What could a stranger do. Asked under a signed instrument, answered with evidence.
The Fenceline review tells you what a stranger can already see. Fenceline Pentest answers the question that comes next: what could they do. A named Bluebird Labs tester attacks named targets inside a named window, under Rules of Engagement your accountable authority signs, and every finding is the hash of stored evidence, screened by the Governor and verdicted by a person before it reaches you.
BEGIN PENTEST RULES OF ENGAGEMENT targets: www.agency.gov.au, app.agency.gov.au window: 2026-11-02 to 2026-11-13 streams: web, api exploitation: yes denial of service: no exclusions: status.agency.gov.au data handling: onshore stop contact: ciso@agency.gov.au END PENTEST RULES OF ENGAGEMENT
Five streams, enabled one at a time
The instrument names which streams run. A stream that is not enabled does not run, and the code enforces that.
Web
Public and authenticated web applications, tested against the full OWASP WSTG case set: configuration, identity, authentication, session management, input validation, business logic, client-side.
API
REST and GraphQL interfaces, including the endpoints the frontend never calls. Authorisation between objects and between tenants is where the findings live.
Cloud
The tenancy's own configuration, read under the instrument: storage exposure, identity sprawl, subdomain takeover, logging that would not notice a stranger.
Network
The perimeter the web properties sit on: exposed services, weak transport, management interfaces that should never answer the internet.
Local applications
Desktop and line-of-business applications, including rollout candidates. A ServiceNow rollout is the expected first engagement shape.
The Rules of Engagement are the product
Every engagement runs under an instrument your accountable authority signs. It extends the write-test clause model from the review: what is named runs, what is not named does not, and the exclusions list always wins.
Exact, never guessed
Targets are named hosts and networks, never suffixes. A host you forgot you had is a conversation about a new instrument, not a quick look. The window is a gate in the code, not a guideline in a runbook.
Techniques, yes or no
Exploitation, denial of service, social engineering and credential use are each named and each answered. Absent means no. Proof-of-concept only: the question is whether the door opens, demonstrated once, with evidence.
Deconflicted before it starts
Your security team knows the window and the egress range before anything runs, and the instrument names the stop contact. A test that trips your alert is a conversation, not an incident.
A versioned methodology, not a wiki page
The method is data: the OWASP Web Security Testing Guide case set mapped to PTES phases, versioned and hashed like everything else we run. The plan for your engagement is generated from it, and the report shows coverage rather than asserting it.
Pre-engagement
Scope, instrument, deconfliction, whitelist.
Intelligence gathering
The estate as a stranger maps it. Subscribers start from the review's exposure register.
Vulnerability analysis
Configuration, identity, transport and platform weaknesses, each logged against the plan.
Exploitation
Where the instrument permits: proof once, with evidence, nothing more.
Findings
Hashed, Governor-screened, verdicted by a person. A draft never ships.
Report and retest
The house pack, then a retest of every confirmed finding where the instrument includes one.
Every finding is evidence
A finding is the hash of what was recorded: the stream, the target, the test cases that raised it, a CVSS 4.0 vector, the assessor's severity, and the sha256 of every byte of evidence behind it.
Screened, then verdicted
The Governor, Bluebird Labs' control layer, screens every finding before a person verdicts it: confirmed, false positive or withdrawn. The report builder refuses to render while any finding lacks a verdict.
Mapped, and labelled
Findings map to the ISM, the Essential Eight and PSPF, labelled in print as the unverified working mapping it is until a person confirms each identifier against the source.
The read and the test are different businesses
Continuous assurance
A read-only, outside-in walk of your public estate under written authority, then a daily diff. It answers what a stranger can already see, every morning, and it never writes.
A point-in-time attack with written authority
A named tester, a signed instrument, a fixed window. It answers what a stranger could do, once, and proves each answer with evidence. Separate engagement, separate price, separate egress range so test traffic never taints the daily watch.
What you receive
- ✓Rules of Engagement summary. What was signed: targets, window, streams, techniques, and the instrument's sha256, so the report and the signature cannot drift apart.
- ✓Methodology coverage. The cases planned against the findings raised, per phase, so the report shows what was tested rather than asserting it.
- ✓Findings report. Every confirmed finding with its CVSS 4.0 vector, severity, evidence hashes and ISM, Essential Eight and PSPF mapping.
- ✓Remediation list. The action for each confirmed finding, written for the team that will do it.
- ✓Executive brief. One page for the secretary or board.
- ✓Retest and assurance statement. Every confirmed finding retested where the instrument includes a retest, with the result appended to the evidence trail.
How to buy
Fenceline Pentest is bought through Bluebird Labs' Commonwealth panel position, priced within the verified Commonwealth band for whole-of-scope work. A fixed-scope engagement, one system or one rollout, carries the low end. The sequence is standard and the instrument does the work.
1. Scoping call
You name the estate and the worry. We name the streams that apply and the fixed scope, and price it the same week.
2. Rules of Engagement
Your accountable authority signs: targets, window, streams, techniques, exclusions, contacts. Template on request.
3. Whitelist and window
You whitelist our documented egress range. The test runs inside the window, deconflicted with your security team.
4. Report and retest
The house pack: instrument summary, coverage, findings, remediation, brief. Confirmed findings retested where the instrument includes it.
Scope an engagement
Ask for the service sheet or book a scoping call. The first estate we run this process on is our own: no client engagement precedes the dogfood.