SysTools
VAPT Service

Network / Infrastructure VAPT

Security assessment of approved internal and external infrastructure — servers, endpoints, network devices, security appliances, databases and remote-access services. The questionnaire below is limited to the technical scope information the assessment team needs.

Progress 0% 0 of 0 answered 0 mandatory pending

Please note

  • Do not enter live passwords, private keys, SNMP community strings or production credentials in this form. Credentials are shared separately through an approved secure channel.
  • Only the IP addresses, hosts and devices listed in the approved scope are tested. Fields marked * are required to begin testing.
  • This is a controlled, defined-scope assessment — not a red-team engagement.

1 Assessment Details

Mandatory

2 Scope Type and Testing Approach

Mandatory

Grey Box shares limited information plus credentials. White Box adds full device configurations and network diagrams. Black Box shares nothing, so part of the effort goes into discovery rather than testing.

Please note: assessment frequency is not included in the timeline estimate in section 7. The estimate covers a single assessment cycle only. Frequency, and the schedule for repeat cycles, is agreed while finalising the scope.

A single-time engagement covers one assessment cycle together with its retests.

A full firewall rule-base audit is only possible when configuration access is provided.

3 Asset Inventory and Counts

Drives effort

Enter approximate counts — leave blank or zero where not applicable. These counts feed the timeline estimate in section 7.

Perimeter and hosts

Public IP
Internal IP
Windows laptops / endpoints
Linux / Unix endpoints
Printers
IP Cameras / NVR

Servers and appliances

Servers
VMs
Application servers
DB servers

Network devices

Firewalls
Routers
Managed switches

Only addresses and hosts listed in the approved scope are tested.

Tick this if the network uses Active Directory — the system most Windows networks use to manage staff logins and permissions. It is assessed as its own piece of work, which adds 4 days to the estimate.

4 Data Sensitivity and Standards

Drives severity ratings

This decides how serious a finding is, so an approximate answer is fine.

5 How We Test

Nothing here needs an answer — it is what you are buying.

How the assessment runs

We confirm exactly which addresses and systems are in scope, then map what is actually reachable on them. Automated scanning covers the whole estate quickly, and every result is checked by hand — scanners over-report badly on infrastructure and nothing goes into your report unverified. We then test manually where it matters: exposed services, weak or default credentials, missing patches and configuration mistakes. Each finding is reproduced, evidenced and rated, and retested once your team has fixed it.

What we look for

Systems reachable from outside that should not be. Services running with default or weak passwords. Missing patches on operating systems and network devices. Firewall and network rules that allow more than intended. Insecure remote access. Weak encryption. And whether the network is genuinely separated, or whether reaching one machine means reaching everything.

What we will not do

This is a controlled assessment, not a red-team exercise. No phishing, no social engineering, no physical security testing, no denial-of-service, and nothing destructive. We do only the minimum needed to prove a finding is real.

6 Vulnerability Risk Classification

SeverityDescription
CriticalMay result in complete system compromise, remote code execution, administrative access, widespread infrastructure impact or significant sensitive-data exposure.
HighMay result in unauthorized access, privilege escalation, system compromise, significant data exposure or access to additional approved systems.
MediumMay affect infrastructure security under specific conditions, or may require authentication, limited privileges, internal access or user interaction.
LowLimited direct impact; remediated as part of infrastructure-hardening and security-improvement activities.
InformationalConfiguration observation or hardening recommendation without direct exploitability.

After retesting each finding is marked Closed, Open, Partially Fixed, Risk Accepted or Not Retested.

7 Timeline Estimate

Calculated from the SysTools infrastructure effort model. Asset counts from section 3 are carried over automatically; the OS image, hypervisor and WLAN counts are entered by the assessment team.

Endpoints

Unique OS images
Windows endpoint hosts
Linux / Unix endpoint hosts
Printers
IP Cameras / NVR

Servers

General servers
Hypervisor hosts
VMs
Application servers
Database servers

Network devices

Firewalls
Routers
Managed switches
WLAN controllers with APs

Retest

Active Directory1 = in use
Number of retests

One retest is included as standard. Increase this only if additional retest cycles are required.

Estimated duration 0 working days
Testing0
Retest0

Subject to final scope review, access availability and resource confirmation. The final timeline is confirmed after the complete scope has been reviewed and understood.

Save and Export Response

Responses are stored in this browser until exported or cleared.