Certified Experts • Real World Threats • Actionable Results

Image module

EHS penetration testing is specifically designed to provide results that are holistic, quantifiable, and actionable, giving you the information you need to make data driven decisions that optimize your resources and protect what is most valuable to you.

Industry Experience

Our world-class engineers are industry-certified and have a wealth of experience performing penetration tests from regional hospitals to Fortune-500 financial institutions.

Certified Professionals

Our engineers are OSCP, CISSP, C|EH, PCIP, GSEC, GCIH, GWAPT, and Security+ certified.

Built Around Real-World Threats

Our penetration tests are built to holistically evaluate your organization against specific threat vectors, emulating techniques currently used by attackers.

Meets Your Compliance Needs

Our methodology satisfies NIST, PCI, HIPAA, FISMA, ISO 27001, and GLBA/FFIEC requirements.

Image module

World class security engineers, proven methodology, exceptional results. No one takes your security more seriously.

Penetration Testing

Our trusted and highly-skilled engineers will assess your resilience to the real-world attacks that organizations are facing today.

Penetration Testing Offerings:


External Penetration Test

An external penetration test emulates an attacker trying to break into your network from the outside. The goal of the engineer performing this assessment is to breach the perimeter and prove they have internal network access. This test includes:

Open source reconnaissance against the organization
Full port scan covering all TCP ports and the top 1,000 UDP ports of the targets in scope
Full vulnerability scan of the targets
Manual and automated exploit attempts
Password attacks

Internal Penetration Test
Internal Penetration Test

An internal penetration test emulates an attacker on the inside of your network. This could be either an attacker who is successful in breaching the perimeter through another method or a malicious insider. The goal of the engineer in this module is to gain root and/or domain administrator level access on the network, and gain access to sensitive files. Activities include:

  • Active and Passive network reconnaissance including traffic sniffing, port scanning, LDAP enumeration, SMB enumeration, etc.
  • Vulnerability scan on all in-scope targets
  • Spoofing attacks such as ARP cache poisoning, LLMNR/NBNS spoofing, etc.
  • Manual and automated exploit attempts
  • Shared resource enumeration
  • Password attacks
  • Pivoting attacks
Wireless Penetration Test
Wireless Penetration Test

A wireless penetration test is a comprehensive evaluation of the wireless networks in your organization using automated and manual methods. Areas covered include:

  • Password attacks
  • WEP/WPA cracking
  • Guest wireless segmentation checks
  • Traffic sniffing attacks
  • SSID spoofing
  • Rogue access point discovery
Web Application Penetration Test
Web Application Penetration Test

A web application penetration test is an in-depth penetration test on both the unauthenticated and authenticated portions of your website. The engineer will test for all of the OWASP Top-10 critical security flaws, as well as a variety of other potential vulnerabilities based on security best practice. Activities include:

  • Website mapping techniques such as spidering
  • Directory enumeration
  • Automated and manual tests for injection flaws on all input fields
  • Directory traversal testing
  • Malicious file upload and remote code execution
  • Password attacks and testing for vulnerabilities in the authentication mechanisms
  • Session attacks, including hijacking, fixation, and spoofing attempts
  • Other tests depending on specific site content and languages
Social Engineering Assessment
Social Engineering Assessment

This assessment is designed to target and take advantage of the human-element to gain access to your network. This is done using a variety of methods to get an employee to click on something they shouldn’t, enter their credentials or otherwise provide them when they shouldn’t, or divulge information that may assist an attacker in breaching your network. The goal for the engineer performing this assessment is to gain information that may assist an attacker in future attacks, gather credentials, or gain a foothold on the internal network. This assessment will include:

  • Phone-based attacks
  • Spear phishing attacks
  • Bulk phishing attacks
Physical Penetration Test
Physical Penetration Test

A physical penetration test is an assessment of the physical security of your premises. Our engineers will attempt to gain access to your facility by identifying weaknesses and/or using social engineering. Once inside, our engineers will attempt to gather sensitive information, gain access to sensitive areas such as the data center, and attempt to gain internal network access

Vulnerability Scanning
Vulnerability Scanning

Vulnerability scanning is a regular, automated process that identifies the potential points of compromise on a network. A vulnerability scan detects and classifies system weaknesses in computers, networks and communications equipment and predicts the effectiveness of countermeasures. Our engineers will conduct this scan for you and use our expertise to remove false positives and produce a risk-prioritized report.

Compliance Audits

Our team has performed countless audits and can provide the expertise you need to meet your regulatory requirements while optimizing your time and resources.

Compliance Audit Offerings:


Compliance Gap Analysis – PCI DSS, HIPAA, GDPR, NIST/DFARS, CSC Top 20, etc.

All-in-One Compliance Packages

Partner with us to meet your compliance objectives. EHS is well-versed in helping our clients meet a wide range of compliance requirements:

All of our consultants are also penetration testers. This means that rather than just checking a box, our engineers can explain the risk behind each control and provide strategies to meet the requirements while prioritizing your organization’s business needs.

Security Best Practice Gap Analysis
Best Practice Gap Analysis

Our best practice gap analysis is an interview based review of your information security program. We use the Center for Internet Security (CIS) Top 20 Critical Security Controls to comprehensively review all aspects of your information security program. Some of the areas covered include:

  • Inventory and asset management
  • System hardening
  • Account management and principle of least privilege
  • Disaster recovery and continuity of operations
  • Incident response
Formal Risk Assessment
Formal Risk Assessment

A formal risk assessment evaluates the threats to your organization, the vulnerabilities of your network, and the security controls you have in place to protect your network. A risk assessment correlates information from your security assessments and evaluates the overall risk to your organization to help drive strategic decisions.


Security Policy Review and Creation
Security Policy Review and Creation

Comprehensive security policies written by security professionals. Our policies are designed to meet your compliance needs while optimizing your business requirements. Some of the policies we can help with include:

  • Access Control Policy
  • Acceptable Use
  • Disaster Recovery Plan
  • Password Policy
  • Incident Response Plan


Strategic Consulting

Our consultants have extensive practical experience across information security disciplines, and are here to help you with any problems your organization is facing.

Strategic Consulting Offerings:


Host Compliance Audit
Host Compliance Audit

A host compliance audit involves the manual inspection of a workstation, server, or network device using the Center for Internet Security (CIS) benchmark and device-specific security best practices. This assessment will identify the security holes in your system and provide specific actions to take to harden the device.

Password Audit
Password Audit

During a password audit, our engineers will evaluate the strength of passwords currently in use in your organization. We will take a dump of your employees’ hashed credentials and run them through a password cracker to identify weak passwords and common usage patterns. This audit can be used to justify stronger password policies, used in security awareness training to improve password choice among employees, and used to help understand the organization’s overall risk if an attacker is able to capture hashed credentials.

Cloud Security Assessment
Cloud Security Assessment

This assessment is an evaluation of your organization’s cloud infrastructure for security vulnerabilities. Our engineers will assist you in evaluating the unique security responsibilities associated with cloud computing. Individual services can include cloud application assessments, cloud infrastructure penetration testing, host/OS configuration audits, and cloud architecture reviews.

Internet of Things Security Assessment
Internet of Things Security Assessment

Developing a secure IoT solution depends on a number of security considerations. This assessment will evaluate the IoT device and its associated infrastructure against common attacks. It can include an evaluation of the edge device, the gateway, the cloud infrastructure, and/or any mobile applications. Our engineers will evaluate your IoT Device utilizing the OWASP IoT Framework Assessment methodology.

Incident Response and Malware Analysis

When you suspect you have been breached, knowing exactly how it happened and what was affected can be difficult to discern. Our certified engineers can assist you with the incident response process, ensuring the malware is removed and normal business operations are restored. Moreover, our root-cause analysis will attempt to determine how the breach was possible and steps to take to prevent it from happening again. Moreover, we will evaluate the malware including:

  • Open-source intelligence – We will evaluate the hash and any unique strings in the malware to see if they match known-malware signatures.
  • Reverse-Engineering – Where possible, we will recreate the incident with advanced process monitors and determine the exact malware behavior.
  • Log Analysis – Using the information gathered, we are now able to analyze the logs of affected devices to determine if the breach spread to other machines.
Customized Security Consulting
Customized Security Consulting

Have a need not mentioned? Contact us today to customize an assessment or package to meet your security needs. Our engineers have a wealth of experience performing a wide variety of assessments, and we’re confident they can meet your needs. Let us know how we can help.

Helpful Links

Ready to start talking with a professional?