The Sythe Explorer / Security
Security, in practice.
A buyer asks for a pentest, a release changes who can see customer data, or your team needs visibility into its laptops. Decide what needs attention, then follow the testing and remediation work.
Illustrative situations and supported workflows, using no customer data.
9 illustrated stories
Security
Start with your situation
01 / Four chapters
A customer needs a pentest report before they can buy
The buyer asks for an independent test of your application. Agree what needs testing and what report they'll accept before commissioning the work.
Explore situation02 / Four chapters
You're about to put customer data into a new application
The demo is becoming a live service. Decide which security questions need answers before real customer records reach the application.
Explore situation03 / Four chapters
New payments, new roles, or a new API change the risk
An old assessment covered the old product. Check whether a new feature changes who can move money or reach customer data, then scope testing around that change.
Explore situation04 / Four chapters
The scanner found problems. Which ones need action?
A list of severe findings isn't a plan. Check what ran, whether the affected system is exposed, and what still needs investigation before choosing the next action.
Explore situation05 / Four chapters
You ship every week. Your last pentest is getting old.
A report describes the product that was tested. Compare its scope with today's service before deciding whether to retest fixes, assess new features, or keep scanning known targets.
Explore situation06 / Four chapters
Do you need EDR for your team's laptops?
Who would notice suspicious activity on a laptop with access to company systems? Decide whether endpoint detection and response fits that risk, and who will act on the information it produces.
Explore situation07 / Four chapters
You shipped the fix. Did it resolve the pentest finding?
The report is in, and an engineer has shipped a fix. A closed ticket doesn't establish that the reported behavior is gone. Follow the finding into a scoped retest to check whether the issue is resolved.
Explore situationSee how the work gets done
01 / Four chapters
Schedule vulnerability scans and check what actually ran
A scan was scheduled for this month. Did it finish, and which targets did it cover? See how Sythe Labs schedules approved scans and records the outcome of each run.
View walkthrough02 / Four chapters
Send a repository security finding to your issue tracker
An engineer picks up a security ticket and asks, 'Where is this coming from?' Investigate the finding first, then file an issue with the code references and a link saved on the original finding.
View walkthrough