How We Work
ARGUS Methodology
Every LawKade engagement follows an eight-phase methodology built on a single principle: no active testing without documented authorization. Every action is scoped, logged, attributed, and reviewed by a human analyst before findings reach the client.
Authorization
No work begins without documented, signed authorization.
- Written authorization signed by the asset owner
- Scope document specifying approved targets
- Approved testing window with start and end times
- Emergency contact and stop-work procedures
- Data-retention and handling agreement
- LawKade analyst approval before any activity
Scope Definition
Approved targets, exclusions, and permitted techniques are codified before work begins.
- Target domains, IP ranges, and cloud accounts entered into ARGUS
- Prohibited systems and out-of-scope assets explicitly listed
- Allowed techniques enumerated and recorded
- Prohibited techniques explicitly documented
- Scope approval required from both client and LawKade before activation
Passive Discovery
Public-only intelligence gathering — no active scanning until authorization is confirmed.
- DNS enumeration and certificate transparency log review
- WHOIS, RDAP, and ASN relationship mapping
- Open-source exposure identification
- Breach and credential-exposure checks
- No network traffic to target systems at this phase
Controlled Validation
Active techniques executed exclusively within the approved scope and window.
- All requests attributed to LawKade-owned infrastructure
- Scope enforcement verified in ARGUS before each job dispatch
- Loopback, private-network, and cloud-metadata targets blocked at the platform level
- All actions logged with timestamps, actor identity, and target
- Emergency stop capability available to client and analyst at all times
Analyst Review
Every machine-generated finding is reviewed by a LawKade analyst.
- False-positive elimination before findings are surfaced to clients
- Severity rating informed by exploitability and business context
- Confidence score assigned to each finding
- Analyst disposition and notes attached
Risk Prioritization
Findings ranked by exploitability, business impact, and exposure level.
- CVSS base score calculated where applicable
- Analyst-reviewed severity may differ from CVSS alone
- Business impact assessment for critical and high findings
- Remediation order recommended by risk profile, not just severity
Evidence-Backed Reporting
Reports include SHA-256-hashed evidence and chain-of-custody records.
- Executive summary with risk posture and severity totals
- Technical findings report with full detail and evidence
- Each finding includes discovery source, timestamps, and analyst notes
- Evidence hashed at collection and verified at report time
- Reports marked CONFIDENTIAL with client name and assessment scope
- Report version and analyst reviewer recorded
Remediation Tracking
Findings remain open until retested and confirmed resolved.
- Findings assigned to owner with due date
- Client updates remediation status through ARGUS
- LawKade analyst performs retest on request
- Closure requires analyst confirmation, not self-attestation
- Full timeline and closure documentation retained