Penetration Tests

A penetration test is an authorized simulated cyberattack to identify weaknesses and strengths regarding the security of systems, applications or organizations and to provide the customer with detailed information about the vulnerabilities.

Compass Security is committed to working closely with you by providing competent advice during the initial scoping, throughout the entire project, and up to the final delivery of the report and the individual concluding discussion. We go the extra mile to always deliver the best and most sustainable results.

Continuous research and cooperation with leading universities in Switzerland guarantee that our experts always have a high and up-to-date standard of knowledge. This enables us not only to report on existing and known vulnerabilities, but also to make specific recommendations to improve your security in the long term.



External Penetration Testing

In an external penetration test, we analyze your exposed infrastructure and search for vulnerabilities and possible direct attack vectors by first scanning your system and services and then manually testing each of them. The identified attack vectors will be exploited and proved out, in order to identify and measure risks associated with the exploitation of the target’s attack surface.

Common activities for external penetration tests:

  • Host and service discovery
  • Hostname enumeration
  • Vulnerability assessment
  • Exploitation of discovered vulnerabilities
  • Hop into internal systems from exploited machines (pivoting)


Internal Penetration Testing

Access to your network can also be granted through malware, a malicious employee or by connected partners. In an internal penetration test, we visit you and simulate an attack from an internal perspective. We analyze your internal infrastructure and search for vulnerabilities and possible attack vectors. We exploit the discovered attack vectors to gain additional privileges, compromise critical systems and gain access to sensitive data.


Common activities for internal penetration tests:

  • Vulnerability assessment
  • Exploitation of discovered vulnerabilities
  • Privilege escalation (local computer and within domain)
  • Search for passwords and key materials (files, configuration, software, repositories, corporate wiki)
  • Network segregation verification
  • Identification and exploitation of Active Directory issues (Bloodhoud, Pingcastle, etc.)
  • Windows network attacks (NTLM Relay, Pass-the-Hash, Kerberoasting, Delegation, etc.)



In an application penetration test, we analyze the entire application and search for logical and technical vulnerabilities.

The tests are tailored to the type of application and its technology - including but not limited to OWASP Top 10, ASVS, technology specific and newly discovered vulnerabilities, in order to fully assess the security of the application.

This high standard of application testing is applied to desktop and mobile applications, whether they are based on web technologies or native frameworks.

Type of applications:

  • Web applications, web services and RESTful APIs
  • Mobile apps (Android & iOS)
  • Client/Server application (fat client)


Social Engineering

To verify and improve the security awareness of your employees, we perform social engineering attacks such as phishing campaigns based on custom-tailored or current threats, vishing using phone calls or physical social engineering, where we try to enter your facilities and gain access to your critical zones and systems. For continuous improvement, we offer yearly phishing subscriptions as well as live hacking presentations and awareness training programs to further train your employees to counter social engineering attacks.



Special Requirements

Our specialists cover a wide range of technologies. This allows us to address very specific requirements, whether specialized cloud environments, IoT technology or proprietary hardware devices.


We are glad to give you further information: Your contact person



New: Compass-Training "Internal Network and System Security" in Bern

In the 2-day seminar (in German) from February 11/12, 2020, you will get to know the most important basic concepts of IT security, attack tools and... Read more

KMU Swiss Forum 2020

The association «KMU Swiss» promotes the interaction between companies and specialists. He organises the annual KMU Swiss Forum. The next years motto... Read more

secIT 2020 – das IT Frühlings-Highlight in Hannover

Heise Medien lädt zur nächsten Veranstaltung der IT Security Branche ein. Im März 2020 öffnen die Tore der secIT zum dritten Mal. Wir sind vor Ort mit... Read more



Daten als Wettbewerbsvorteil

Das Basel Economic Forum ist das Wirtschaftsforum für die trinationale Metropolitanregion Basel und die Nordwestschweiz. Im November fand die 6.... Read more

Vulnerability in Apache Olingo OData 4.0

Compass analysts identified an XXE vulnerability in Apache Olingo OData 4.0. Read more

Vulnerability in totemodata

Fabio Poloni identified an XSS vulnerability in totemodata®. Read more


Compass Security Blog

Finding Active Directory attack paths using BloodHound

As a defender, you want to find and patch attack paths in your Active Directory environment. One cannot easily spot issues by looking at the Active Directory Users and Computers console, GPOs, etc.... mehr

Challenging Your Forensic Readiness with an Application-Level Ransomware Attack

Ransomware focuses on encrypting data on a filesystem-level, either locally on infected client systems or remotely on accessible file servers. However, what if ransomware would start encrypting data... mehr