attacker identifies the vulnerable library and uses a specially crafted request to exploit the vulnerability. For known vulnerabilities, ready-made exploits often already exist, meaning even attackers without deep technical knowledge can carry out the attack. More complex vulnerabilities, however, require solid expertise for manual exploitation.

Potential impact

The damage potential depends heavily on the specific vulnerability and the underlying infrastructure. In this case, an attacker could: gain access to sensitive data stored server-side, use the vulnerability as an entry point into the internal network, plan and prepare further attack steps on that basis, and in the worst case, compromise the entire internal infrastructure.

//

Frequently asked questions about pentesting

How long does a penetration test take?
That depends on the scope. A standard web test takes approx. 3–7 days, while complex infrastructures or production networks are planned individually. After the scoping call, we provide you with a binding timeline.
Can systems go down during the test?
Safety comes first. We use controlled testing methods and coordinate closely with your system administrators – especially in OT environments. This minimizes the risk to ongoing operations to an absolute minimum.
What information do you need from us to carry out a penetration test?
For a web application pentest, a walkthrough of the application is helpful to better understand its processes. It's also important for us to know about any special considerations such as maintenance windows or critical legacy systems. We decide together with you how the test should be conducted – as a blackbox, greybox, or whitebox pentest.
What is the difference between a standard pentest and threat-led pentesting (TLPT)?
A classic pentest looks for technical vulnerabilities in a defined system (e.g. a web app). It is a focused, in-depth review. TLPT, on the other hand, is scenario-based: we take on the role of a specific attacker and attempt by all means available (technology, social engineering, processes) to reach a predefined objective – for example, gaining access to executive management data. It tests not only the IT, but also how well your detection teams notice and respond to a real attack.
Is our company already ready for threat-led pentesting?
TLPT is the supreme discipline of IT security. It makes sense when you have already conducted regular pentests and largely completed your technical homework (patch management, firewall configuration, IAM). Once the basic security foundation is in place, TLPT helps you validate the coordination of your defense teams and the effectiveness of your security strategy under real-world conditions.
What does a penetration test cost?
The cost of a penetration test depends directly on the scope – and that's different for every company.
The key factors are: how complex is the application or infrastructure? How large is the attack surface? Which test scenario fits the situation? We discuss the exact scope in a free initial consultation.
What is ethical hacking?
Ethical hacking refers to the targeted, authorized testing of IT systems using the same methods that real attackers would use – with the difference that you commission the work and receive an action plan at the end instead of damage. Penetration tests are the most well-known form of ethical hacking.
What is the difference between a blackbox, greybox, and whitebox pentest?
In a blackbox pentest, we start without any prior knowledge, just like an external attacker. In a greybox pentest, we have partial information, such as credentials or an architectural overview. The whitebox pentest gives us full insight into the code and architecture and enables the most in-depth review.

Find the gaps before attackers do.

No system is secure by definition. But with a pentest, you at least know where you really stand.

Marc Lenze

IT-Security Business Development Lead

Marc Lenze

IT-Security Business Development Lead