Skip to main content

How We Work

ARGUS Methodology

Every LawKade engagement follows an eight-phase methodology built on a single principle: no active testing without documented authorization. Every action is scoped, logged, attributed, and reviewed by a human analyst before findings reach the client.

  1. Authorization

    No work begins without documented, signed authorization.

    • Written authorization signed by the asset owner
    • Scope document specifying approved targets
    • Approved testing window with start and end times
    • Emergency contact and stop-work procedures
    • Data-retention and handling agreement
    • LawKade analyst approval before any activity
  2. Scope Definition

    Approved targets, exclusions, and permitted techniques are codified before work begins.

    • Target domains, IP ranges, and cloud accounts entered into ARGUS
    • Prohibited systems and out-of-scope assets explicitly listed
    • Allowed techniques enumerated and recorded
    • Prohibited techniques explicitly documented
    • Scope approval required from both client and LawKade before activation
  3. Passive Discovery

    Public-only intelligence gathering — no active scanning until authorization is confirmed.

    • DNS enumeration and certificate transparency log review
    • WHOIS, RDAP, and ASN relationship mapping
    • Open-source exposure identification
    • Breach and credential-exposure checks
    • No network traffic to target systems at this phase
  4. Controlled Validation

    Active techniques executed exclusively within the approved scope and window.

    • All requests attributed to LawKade-owned infrastructure
    • Scope enforcement verified in ARGUS before each job dispatch
    • Loopback, private-network, and cloud-metadata targets blocked at the platform level
    • All actions logged with timestamps, actor identity, and target
    • Emergency stop capability available to client and analyst at all times
  5. Analyst Review

    Every machine-generated finding is reviewed by a LawKade analyst.

    • False-positive elimination before findings are surfaced to clients
    • Severity rating informed by exploitability and business context
    • Confidence score assigned to each finding
    • Analyst disposition and notes attached
  6. Risk Prioritization

    Findings ranked by exploitability, business impact, and exposure level.

    • CVSS base score calculated where applicable
    • Analyst-reviewed severity may differ from CVSS alone
    • Business impact assessment for critical and high findings
    • Remediation order recommended by risk profile, not just severity
  7. Evidence-Backed Reporting

    Reports include SHA-256-hashed evidence and chain-of-custody records.

    • Executive summary with risk posture and severity totals
    • Technical findings report with full detail and evidence
    • Each finding includes discovery source, timestamps, and analyst notes
    • Evidence hashed at collection and verified at report time
    • Reports marked CONFIDENTIAL with client name and assessment scope
    • Report version and analyst reviewer recorded
  8. Remediation Tracking

    Findings remain open until retested and confirmed resolved.

    • Findings assigned to owner with due date
    • Client updates remediation status through ARGUS
    • LawKade analyst performs retest on request
    • Closure requires analyst confirmation, not self-attestation
    • Full timeline and closure documentation retained

Ready to start an authorized assessment?

Tell us about your organization and objectives. We will review your request and contact you to discuss scope, authorization requirements, and engagement structure.