Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. Services

Services

Fifteen services in three groups, all run through the Aurian engagement lifecycle: scope, test, report, retest. Each page explains exactly what we test, how, and what you receive.

Offensive, 8 services

Penetration testing

Manual testing of your perimeter, applications, cloud and people by senior consultants, reported so your own team can close every path.

Penetration testing services

External network penetration testing

External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

You receive Findings for every exposed service, each with evidence and a fix, and a debrief call on the priorities

Internal network penetration testing

Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

You receive The attack path drawn out from foothold to domain admin, step by step, with a fix for each link

Web application penetration testing

Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

You receive Findings with evidence and reproduction steps, and a debrief with your development team

API penetration testing

API penetration testing for REST, GraphQL and SOAP against the OWASP API Security Top 10: authorisation, rate limiting and undocumented endpoints.

You receive An inventory of every endpoint tested, undocumented ones included, with the request that reproduces each finding

Mobile application penetration testing

Mobile application penetration testing for iOS and Android against OWASP MASVS: local storage, transport security, reverse engineering and the API.

You receive One report covering the app and the API it depends on, with evidence from the device

Wireless penetration testing

Wireless penetration testing of corporate and guest Wi-Fi: WPA2 and WPA3-Enterprise, rogue access points, guest isolation and signal leakage.

You receive A signal survey of where your networks reach beyond your walls, with findings ranked by risk

Cloud security assessment

Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

You receive The identity attack paths drawn out, from ordinary account to tenancy control, mapped to the CIS Benchmark

Social engineering and phishing simulation

Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

You receive Aggregate results, the reporting rate above all, and the process gaps behind them. Nothing that names individuals

Assurance, 3 services

Security assurance

Independent assessment against the Essential Eight, CIS Benchmarks and vendor guidance, with evidence gathered by testing rather than questionnaires.

Security assurance and compliance services

Essential Eight assessment

Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

You receive A maturity rating for each of the eight strategies, with the evidence behind it and a prioritised uplift roadmap

Configuration review and benchmarking

Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

You receive A finding for each deviation, ranked by risk, with the exact setting to change

Remediation support and retesting

Penetration test remediation support and retesting: hands-on help closing findings, sessions with your engineers or MSP, and a formal retest and report.

You receive A formal retest of the remediated findings and an updated report recording what has been closed

Managed, 4 services

Managed security

Ongoing scanning and monitoring run by the same consultants who test, for organisations that need more than an annual engagement.

Managed security services

Vulnerability management

Managed vulnerability management: continuous scanning of external and internal assets, results validated and ranked by a consultant, reported monthly.

You receive A monthly report ranked by exploitability, false positives already removed, and a standing point of contact

Continuous application scanning

Continuous web application scanning between manual tests: authenticated scans with human review, drift detection between releases and monthly summaries.

You receive Consultant-reviewed findings after every release, with false positives removed and drift since the last scan

SIEM monitoring

Managed SIEM monitoring: correlation and triage of events from network, endpoint, cloud and identity sources, with rule tuning and monthly reporting.

You receive Analyst-triaged alerts with context and a recommended action, mapped to MITRE ATT&CK

EDR monitoring

Managed EDR monitoring on your endpoint platform: alert triage, investigation, containment guidance, threat hunting and tuning by the consultants who test.

You receive Triaged, investigated alerts with a containment action, plus threat hunting across the fleet

Tell us what you need to know

Describe the system, the deadline and who is asking for the test. We will tell you which engagement fits and what it involves.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.