Are you getting the most out of your pen testing program? Does your penetrating testing services provider follow an execution standard for completeness and quality control? Winmill breaks out its pen testing services into seven phases as they are defined in the Penetration Testing Execution Standard.
The Penetration Testing Stream pairs AI-accelerated testing with senior human testers who verify every finding.
How Winmill Executes a Penetration Test
At Winmill, our certified pen testers follow seven steps or phases of penetration testing during every engagement. Scanning for vulnerabilities ensures that low-hanging fruit is not missed. But a vulnerability scan cannot identify zero-days, misconfigurations, business logic flaws, and other insecurities that an attacker could use to compromise the target’s confidentiality, integrity, and availability (the CIA triad). This is something that only a highly skilled penetration tester with patience, imagination, and lateral thinking skills can accomplish.
- Plan and Map the Test – The first phase of penetration testing clearly defines the scope and objectives of the penetration test, as well as what tests to perform and in which order. This phase also includes careful preliminary risk planning with contingency plans to minimize service disruption.
- Reconnaissance (Recon)/Open Source Intelligence (OSINT) – How exposed is your data on the internet? How big is your footprint? What is your attack surface? Is your data available on the dark web? These and other questions will be answered during our Recon/OSINT threat modeling phase.
- Threat Modeling – How is the network or application used, and what are the potential attack vectors?
- Scan for Vulnerabilities – The fourth phase enumerates suspected vulnerabilities identified by automated scanning tools. Virtually every tool generates false positives, so a vulnerability is only enumerated when it appears across multiple automated tools using different detection methods, or when it can be manually verified.
- Assess the Vulnerability Results – In the fifth phase, a penetration tester analyzes the suspected vulnerabilities using specialized pen testing tools and manual pen testing techniques. The goal in this phase is to identify and validate exploitable entry points.
- Gain Access – The sixth phase verifies high-risk vulnerabilities comprehensively using safe exploitation techniques, such as automated pen testing tools, manual processes, and code injection. Often a goal in this step is to gain privileged access status on a networked device and then pivot between trusted network zones and move unabated from one system on a network to another system in a different security zone on the same network.
- Report Findings – The seventh phase reports the pen test findings ranked by severity with a focus on critical and high-severity vulnerabilities. The report includes step-by-step instructions for how to reproduce the exploits so remediators can reproduce and fix them.
At Winmill, we divide a penetration test into seven phases as defined in the Penetration Testing Execution Standard for completeness and quality assurance. We provide real-time, on-demand project status in our client portal throughout the penetration test. Read more about our process.
How good are your cyber security measures? Are you getting the most out of your pen testing budget? Schedule a free consultation today.
Introducing Winmill’s Penetration Testing Stream
We’re excited to announce our latest offering: the Penetration Testing Stream subscription. Designed to fortify your organization’s cybersecurity posture, the Penetration Testing Stream provides continuous assurance. Whether you’re safeguarding critical infrastructure or ensuring compliance with industry standards, our expert team delivers fast, comprehensive testing to help you mitigate risks effectively.
If continuous testing on your release cadence would fit your environment, the Penetration Testing Stream page explains how the program works and how to check whether your application qualifies.


