ЕN / FR

Offensive security

We provide cybersecurity services, specialising in penetration testing, a great preventive measure allowing you to be ahead of the hacker

Our ethical principles

  • Consent
  • Confidentiality
  • Accountability
  • Scope control
  • No harm
  • Transparency

We follow a strict «do no harm» approach, working only with explicit consent and within a clearly defined scope. Acting as white-hat professionals, we protect confidentiality, minimize operational impact, and use all findings solely to strengthen your security.

Every engagement is conducted with full accountability, honesty, and transparency — and your systems are left exactly as they were before testing.

Our services

Penetration testing (pentesting) is a security assessment where we simulate attacker’s actions to identify vulnerabilities in your system.

Web pentest

A penetration test of your websites designed to proactively identify and fix critical vulnerabilities before attackers can exploit them. The test uncovers web application flaws, misconfigurations, business logic abuse, and horizontal or vertical privilege escalation, helping you safeguard sensitive data, maintain compliance, and protect customer trust.

Internal Infrastructure Pentest

A technical evaluation of your internal network that simulates the impact of a threat actor with access to the corporate environment. The test focuses on what an attacker could do after gaining access, such as taking over a workstation, moving through the network, abusing internal services, and reaching critical systems. It identifies high-risk vulnerabilities and paths that allow attackers to escalate privileges.

Exposed Infrastructure Pentest

A focused assessment of your internet-facing infrastructure (Cloud, VPN, Email) to uncover vulnerabilities before attackers do. This test evaluates exposed applications, mail and file servers, VPN gateways, remote access services, and network devices, mapping potential attack surfaces and highlighting high-risk entry points.

Mobile Application Penetration Test

A full security audit of your mobile applications, examining the core application features, configurations, data handling, web services, and APIs. Static and dynamic testing uncover vulnerabilities that could be exploited, helping you secure sensitive user data and ensure reliable app performance.

Reconnaissance Audit and OSINT

A detailed audit of publicly available information about your company, including exposed documents, credentials, IPs, shadow IT, and databases. The collected data is analyzed to assess risks and potential attack vectors, helping you strengthen your security posture before threats emerge.

Pentest types

The types of pentests differ by scope, goals, and the level of access and information provided to the tester.

WHITE BOX

Access level: Full

Purpose: In-depth audit

In this scenario, we do not have to simulate an attacker’s actions, but instead work with the access provided by your company.

This approach allows for an in-depth assessment of code, configurations, and logic to uncover all possible vulnerabilities.

GREY BOX

Access level: Partial

Purpose: Insider modeling

The pentester has partial knowledge of the system, simulating an insider threat or a compromised user.

This approach identifies access control issues, lateral movement risks, and potential privilege escalation paths in a realistic scenario.

BLACK BOX

Access level: Zero

Purpose: Simulate an external attacker

Simulates a real-world external attacker with no prior knowledge of the system.

This test evaluates your defenses from an outsider’s perspective, uncovering visible vulnerabilities and attack paths that could be exploited from the internet.

About us

We are a team of certified and highly skilled cybersecurity experts with over 10 years of experience in penetration testing and offensive security.

Our specialists hold industry-leading certifications, including PNPT, OSCP, BSCP, Cisco Ethical Hacker, ISO 27001, and more, validating our expertise and commitment to excellence.

We deliver a fresh, critical perspective on modern cyber threats to help your businesses stay secure.