Skip to content
Home / Services / EHT
Services

EHT starts from the adversarial objective, not from the URL.

The investigation starts from the critical asset that must not be compromised and correlates every route capable of reaching it — technical, identity, business-rule and process routes.

Plans · Engagement Depth

Three tiers, one philosophy: Anticipate attacks before they impact your business

Each plan evolves in methodology, scope, and retest duration — not in volume of promises. Compare and choose by the threat model you need to cover.

Diamond

Complete

Critical & Regulated Environments

MethodologyOWASP ASVS L3 + Advanced Security Analysis
RetestsUnlimited / 6 months
Timeline4–6 weeks
  • Full OWASP ASVS Level 3 coverage
  • Business-oriented threat modeling
  • Deep business logic and fraud analysis
  • Unlimited retests for 6 months
  • Executive + technical reports
  • Dedicated security consultant
  • Source-code-assisted analysis
  • Compliance mapping (PCI-DSS, ISO 27001)
AI Add-on Full AI security assessment (LLM, RAG, agents)
What it is

Manual offensive validation conducted by offensive security specialists — not an automated checklist scan.

Who it's for

Startups validating launch, companies in compliance, and banks in critical exposure.

What you get

Report with evidence, CVSS severity, remediation roadmap, and included retests.

How we attack · A REAL EXCERPT

Not a theoretical test
It's that log that will hit your SIEM

Every engagement generates reproducible evidence: payload, request, target response, proof of impact. This is an excerpt from a real Gold session (sanitized).

▶ ENGAGEMENT · LIVE TRACECWE-89 · OWASP A03:2021
# 14:32:07 — Reconhecimento da superfície de aplicação
$ berghem-recon --target app.cliente.com.br --depth 3
[+] 142 endpoints · 8 com input dinâmico · 3 com auth quebrada

# 14:47:21 — Identificada lógica de autorização por parâmetro de URL
$ curl -s "https://app.cliente.com.br/api/v2/orders?account_id=1043"
{ "status": "ok", "items": [ { "id": 88291, "value": 14580.00 } ] }

# 14:48:02 — IDOR confirmado: troca account_id devolve dados de terceiros
$ curl -s "https://app.cliente.com.br/api/v2/orders?account_id=1042"
{ "status": "ok", "items": [ { "id": 88112, "value": 9230.50, "owner": "outro_cliente" } ] }

# 14:51:14 — Severidade: ALTA · CVSS 8.1 · Exploração: trivial · Escopo: PII + transações
[✓] Evidência capturada · ticket BRG-2826 aberto · cliente notificado em <15min
Methodology · 6 PHASES

From NDA signing to final report, every step is mapped

We combine OWASP, NIST SP 800-115, and PTES with our offensive expertise — no magic black-box, no elastic scope.

01

Pre-engagement

Scope, rules of engagement, written authorization, windows and contacts.

02

Reconnaissance

Attack surface: assets, subdomains, integrations, leaks.

03

Enumeration

Technologies, versions, endpoints, authentication flows and data.

04

Exploitation

Manual validation, vector chaining, proof of impact.

05

Post-exploitation

Lateral movement and escalation within the authorized perimeter.

06

Report

Prioritized findings, evidence, executive and technical roadmap.

Coverage · DEPTH MATRIX

Everything each plan tests, side by side

No fine print. What is marked is executed and documented in the final report.

Test AreaSilverGoldDiamond
OWASP Top 10 (Web)
OWASP API Security Top 10
OWASP ASVS Level 2
OWASP ASVS Level 3 (full)
STRIDE Threat Modeling
Business Logic Analysis
Transactional Fraud Detection
Source-code-assisted analysis
PCI-DSS / ISO 27001 Mapping
AI / LLM Security Add-on
Retests1 in 30 days2 in 90 daysUnlimited / 6 months
Included Partial / scoped Not included
COMPLEMENTARY

Pentest and EHT start in different places.

They are complementary approaches. The difference lies in the starting point, the methodology and the success criteria.

Pentest

Starts from an asset, application, API or infrastructure.

  • Question: where can this environment be compromised?
  • Evidence: vulnerability, exploitation and impact.

Berghem EHT

Starts from the adversarial objective and the business-critical asset.

  • Question: what can an adversary reach, and through which combinations?
  • Evidence: the chain of conditions leading to impact.
FRAMEWORK

CORE: from the critical asset to the evidence.

Berghem structures business-driven missions across four connected dimensions.

C

Core business

Money, data, identity, critical operations, trust and secrets.

O

Orchestration

Specialists, agents, models, tooling and authorized sources.

R

Routes

Technology, identities, rules, processes, controls and context.

E

Evidence

Logged actions, understandable impact, reproduction and recommendation.

CONTROL

Sufficient evidence, controlled impact.

The mission ends when the evidence criterion is met or when a boundary requires human intervention.

Deliverables

  • Route and hypothesis map.
  • Reproducible proofs.
  • Technical and business impact.
  • Recommendations and retest.

Rules of engagement

  • Permitted and blocked actions.
  • Segregated identities.
  • Time and volume limits.
  • Approval and stop conditions.

Frequently Asked Questions

What's the difference between Silver, Gold, and Diamond?
The three EHT tiers differ in methodology depth, retest coverage, and engagement duration. Silver delivers OWASP Top 10 testing with automated and manual techniques, one retest within 30 days, and 2–3 week delivery — ideal for startups and basic compliance needs. Gold adds OWASP ASVS Level 2 coverage, STRIDE threat modeling, and business logic analysis, with two retests across 90 days over a 3–4 week engagement. Diamond is the most comprehensive tier, with full OWASP ASVS Level 3, deep fraud detection, unlimited retests for six months, source-assisted review, and compliance mapping for PCI-DSS and ISO 27001.
Which tier should I choose?
The right tier depends on your security maturity, compliance requirements, and the criticality of the system being tested. Startups and early-stage products with basic compliance obligations are usually served well by Silver. Mid-size companies with production systems handling customer data and moderate regulatory exposure typically choose Gold, which is our most popular tier. Financial institutions, enterprises, and organizations subject to strict regimes like PCI-DSS or ISO 27001 should choose Diamond for its depth and compliance mapping. If you are unsure, our consultants will assess your environment and recommend the right tier at no cost.
Do you offer retests?
Yes. Retesting is included in every EHT tier so you can verify that remediation actually closed the findings. Silver includes one retest within 30 days of the initial report. Gold includes two retests within 90 days, giving teams more time to fix and validate. Diamond offers unlimited retests for six months, recognizing that enterprise and financial environments often require iterative fixes across multiple teams and change windows. Retests are conducted using the same methodology as the initial engagement, and we update the final report to reflect the current state of each finding.
How long does a pentest engagement take?
Engagement length varies by tier and scope. A Silver test typically runs for 2–3 weeks from kickoff to final report, including reconnaissance, testing, reporting, and debrief. Gold takes 3–4 weeks due to deeper methodology and threat modeling. Diamond runs for 4–6 weeks, covering full OWASP ASVS Level 3 coverage, business logic and fraud testing, and source-assisted review. We also factor in a kickoff meeting to align on scope and rules of engagement, and a closing session to walk stakeholders through findings. Rush timelines can be accommodated when necessary and commercially reasonable.
Do you test mobile apps?
Yes. Berghem tests mobile applications across Android and iOS as part of our EHT engagements, including native apps, hybrid apps, and mobile SDKs. We follow the OWASP MASVS and MASTG methodology, covering insecure data storage, insecure communication, authentication and session management, cryptography, code tampering, reverse engineering resistance, and runtime protections like SSL pinning and root or jailbreak detection. Mobile testing can be scoped standalone or as part of a broader engagement that also includes backend APIs and web admin panels, giving you coverage across the full mobile application stack.

Not Sure Which Plan to Choose?

Our security consultants will assess your environment, compliance requirements, and risk profile to recommend the ideal plan for your organization.

Talk to a Specialist