AxonSentry — compliance for Luxembourg SMEs
Offensive security

Stop guessing.
Find out what an
attacker would do.

For organisations that already run a security function and need something harder than a questionnaire: adversary simulation, deep penetration testing and full red team operations. Scoped around your environment, quoted per engagement, never sold as a package.

Capabilities

What we can put
under attack

Each of these can be a standalone engagement or one thread in a broader operation. Where they overlap in your environment, we say so during scoping rather than selling you two of them.

01

Web applications and APIs

Manual, logic-first testing beyond the scanner: authentication and session handling, access control between tenants and roles, injection chains, and the business logic nobody thought to abuse.

02

Internal network and Active Directory

From a standard user account to domain compromise: credential exposure, delegation and certificate abuse, lateral movement paths, and the trust relationships between your domains.

03

Cloud and identity

AWS, Azure, GCP, Microsoft 365 and Entra ID: privilege escalation paths, conditional access gaps, token and consent abuse, exposed storage, and the identities that quietly bridge tenants.

04

External attack surface

Everything you expose without meaning to: forgotten hosts and subdomains, edge devices and VPNs, third-party portals in your name, and credentials already circulating in breach data.

05

Social engineering

Targeted phishing built on real reconnaissance, pretext calls, and payload delivery against your actual controls — measured, evidenced, and agreed in advance with your leadership.

06

Physical intrusion

Access to buildings, floors and comms rooms: tailgating, badge cloning, reception pretexting, and what an intruder can reach once a laptop is plugged into your network.

07

Mobile and thick clients

iOS and Android applications and desktop clients: static and runtime analysis, local data storage, certificate pinning, and the backend APIs behind them.

08

Source code and build pipeline

Code review of the parts that matter — authentication, authorisation, cryptography, deserialisation — plus your CI/CD pipeline, secrets handling and dependency supply chain.

09

Purple team and detection

Run known techniques against your SOC, side by side with your defenders, and measure what was logged, what alerted and what nobody saw. Tuning included, not just a scorecard.

Red team operations

A test has a scope.
An operation has
an objective.

A penetration test answers "what is broken here". A red team operation answers a harder question: can a capable, patient adversary reach the thing that would actually hurt us — and would anyone notice? We agree the objective with your leadership, then work towards it the way a real intrusion set would, across whichever paths are in scope.

Threat-led testing under DORA

If you are a financial entity, your supervisor may expect threat-led penetration testing on top of ordinary testing. We are happy to explain what that framework involves, how it differs from what we do, and where an operation like ours fits alongside it — including telling you when you need an accredited provider rather than us.

  • Objective-led. Agreed in advance and written down: reach the payment system, obtain a copy of the client database, gain persistent access to the trading floor.
  • Threat-informed. We model the groups that plausibly target your sector and reuse their tradecraft, rather than running whatever is quickest.
  • Full spectrum. External, social, physical and internal paths in one operation, because that is how real intrusions actually chain together.
  • Quiet by default. Detection is part of the result. Your SOC is not told, unless the scenario calls for it.
  • Controlled. A named control group on your side, a deconfliction line open throughout, and hard stops written into the rules of engagement.
  • Replayable. Every step timestamped, so afterwards you can walk the whole chain with your defenders and fix the detection gaps.
How an engagement runs

Five phases, no surprises

Everything is written down before anything is touched. You always know who is testing, what is in scope, and how to reach us if something breaks.

PHASE 01

Scope and authorisation

Targets, objectives, exclusions, testing window and escalation contacts — signed by someone entitled to authorise it.

PHASE 02

Reconnaissance

Mapping what exists and what is reachable, from public sources and from inside the agreed perimeter.

PHASE 03

Exploitation

Controlled exploitation and privilege escalation, chained as far as the scope permits. Critical findings are reported the same day.

PHASE 04

Reporting

Written up in full within five working days of the test window closing, then walked through with your team.

PHASE 05

Retest

Once you have remediated, we verify the fixes and reissue the report. Included in the price, not billed again.

Written for two audiences at once

An executive summary your board and your insurer can read, and a technical section your engineers can act on without a translation layer. Both in the same document, clearly separated.

Evidence for every claim

Each finding carries the request, the response, the screenshot or the command output that proves it — with severity ratings and reproduction steps, so nobody has to take our word for it.

The attack narrative

A chronological account of how the chain was built, step by step. This is usually the part that changes minds internally — and the part most reports leave out.

Fixes in priority order

Not a list of 80 items sorted by CVSS, but what to do first, what can wait, and which single change would break the most attack paths at once.

Methodologies we work to

OWASP WSTGOWASP ASVSMITRE ATT&CKPTES NIST SP 800-115OWASP MASVSCIS Benchmarks
Scope and quote

No packages. No day rate
pulled out of the air.

Every engagement is priced on its own

Two companies of the same size can differ by a factor of five in the work involved. So we scope first: a call, a short questionnaire, and if useful a look at your architecture under NDA. You get a written scope, rules of engagement and a fixed quote before anything is booked. What drives that quote:

  • Number and complexity of applications, roles and integrations
  • Size of the internal estate and number of domains
  • Cloud tenants and identity providers in scope
  • Whether social engineering or physical access is included
  • Objective-led operation or bounded technical test
  • Testing window, out-of-hours work, and on-site days
  • Whether your detection team is informed or blind
  • Reporting language and any regulator-specific format

Scoping costs you nothing and puts you under no obligation. If your budget and the work do not meet, we will say so on the first call.

Start with a scoping call
Contact

Tell us what you
want tested

A sentence or two is enough to start. If you would rather not describe your environment in an email, say so and we will set up a call under NDA first.

Encrypted
pgp@axonsentry.com — PGP key on request
Office
7 avenue du Swing
L-4367 Belvaux, Luxembourg
Before we test anything
Signed authorisation, agreed scope, and a named contact on your side

Treated as confidential. We are happy to sign your NDA before any technical discussion.