cyberagent.id · docs Methodology

Methodology & Standards

How we work, the tooling we use, and the quality controls that keep every report free of findings that cannot be proven.

Workflow

Surface mapping

Identify every asset, endpoint, user role, and data flow within scope. This includes undocumented paths discovered from client applications and configuration.

Manual review

Manual reading of code and configuration along critical paths: authentication, authorization, input processing, secrets handling, and system-to-system integration.

Dynamic testing

Testing against running systems with request-flow tracing, cross-role response comparison, and boundary input testing — entirely non-destructive.

Evidence validation

Every candidate finding is reproduced from a clean state, fully recorded (request, response, timestamp), and assessed for impact. Anything that fails this stage does not enter the report.

Reporting & re-test

Findings are documented with measured severity and remediation steps, then re-tested after fixes are applied.

Reference Frameworks

FrameworkRole in our work
OWASP Top 10Baseline for web application testing
OWASP API Security Top 10Baseline for API testing
OWASP LLM Top 10Baseline for testing language-model-based systems
OWASP ASVS & WSTGVerification levels and detailed testing steps
MITRE ATT&CKMapping attacker techniques for detection relevance
NIST CSF 2.0Framework for positioning risk at the organizational level
ISO/IEC 27001Mapping findings to information security controls
PTESFramework for end-to-end testing phases
CVSSComparable severity scoring

Quality Control

Ethics of Engagement

RuleApplication
AuthorizationWritten, from the system owner, before work begins
Non-destructiveNo modification, deletion, or corruption of data or configuration
DataNot exfiltrated, not used outside the engagement, deleted after reporting
Third partiesNot tested without separate authorization
TransparencyTesting activity can be explained and traced from logs on request
© 2026 CyberAgent.id Assessment · Disclosure · cyberagent.id