ThreadFusion
Aligned with NIST SP 800-115

Methodology

Your auditor will ask which methodology was followed. This page is the answer, and it is written to be handed over as it is.

01

Planning

NIST SP 800-115 §3

Rules of engagement in writing before anything is touched: the assets in scope, what is explicitly excluded, the testing window, and the escalation contact on your side. Every host is matched against that list programmatically before a single request goes out, with anchored matching, so a lookalike domain can never slip into scope by accident.

02

Discovery

NIST SP 800-115 §4

Passive first — certificate transparency, passive DNS and public corpora, none of which touch your infrastructure. Then live-host verification and route discovery. Enumeration always runs from several independent sources, because any single source misses assets that the others find. One pass is not a measurement.

03

Attack

NIST SP 800-115 §5

Every candidate is verified by hand before it becomes a finding, and each verification carries its own control: a positive control proving the instrument works, and a differential against an impossible path proving the server is not simply answering 200 to everything. Nothing destructive, nothing outside the window, and no data of yours moved, altered or deleted.

04

Reporting

NIST SP 800-115 §6

An executive summary in plain language and a technical body with reproduction steps your engineers can follow line by line. Severity ranked by reachability, not by CVSS alone. Plus the remediation retest and a dated attestation letter for your audit file.

The coverage statement

Every report ends with what could NOT be measured, and why: a host behind a bot wall, a flow that needed credentials I was not given, a check that timed out.

This is not a disclaimer, it is the whole point. A scanner that cannot reach a host reports nothing, and the page looks clean. A 403 from a bot manager and a host running no service produce exactly the same silence — and only one of them is safe.

If a gap is written down, you can decide what to do about it. If it is hidden, you are trusting a blank space.

What your auditor receives

  • Named methodology with its standard reference (NIST SP 800-115)
  • Scope and testing window, as agreed in writing
  • Findings with severity, evidence and reproduction steps
  • Remediation retest, with the date it was confirmed
  • Dated attestation letter