Vulnerability Assessment
Identify and prioritize known weaknesses
Vulnerability assessments provide systematic coverage of in-scope systems to identify known vulnerabilities, outdated software, and other weaknesses that should be addressed.
They can include external or internal systems and may be performed as a one-time assessment or on a recurring basis when an organization needs independent third-party vulnerability testing. Where appropriate, authenticated scanning can provide additional visibility into installed software, missing patches, and system-level weaknesses.
Unlike penetration testing, the objective is broad identification rather than controlled exploitation. If you are comparing the two approaches, see Penetration Test vs. Vulnerability Scan.
Cloud Security Benchmarking & Configuration Review
Measure cloud configuration against established guidance
Cloud security benchmark assessments evaluate selected cloud environments against current security guidance such as Center for Internet Security (CIS) Benchmarks and, where applicable, Cybersecurity and Infrastructure Security Agency (CISA) Secure Cloud Business Applications (SCuBA) guidance.
Our focus is on major cloud platforms and services, including Microsoft Azure and Microsoft 365, Amazon Web Services (AWS), and Google Cloud Platform (GCP). The objective is to identify configuration gaps, risky defaults, and settings that do not align with the selected benchmark or guidance.
CISCISAMicrosoft 365AzureAWSGCP
Phishing Assessment & Open-Source Intelligence
Test the human side of an external attack path
Some attack paths begin with people rather than exposed systems. KobReySec conducts controlled phishing assessments to evaluate how employees respond to realistic messages, links, and sign-in scenarios.
Open-source intelligence (OSINT) can be used to understand what information about the organization and its employees is publicly available and how that information could make a phishing scenario more convincing. We often recommend pairing phishing with an Edge Assessment or External Penetration Test so the engagement can show what happens if a user actually submits credentials and how that access could affect the broader attack path.
Cyber Health Assessment
A broader look at overall security posture
A Cyber Health Assessment takes a broader look at the organization’s cybersecurity environment rather than focusing on a single attack surface. The review can span physical security, cloud environments, vendors, servers, applications, policies, and other areas that shape overall security posture.
The goal is to identify gaps, outdated practices, and overlooked areas that may not surface through a narrowly scoped technical review, then provide a clearer picture of where security improvements should be prioritized.