Bluebird bluebird labs Fenceline Pentest
Signed Rules of Engagement · Named testers · Analysed onshore · Nothing leaves Australia
Signed Rules of Engagement · Five streams · Evidence standard

What could a stranger do. Asked under a signed instrument, answered with evidence.

The Fenceline review tells you what a stranger can already see. Fenceline Pentest answers the question that comes next: what could they do. A named Bluebird Labs tester attacks named targets inside a named window, under Rules of Engagement your accountable authority signs, and every finding is the hash of stored evidence, screened by the Governor and verdicted by a person before it reaches you.

97
versioned test cases in the methodology, mapped to PTES phases
5
streams: web, API, cloud, network, local applications
0
bytes of your estate sent offshore. Ever.
The windowIllustration
THE SIGNED WINDOW excluded: always wins a named tester, whitelisted everyone else
targets: exact, never guessedexclusions: win every time
Rules of Engagement · machine-readable termsIllustration
BEGIN PENTEST RULES OF ENGAGEMENT
targets: www.agency.gov.au, app.agency.gov.au
window: 2026-11-02 to 2026-11-13
streams: web, api
exploitation: yes
denial of service: no
exclusions: status.agency.gov.au
data handling: onshore
stop contact: ciso@agency.gov.au
END PENTEST RULES OF ENGAGEMENT
The code enforces this block. An unknown line is refused as a term nobody enforces. Values shown are placeholders.
Scope

Five streams, enabled one at a time

The instrument names which streams run. A stream that is not enabled does not run, and the code enforces that.

01

Web

Public and authenticated web applications, tested against the full OWASP WSTG case set: configuration, identity, authentication, session management, input validation, business logic, client-side.

02

API

REST and GraphQL interfaces, including the endpoints the frontend never calls. Authorisation between objects and between tenants is where the findings live.

03

Cloud

The tenancy's own configuration, read under the instrument: storage exposure, identity sprawl, subdomain takeover, logging that would not notice a stranger.

04

Network

The perimeter the web properties sit on: exposed services, weak transport, management interfaces that should never answer the internet.

05

Local applications

Desktop and line-of-business applications, including rollout candidates. A ServiceNow rollout is the expected first engagement shape.

Authorisation

The Rules of Engagement are the product

Every engagement runs under an instrument your accountable authority signs. It extends the write-test clause model from the review: what is named runs, what is not named does not, and the exclusions list always wins.

Exact, never guessed

Targets are named hosts and networks, never suffixes. A host you forgot you had is a conversation about a new instrument, not a quick look. The window is a gate in the code, not a guideline in a runbook.

Techniques, yes or no

Exploitation, denial of service, social engineering and credential use are each named and each answered. Absent means no. Proof-of-concept only: the question is whether the door opens, demonstrated once, with evidence.

Deconflicted before it starts

Your security team knows the window and the egress range before anything runs, and the instrument names the stop contact. A test that trips your alert is a conversation, not an incident.

Method

A versioned methodology, not a wiki page

The method is data: the OWASP Web Security Testing Guide case set mapped to PTES phases, versioned and hashed like everything else we run. The plan for your engagement is generated from it, and the report shows coverage rather than asserting it.

1

Pre-engagement

Scope, instrument, deconfliction, whitelist.

2

Intelligence gathering

The estate as a stranger maps it. Subscribers start from the review's exposure register.

3

Vulnerability analysis

Configuration, identity, transport and platform weaknesses, each logged against the plan.

4

Exploitation

Where the instrument permits: proof once, with evidence, nothing more.

5

Findings

Hashed, Governor-screened, verdicted by a person. A draft never ships.

6

Report and retest

The house pack, then a retest of every confirmed finding where the instrument includes one.

Every finding is evidence

A finding is the hash of what was recorded: the stream, the target, the test cases that raised it, a CVSS 4.0 vector, the assessor's severity, and the sha256 of every byte of evidence behind it.

Screened, then verdicted

The Governor, Bluebird Labs' control layer, screens every finding before a person verdicts it: confirmed, false positive or withdrawn. The report builder refuses to render while any finding lacks a verdict.

Mapped, and labelled

Findings map to the ISM, the Essential Eight and PSPF, labelled in print as the unverified working mapping it is until a person confirms each identifier against the source.

The two products

The read and the test are different businesses

Fenceline Review

Continuous assurance

A read-only, outside-in walk of your public estate under written authority, then a daily diff. It answers what a stranger can already see, every morning, and it never writes.

Fenceline Pentest

A point-in-time attack with written authority

A named tester, a signed instrument, a fixed window. It answers what a stranger could do, once, and proves each answer with evidence. Separate engagement, separate price, separate egress range so test traffic never taints the daily watch.

Deliverables

What you receive

  • ✓Rules of Engagement summary. What was signed: targets, window, streams, techniques, and the instrument's sha256, so the report and the signature cannot drift apart.
  • ✓Methodology coverage. The cases planned against the findings raised, per phase, so the report shows what was tested rather than asserting it.
  • ✓Findings report. Every confirmed finding with its CVSS 4.0 vector, severity, evidence hashes and ISM, Essential Eight and PSPF mapping.
  • ✓Remediation list. The action for each confirmed finding, written for the team that will do it.
  • ✓Executive brief. One page for the secretary or board.
  • ✓Retest and assurance statement. Every confirmed finding retested where the instrument includes a retest, with the result appended to the evidence trail.
Procurement

How to buy

Fenceline Pentest is bought through Bluebird Labs' Commonwealth panel position, priced within the verified Commonwealth band for whole-of-scope work. A fixed-scope engagement, one system or one rollout, carries the low end. The sequence is standard and the instrument does the work.

1. Scoping call

You name the estate and the worry. We name the streams that apply and the fixed scope, and price it the same week.

2. Rules of Engagement

Your accountable authority signs: targets, window, streams, techniques, exclusions, contacts. Template on request.

3. Whitelist and window

You whitelist our documented egress range. The test runs inside the window, deconflicted with your security team.

4. Report and retest

The house pack: instrument summary, coverage, findings, remediation, brief. Confirmed findings retested where the instrument includes it.

Scope an engagement

Ask for the service sheet or book a scoping call. The first estate we run this process on is our own: no client engagement precedes the dogfood.

Request the service sheet Scope an engagement