As cyber attacks become more sophisticated every day, it is essential that your organization takes a proactive approach to cybersecurity and addresses vulnerabilities before attackers find them.
As ADEO, our expert teams identify security vulnerabilities on critical systems and make it possible to eliminate these vulnerabilities by taking measures before they are used by attackers.
Black Box Penetration Test
In Black Box testing, we perform security tests based on real scenarios without obtaining information from the organization and report them in detail.
Gray Box Penetration Test
In Gray Box testing, we perform security tests on target systems with the authorization of previously authenticated users. This helps in taking necessary precautions by seeing the potential damage that attackers can cause along with stealing information belonging to company employees.
White Box Penetration Test
We perform White Box Penetration Testing with "Administrator" or "Root" level access privileges. This usually involves access to important resources such as architectural diagrams, design documents, specifications, and source code. White Box Penetration Testing presents an ideal approach for developing your own products or integrating your system into your environment.
Our Methodology
We follow a seven-step methodology designed to maximize our efficiency, minimize risk and provide complete and accurate results.

Types of Penetration Tests
The penetration tests offered by ADEO are divided into different categories. The details are as follows:
Network Penetration Testing
The network penetration testing service offered by ADEO is designed to detect vulnerabilities in networks, systems, servers, clients and other network devices. Its purpose is to help clients identify potential vulnerabilities before they are discovered and exploited by malicious actors and to help prevent potential cyber attacks.
To identify security vulnerabilities in your IT infrastructure, we conduct security scans on the client, server and active network devices. ADEO's Network Penetration Testing service aims to detect vulnerabilities before they can be exploited by malicious actors and prevent potential cyberattacks. During the scanning process, we utilize both open-source and licensed software that has been proven by the industry.
One of the optional steps in ADEO Network Penetration Testing service is configuration review. ADEO security experts perform a compliance check on your mission-critical servers, active network devices (switch, router, firewall, IPS, etc.) and client computers with generally accepted security criteria by reviewing the definitions and settings on these devices. They do not perform console access themselves in any way. Configuration reviews are conducted with the participation of authorized persons from the relevant department of your company.
Web Application Penetration Testing Service
In today's internet world, ensuring the security of the software used in your IT infrastructure is important. To achieve this, it is necessary to ensure that the software does not contain application vulnerabilities and regular application penetration tests are needed to detect any vulnerabilities in advance and prevent them from being exploited by malicious actors. ADEO's Web Application Penetration Testing service utilizes black-box penetration testing to evaluate the security of your applications and provide recommendations for necessary measures to ensure a secure application infrastructure.
In web application penetration tests, the following tests are performed to determine whether there are any vulnerabilities in your applications that can be exploited by attackers.
- Buffer Overflow Tests (Heap Overflow, Stack Overflow, Format String Overflow)
- Access Permission and Authorization Bypass
- Path Traversal and Forceful Browsing
- Privilege Escalation Attacks
- SSL Analysis (SSL Traffic Analysis)
- User and System Administrator Rights Segregation Tests (Segregation of Duties)
- Data Input Controls (Input Validation, URL validation, XML Injection, XPATH Injection)
- Output Validation
- User Authentication Tests (User Authentication, User Enumeration, Default User Accounts, Authentication Bypass, Password Reset Vulnerabilities, Captcha Breaking, Race Conditions)
- Session Management Tests (Session Management, Session Fixation)
- Weak Password Structures (Weak Passwords)
- Cross Site Scripting (Reflected Cross Site Scripting, Stored Cross Site Scripting, DOM Based Cross Site Scripting, Cross Site Flashing)
- Unsecure Data Storage
- Parameter Manipulation Tests
- SQL Injection
- Command Injection
- Handling Errors and Exceptions (Error Handling, Exception Handling)
Wireless Network Penetration Testing Service
We perform authorized and unauthorized security tests on your organization's wireless network access points. The purpose of the test is to check whether an external attacker can access the network, and if so, what kind of damage it can cause. Tests can be customized upon request. We can test any of the fake access point, brute force attack and ARP poisoning attack techniques.
Mobile Application Security Testing
We focus on identifying potential security vulnerabilities by examining the APIs, addresses and application source code that the mobile app connects to. The purpose of the test is to determine what kind of damage the attacker can do through the mobile application. Our tests are performed using OWASP mobile security methodology.
Social Engineering Services
The use of social engineering techniques is a crucial aspect of cybersecurity testing, and asADEO we offer services that test your organization's susceptibility to such attacks. We utilize email phishing and voice phishing techniques to measure how easily users can be deceived into providing confidential information or granting unauthorized access to their devices. By simulating these types of attacks, we can identify potential weaknesses and help you take proactive measures to prevent real-world breaches.
Our email phishing services simulate cybercriminals using common techniques. Unlike automated phishing services that rely on ready-made templates, we conduct research on your organization and its users. We use various tools and Open Source Intelligence (OSINT) methods to gather information that is useful for phishing and hunting techniques for your users. We utilize a combination of manual methods and automated tools to provide realistic phishing simulations tailored to your unique environment and users.
DDoS Tests
İstenilen saldırı tekniği kullanılarak sisteminizin yük altında veya DDoS (Distributed Denial of Service) saldırıları karşısında nasıl tepki verdiğini test ederiz. Geliştirdiğimiz özel araç sayesinde birçok saldırı tipi gerçekleştirilebilmektedir.
We test how your system reacts under load or in the face of DDoS (Distributed Denial of Service) attacks using the desired attack technique. Thanks to the special tool we have developed, many types of attacks can be realized.
The supported attack types are as follows:
- SYN Flood
- SYN/ACK Flood
- ACK Flood
- Null TCP
- Null UDP
- UDP Flood
- DNS Flood
- ICMP Flood
- TCP Connection Flood
- PUSH/ACK Flood
- RST/FIN Flood
- SSL Flood
- HTTP GET Flood
- HTTPS GET Flood
- HTTP GET Flood (Proxy)
Static Source Code Security Analysis
After receiving the organization's source codes, we conduct static security tests on the project to detect vulnerabilities with a high probability. Based on the programming language and platform used, we provide solution suggestions for closing the security vulnerabilities quickly and accurately.
Our Competencies
As ADEO , we are one of the first companies to win the "Network and System Infrastructure" and "Web Applications and Databases" competencies by successfully fulfilling the qualifications in the stages of certification of penetration testing companies within the scope of TS 13638/T2 "Information Technologies - Security Techniques - Requirements for penetration testing personnel and companies" standard issued by TSE.