Methodology
How Kyeson Blake Utley runs a penetration test
Scanners find the obvious problems. A real test models the attacker who wants your system specifically and proves what they could do. This is the process I follow on every engagement.
View the slide deck on Speaker Deck →Six phases

Map the attack surface
OSINT, enumeration and exposure discovery. The goal is to see your organization the way an outsider does, including the forgotten subdomain or the staging server nobody turned off.
Model the threat
Decide who would realistically attack this system and what they would want. That ranking, not a scanner's severity score, decides where testing time goes.
Find the weaknesses
Automated tools for coverage, then manual testing for depth. Broken access control, business-logic flaws and chained low-severity bugs only show up when a person is looking.
Prove exploitation
Each finding is demonstrated with a controlled, production-safe proof. "Potentially vulnerable" isn't a finding.
Measure the blast radius
From a foothold, how far can an attacker get? Privilege escalation, lateral movement and data reach are measured, then the test stops before anything is harmed.
Report and re-test
A plain-language summary for leadership, CVSS-scored technical findings with reproduction steps, a prioritized fix list, and a free re-test once fixes are in.
What can be in scope
Web apps & APIs
Authentication, authorization, injection and business-logic abuse, across REST and GraphQL.
Cloud & identity
AWS, GCP and Azure permissions, exposed storage, and the path from a single foothold to admin keys.
Smart contracts & protocols
Re-entrancy, oracle manipulation, key handling and custody logic, wherever the money moves.
Cryptographic review
Implementation audits, key lifecycle, and readiness for post-quantum migration.
Rules of engagement
Testing only starts with written authorization and an agreed scope, testing windows and emergency contacts. Production-impacting techniques need explicit sign-off. Findings and data stay confidential and are destroyed on an agreed schedule after the engagement ends.
The method aligns with PTES, OWASP WSTG, MITRE ATT&CK and NIST SP 800-115, so auditors and compliance teams can map the results to frameworks they already use. Engagements are booked through GhostKey Development.