Stop guessing.
Find out what an
attacker would do.
For organisations that already run a security function and need something harder than a questionnaire: adversary simulation, deep penetration testing and full red team operations. Scoped around your environment, quoted per engagement, never sold as a package.
What we can put
under attack
Each of these can be a standalone engagement or one thread in a broader operation. Where they overlap in your environment, we say so during scoping rather than selling you two of them.
Web applications and APIs
Manual, logic-first testing beyond the scanner: authentication and session handling, access control between tenants and roles, injection chains, and the business logic nobody thought to abuse.
Internal network and Active Directory
From a standard user account to domain compromise: credential exposure, delegation and certificate abuse, lateral movement paths, and the trust relationships between your domains.
Cloud and identity
AWS, Azure, GCP, Microsoft 365 and Entra ID: privilege escalation paths, conditional access gaps, token and consent abuse, exposed storage, and the identities that quietly bridge tenants.
External attack surface
Everything you expose without meaning to: forgotten hosts and subdomains, edge devices and VPNs, third-party portals in your name, and credentials already circulating in breach data.
Social engineering
Targeted phishing built on real reconnaissance, pretext calls, and payload delivery against your actual controls — measured, evidenced, and agreed in advance with your leadership.
Physical intrusion
Access to buildings, floors and comms rooms: tailgating, badge cloning, reception pretexting, and what an intruder can reach once a laptop is plugged into your network.
Mobile and thick clients
iOS and Android applications and desktop clients: static and runtime analysis, local data storage, certificate pinning, and the backend APIs behind them.
Source code and build pipeline
Code review of the parts that matter — authentication, authorisation, cryptography, deserialisation — plus your CI/CD pipeline, secrets handling and dependency supply chain.
Purple team and detection
Run known techniques against your SOC, side by side with your defenders, and measure what was logged, what alerted and what nobody saw. Tuning included, not just a scorecard.
A test has a scope.
An operation has
an objective.
A penetration test answers "what is broken here". A red team operation answers a harder question: can a capable, patient adversary reach the thing that would actually hurt us — and would anyone notice? We agree the objective with your leadership, then work towards it the way a real intrusion set would, across whichever paths are in scope.
Threat-led testing under DORA
If you are a financial entity, your supervisor may expect threat-led penetration testing on top of ordinary testing. We are happy to explain what that framework involves, how it differs from what we do, and where an operation like ours fits alongside it — including telling you when you need an accredited provider rather than us.
- Objective-led. Agreed in advance and written down: reach the payment system, obtain a copy of the client database, gain persistent access to the trading floor.
- Threat-informed. We model the groups that plausibly target your sector and reuse their tradecraft, rather than running whatever is quickest.
- Full spectrum. External, social, physical and internal paths in one operation, because that is how real intrusions actually chain together.
- Quiet by default. Detection is part of the result. Your SOC is not told, unless the scenario calls for it.
- Controlled. A named control group on your side, a deconfliction line open throughout, and hard stops written into the rules of engagement.
- Replayable. Every step timestamped, so afterwards you can walk the whole chain with your defenders and fix the detection gaps.
Five phases, no surprises
Everything is written down before anything is touched. You always know who is testing, what is in scope, and how to reach us if something breaks.
Scope and authorisation
Targets, objectives, exclusions, testing window and escalation contacts — signed by someone entitled to authorise it.
Reconnaissance
Mapping what exists and what is reachable, from public sources and from inside the agreed perimeter.
Exploitation
Controlled exploitation and privilege escalation, chained as far as the scope permits. Critical findings are reported the same day.
Reporting
Written up in full within five working days of the test window closing, then walked through with your team.
Retest
Once you have remediated, we verify the fixes and reissue the report. Included in the price, not billed again.
Written for two audiences at once
An executive summary your board and your insurer can read, and a technical section your engineers can act on without a translation layer. Both in the same document, clearly separated.
Evidence for every claim
Each finding carries the request, the response, the screenshot or the command output that proves it — with severity ratings and reproduction steps, so nobody has to take our word for it.
The attack narrative
A chronological account of how the chain was built, step by step. This is usually the part that changes minds internally — and the part most reports leave out.
Fixes in priority order
Not a list of 80 items sorted by CVSS, but what to do first, what can wait, and which single change would break the most attack paths at once.
Methodologies we work to
No packages. No day rate
pulled out of the air.
Every engagement is priced on its own
Two companies of the same size can differ by a factor of five in the work involved. So we scope first: a call, a short questionnaire, and if useful a look at your architecture under NDA. You get a written scope, rules of engagement and a fixed quote before anything is booked. What drives that quote:
- Number and complexity of applications, roles and integrations
- Size of the internal estate and number of domains
- Cloud tenants and identity providers in scope
- Whether social engineering or physical access is included
- Objective-led operation or bounded technical test
- Testing window, out-of-hours work, and on-site days
- Whether your detection team is informed or blind
- Reporting language and any regulator-specific format
Scoping costs you nothing and puts you under no obligation. If your budget and the work do not meet, we will say so on the first call.
Start with a scoping callTell us what you
want tested
A sentence or two is enough to start. If you would rather not describe your environment in an email, say so and we will set up a call under NDA first.
L-4367 Belvaux, Luxembourg