Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
InternetMail gatewayPerimeter firewallRemote access VPNWeb applicationAPI gatewaySupplier accessCloud tenancyIdentity (AD, Entra ID)Office networkApplication serverWorkstationWorkstationWirelessFinance systemDomain controllerFile serverDatabaseBackupsCustomer dataexposed VPNweak credentiallocal admin reuseAD CS misconfigdomain adminreportopen portIDORmass assignmentSSRFreused DB passwordreportphishing emailmacro runsKerberoastDCSyncbackups deletedevil twinno isolationLLMNR poisoninggroup misusereportno MFAlegacy authrole escalationbackups reachedshared accountunpatched servicedomain adminexposed VPNweak credentiallocal admin reuseAD CS misconfigdomain adminreport

We find the way in before someone else does.

Aurian is an Australian penetration testing and security assurance firm, founded in 2020, working with organisations across the country. Senior consultants perform every test, all of it onshore, and every report is written so your own engineers can close the findings.

Scope a test See our services

Illustration: a map of a typical organisation's systems, on which attack paths are traced from the internet to customer data.

What we test

Each system an attacker crosses, and the test that covers it.

  • Internet
  • Perimeter
  • Email
  • Web application
  • API
  • Cloud tenancy
  • Wireless
  • Office network
  • Workstation
  • Identity
  • Servers
  • Crown jewels

Services, three groups

One method, fifteen services

Every engagement follows the Aurian engagement lifecycle: scope, test, report, retest. Choose the group that matches what you need to know.

Offensive, 8 services

Penetration testing

Manual testing of your perimeter, applications, cloud and people by senior consultants, reported so your own team can close every path.

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
See all 8 penetration testing services

Assurance, 3 services

Security assurance

Independent assessment against the Essential Eight, CIS Benchmarks and vendor guidance, with evidence gathered by testing rather than questionnaires.

  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
See all 3 security assurance services

Managed, 4 services

Managed security

Ongoing scanning and monitoring run by the same consultants who test, for organisations that need more than an annual engagement.

  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
See all 4 managed security services

The Aurian engagement lifecycle

Scope, test, report, retest

Four phases, whatever we are testing. You know what happens next before we start, and you know what you will hold at the end.

  1. 01 Scope

    We agree what is in and out, the test windows, the credentials and contacts, and the rules of engagement, in writing.

  2. 02 Test

    A senior consultant tests by hand, using automated tooling for coverage. You hear about serious findings the day we confirm them.

  3. 03 Report

    An executive summary for the board and the insurer, and technical findings with evidence and a fix your engineers can apply.

  4. 04 Retest

    Once you have remediated, we retest and update the report so the record shows what was found and what was closed.

Read how a penetration test with Aurian works

The report

What you receive

Every finding in an Aurian report looks like this: what we found, the evidence, what it means for your organisation, and what to change.

Extreme AUR-2026-014 Sample finding, fictional environment

AD CS misconfiguration allows privilege escalation to domain admin

Affected asset
Certificate template CorpComputer on CA01.corp.example.local
Rating
Extreme Likely 4 × Critical 6 = 24

Description

A published certificate template allows a standard domain user to request a certificate that authenticates as any account, including a domain administrator. This is the ESC1 misconfiguration: the template permits requesters to supply the subject name and enables client authentication.

Evidence

PS> Certify.exe find /vulnerable
[!] Vulnerable Certificate Template : CorpComputer
    Enrollment Rights   : CORP\Domain Users
    msPKI-Certificate-Name-Flag : ENROLLEE_SUPPLIES_SUBJECT
    pkiExtendedKeyUsage : Client Authentication
PS> Certify.exe request /template:CorpComputer /altname:CORP\Administrator
[*] Certificate issued for CORP\Administrator

A standard user account was able to request a certificate that authenticates as the domain Administrator.

Impact

Any user who can log in, including one an attacker has just phished, can become a domain administrator in minutes. From there the attacker controls every account, server and file share in the domain. There is no exploit code or missing patch here, only a misconfigured template, which is why it is so often missed.

Remediation

Remove the ENROLLEE_SUPPLIES_SUBJECT flag from the template, or restrict enrolment to a small, trusted group and require manager approval. Audit every template for the same pattern, and enable the certificate authority logging that records these requests so future abuse is visible.

References

  • MITRE ATT&CK, T1649 steal or forge authentication certificates
  • ASD, securing Active Directory

Sectors

Sectors we work in

Aurian works across every sector. These are the ones we work in most, with the audit and insurance drivers that shape each.

  • Federal government
  • State government
  • Local government
  • Independent and faith-based schools
  • Universities and tertiary education
  • Not-for-profits and associations
  • Financial services and lenders
  • Legal services
  • Professional services
  • Healthcare
  • Utilities and critical infrastructure
  • Manufacturing, construction and industrial
  • Technology and SaaS
  • Automotive, logistics and transport
  • Enterprise

Why Aurian

Why organisations choose Aurian

  • Senior consultants only

    Every engagement is performed by a senior Aurian consultant, onshore in Australia. Nothing is outsourced, offshored or crowdsourced.

  • Australian and independent

    Australian-owned, with consultants across the country. No vendor partnerships that shape what we recommend.

  • Standards-aligned, plainly reported

    OWASP, PTES, NIST SP 800-115, CIS Benchmarks and the ASD Essential Eight, written up so your own engineers can act without calling us.

  • Fixed-price engagements

    A fixed price agreed after scoping, so the cost is known before any testing starts.

Certifications

Examined by doing

Aurian's consultants hold offensive-security certifications that are examined by compromising live systems under time pressure.

  • OSCE certification badge

    OSCE

    OffSec Certified Expert

  • OSCP certification badge

    OSCP

    OffSec Certified Professional

  • OSWP certification badge

    OSWP

    OffSec Wireless Professional

Blog

Latest from the blog

Cybersecurity news and insights for Australian organisations, written by the people who do the testing.

Security Insights

How to read a penetration test report

What each section of a penetration test report is for, how severity ratings work, and how to turn the findings into a plan your team can actually run.

6 September 2026

Read all posts

Scope a test with a senior consultant

Tell us what you need to know about your environment. We reply within one business day.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.