OFFENSIVE SECURITY
Audits with real-world exploitation: the attacker’s route, documented step by step
We do not deliver scanner alerts. Every finding is exploited manually to prove its impact, with a proof of concept, CVSS scoring and remediation.
SERVICES
Three complementary services
- Web
- REST API
- GraphQL
- Infrastructure
- Mobile
- Working PoC
- CVSS
- Attack surface
- CVE
- Leaked credentials
- Cybercrime forums
- Phishing
- Telegram
- Providers
- 24/7
- Kerberos
- GPO
- PrivEsc
- Trusts
- Lateral movement
- EDR evasion
METHODOLOGY
Audit phases
Five phases, each with a closed deliverable, and a single point of contact from start to finish. Testing follows the OWASP WSTG cases and the PTES phases. Techniques are mapped to MITRE ATT&CK and the testing approach to NIST SP 800-115.
- Assets included and assets excluded
- Rules of engagement in writing
- Execution window, notification channel and NDA
RESEARCH
Published technical analyses
Technical analyses of real findings, anonymised and published after remediation.
Cache poisoning through a header left out of the cache key
Read the analysis Reflected headerPoisoned cache entryServed to other visitors9.1CriticalSecond factor skipped: the session was issued before the code was checked
Read the analysis Cookie at the first stepCode screen discardedFull account access8.6HighAdministration panel reached by rewriting a 403 in the response
Read the analysis Data in the error bodyStatus rewritten to 200Invoices from other companies9.8CriticalBlind SQL injection in an HTTP header leading to command execution
Read the analysis Non-standard headerDB administrator privilegesSystem stored proceduresTEAM AND COMPANY
Business and engineering, at the same table
Miguel OvejeroCO-FOUNDER · CEOA single point of contact throughout the engagement. From the first conversation to final delivery, he stays with the client and keeps the project moving to plan. LinkedIn
Miguel ArrabalCO-FOUNDER · CTOResponsible for the technical direction and execution of the audit, for the rigour of the testing and for the quality of every deliverable. LinkedInFrequently asked questions
Can the audit affect service availability?
No. Exploitation is manual and stops before any damage is caused: the vulnerability is proven without affecting the service. Destructive testing is excluded unless authorised in writing and run in a prepared environment.
What happens if a critical finding appears during the audit?
Critical findings are reported immediately through the channel agreed in the rules of engagement, together with the minimum containment steps to reduce the risk. Notification does not wait for the final report.
Is the report valid for ENS or ISO 27001?
We prepare the report with the technical evidence these audits usually ask for: CVSS scoring, reproduction steps, evidence, remediation and a separate executive summary. The report can be submitted as evidence of the security testing carried out, although final acceptance rests with your auditor.
Do you sign an NDA?
Yes. We sign it before you send us any data and we can work from your own template. The report goes only to the recipients you name, and the NDA covers evidence storage, retention and destruction. Any analysis we publish is anonymised and needs your prior approval.
CONTACT
Request a proposal with the scope defined
Tell us which assets you want tested. We reply within 24 hours.







