Skip to main content
Offensive security · delivered by NaviSec

Find out what an attacker finds.
Before they do it for free.

Vulnerability assessment through red team, delivered by NaviSec Delta and available white-label to Vijilan partners. We run the defense. They test it. You get the part most security programs never buy: a second opinion from someone trying to get in.

The short answer

Vijilan brings penetration testing to its partners and customers through NaviSec, LLC, whose Delta practice performs the engagements. Vijilan does not run the tests. We scope them, we sit in on remediation, and where we run the SOC we treat the test as a check on whether our own detection saw it.

Four tiers: a quarterly Vulnerability Assessment, an annual full-scope Penetration Test, an Application and API test for clients who ship software, and Red or Purple Team for organizations that already expect to pass a pentest.

Every engagement is scoped per client rather than from a template, and every one ends with a review call and 90 days of free retesting. MSPs can resell all four; the client relationship stays with the MSP.

Why it sits next to the SOC

Detection tells you what it saw.
A pentest tells you what it missed.

Monitoring is a claim about coverage, and the only honest way to test a claim about coverage is to have somebody competent try to get past it. That is the whole argument for buying offensive testing alongside managed detection rather than instead of it.

When Vijilan runs the SOC and NaviSec runs the test, the alerting during the testing window stops being noise and becomes the deliverable. Either the detection fired on the activity or it did not, and both answers are worth paying for. NaviSec spins up a fresh cloud environment per engagement and routes operator traffic through it specifically so that the question every SOC asks during a test, which is “is this you?”, has a clean answer.

It also works the other way. A finding that never showed up in the SOC is a detection gap with a reproduction case attached, which is a far more useful input to tuning than a vendor feature request.

Four engagements

Pick the one that answers
the question you are being asked.

Most organizations are buying this because someone asked them to. Which tier you need depends on who is asking and what they will accept as an answer.

Essential
Vulnerability Assessment
Quarterly

A point-in-time picture of what is unpatched, misconfigured or exposed, then a human reading it. NaviSec is explicit that the value is the interpretation rather than the scan: the report ties findings to the client’s industry and operations instead of reprinting scanner output under a new logo.

  • External vulnerability scan across the estate
  • Analyst interpretation, mapped to business risk
  • Executive report aimed at the underlying problem, not each symptom
  • Runs quarterly as the baseline under an annual test
Most asked for
Advanced
Full-scope Penetration Test
Annual

An adversary simulation rather than a scan. Reconnaissance from public sources, then active discovery, then exploitation, with post-exploitation and lateral movement where the engagement is grey-box. NaviSec publishes one to two weeks as the typical black-box window, varied per engagement.

  • Everything in Essential, plus
  • OSINT: employee enumeration, breach and dark web exposure, asset discovery
  • Active recon: port and service discovery, subdomain takeover analysis, framework fingerprinting
  • Exploitation: password spraying, phishing and spearphishing, web application exploitation
  • Grey-box post-exploitation: Active Directory mapping, lateral movement, NetBIOS and LLMNR poisoning
  • Hand-crafted executive report plus a review call with the engineer who ran it
  • AfterGuard: free retesting of every finding for 90 days
Premium
Application and API Penetration Test
Per application

The same methodology aimed at software your client builds or depends on. Testers spend the first phase understanding what the application is for, because the interesting flaws are usually in the business logic rather than in a library version.

  • Everything in Advanced, applied at the application layer
  • OWASP Top 10 as the assessment spine
  • Authentication, session handling, password reset and access control
  • Input validation, file upload testing and API assessment
  • Encryption and cryptography review
  • Web server and supporting infrastructure configuration
Elite
Red Team and Purple Team
Objective-driven

A test of the defense rather than of the estate. The red team maps the blue team’s controls first, then works toward a named objective while trying to stay undetected. Purple Team runs the same engagement with both sides in the room and the learning as the deliverable.

  • Everything in Advanced, plus
  • Control mapping against the live detection and response stack
  • Objective-led: persistence, data access, exfiltration, source-code modification
  • Detection-evasion as an explicit goal, so the finding is what was missed
  • Purple Team option: red and blue working the exercise together
  • Blue-team outcomes named up front: prevent, stop, slow, contain, detect, remediate

Scope, duration and price are set per engagement. NaviSec scopes from a conversation rather than a template, which is why there is no price on this page and why anyone quoting one before a scoping call is quoting a guess.

How an engagement runs

Six stages,
and one of them is after the report.

01

Pre-engagement

A conversation about what you are actually trying to prove. Compliance evidence, an insurance renewal and a genuine assurance question produce different engagements.

02

Scoping

Size, scale and rules of engagement. NaviSec scopes per client rather than from a template, which is the reason the quote is a conversation and not a price list.

03

Assessment

The testing window. The engineer is reachable throughout, and contacts your technical point of contact immediately on a critical finding, a live breach or an insider-threat indicator rather than saving it for the report.

04

Reporting

Findings triaged, proof of concept built, report hand-written and then put through QA before anyone sees it.

05

Delivery

An encrypted archive, then a review call where the engineers walk the findings and answer remediation questions.

06

AfterGuard

Free retesting of the identified issues for 90 days after delivery, so remediation gets verified rather than assumed.

Method

Techniques first,
tools second.

NaviSec describes its approach as tactics-led rather than tool-led: the engagement is built around the techniques, tactics and procedures a real attacker would use, and the tooling is incidental to that and changes between engagements. Their engineers write custom tooling where nothing off the shelf fits the scenario.

Engagements follow the MITRE ATT&CK framework and the PTES standard, with the OWASP Top 10 as the spine of application testing. The distinction that matters to a buyer is the one NaviSec draws itself: plenty of vendors run a scanner and put their logo on the output, and a client capable of running that scan is not buying a scan. They are buying somebody deciding what it means.

Method, tooling and scope described here are NaviSec’s own, taken from their 2025 product guides and navisec.io. Vijilan does not perform these engagements.

For partners

A service you can sell
without building a red team.

You keep the client

The engagement is sold and delivered under the arrangement you already have with us. We never compete with our partners for their clients, and that applies to a partner-delivered service exactly as it applies to the SOC.

The trigger is usually not security

Most pentests get bought because a cyber-insurance renewal, a customer security questionnaire or a compliance regime asked for one. Those are calendar events you can see coming, which makes this the rare security service you can pipeline.

It pairs with the monitoring you already sell

A test against an environment we monitor is also a test of whether the monitoring saw it. That is a better QBR slide than a clean scan, and it is an honest one either way it lands.

Commercials sit behind partner verification

Rates, margin and the referral mechanics are in the Partner Portal rather than on a page your client can read. Get verified and they are there in about two minutes.

If you already run ThreatRespond or ThreatDefend for a client, offensive testing is the natural next line on the same account, and the one most likely to be approved because somebody outside the relationship is asking for it.

Get the engagement guides

What is actually in a NaviSec engagement: scope, methodology, tooling, the report, and what happens in the 90 days after. Sent by email, no download link to pass around.

Which guides
Work email required. We do not sell your address, and one reply stops the follow-up.
Questions

The ones people
actually ask.

Who actually performs the penetration test?

NaviSec, LLC, through its Delta offensive-security practice. Vijilan does not perform penetration tests. We bring the engagement to a partner who does this as their primary business, stay involved through scoping and remediation, and run the detection and response side where the client is also a Vijilan customer.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment finds what is exposed and tells you how bad it looks. A penetration test finds out whether it can actually be used, by someone trying to use it. The assessment is a quarterly baseline; the test is the annual answer to "could someone really get in". NaviSec packages them together for that reason, with quarterly assessments under an annual test.

Will the test set off our SOC?

It should, and that is part of the value. NaviSec initializes a fresh cloud environment per engagement and routes operator traffic through it, so when alerts fire the question "is this you?" has a clean answer. Where Vijilan runs the SOC, we coordinate the window in advance and the alerting becomes a record of what the defense actually caught.

What does a penetration test cost?

It depends on scope, and anyone quoting a number before a scoping call is quoting a template. Engagements are sized on the estate, the objective and the depth of testing. Partners see rates in the Partner Portal after verification; end customers get a quote after a scoping call, which takes about twenty minutes.

What happens after the report?

A review call where the engineers walk the findings, then AfterGuard: NaviSec retests the identified issues free for 90 days after delivery. That window matters more than it sounds, because it is the difference between a report that says what was wrong and a report that shows it was fixed.

Can an MSP resell this to their own clients?

Yes, and that is the main way it is delivered. The MSP owns the client relationship throughout. Commercial terms sit behind partner verification in the Partner Portal rather than on this page.

Is a penetration test the same as a red team engagement?

No. A penetration test asks how much of the estate can be compromised and reports everything it finds. A red team engagement picks an objective, tries to reach it without being detected, and the finding is as much about what your defense missed as about the route in. Buy the pentest first; the red team is worth it once you already expect to pass one.

Twenty minutes, no deck

Scope it with the engineer
who would run it.

Tell us what you are being asked to prove and who is asking. You will get a straight answer about which tier fits, including when the answer is that you do not need the expensive one yet.