Kyeson Blake Utley

Methodology

How Kyeson Blake Utley runs a penetration test

Scanners find the obvious problems. A real test models the attacker who wants your system specifically and proves what they could do. This is the process I follow on every engagement.

View the slide deck on Speaker Deck →

Six phases

Diagram by Kyeson Blake Utley showing the six phases of a penetration test: map the attack surface, model the threat, find the weaknesses, prove exploitation, measure the blast radius, report and re-test
The six-phase penetration testing method. Diagram by Kyeson Blake Utley.
  1. Map the attack surface

    OSINT, enumeration and exposure discovery. The goal is to see your organization the way an outsider does, including the forgotten subdomain or the staging server nobody turned off.

  2. Model the threat

    Decide who would realistically attack this system and what they would want. That ranking, not a scanner's severity score, decides where testing time goes.

  3. Find the weaknesses

    Automated tools for coverage, then manual testing for depth. Broken access control, business-logic flaws and chained low-severity bugs only show up when a person is looking.

  4. Prove exploitation

    Each finding is demonstrated with a controlled, production-safe proof. "Potentially vulnerable" isn't a finding.

  5. Measure the blast radius

    From a foothold, how far can an attacker get? Privilege escalation, lateral movement and data reach are measured, then the test stops before anything is harmed.

  6. Report and re-test

    A plain-language summary for leadership, CVSS-scored technical findings with reproduction steps, a prioritized fix list, and a free re-test once fixes are in.

What can be in scope

Web apps & APIs

Authentication, authorization, injection and business-logic abuse, across REST and GraphQL.

Cloud & identity

AWS, GCP and Azure permissions, exposed storage, and the path from a single foothold to admin keys.

Smart contracts & protocols

Re-entrancy, oracle manipulation, key handling and custody logic, wherever the money moves.

Cryptographic review

Implementation audits, key lifecycle, and readiness for post-quantum migration.

Rules of engagement

Testing only starts with written authorization and an agreed scope, testing windows and emergency contacts. Production-impacting techniques need explicit sign-off. Findings and data stay confidential and are destroyed on an agreed schedule after the engagement ends.

The method aligns with PTES, OWASP WSTG, MITRE ATT&CK and NIST SP 800-115, so auditors and compliance teams can map the results to frameworks they already use. Engagements are booked through GhostKey Development.