Skip to content

OFFENSIVE SECURITY

Audits with real-world exploitation: the attacker’s route, documented step by step

We do not deliver scanner alerts. Every finding is exploited manually to prove its impact, with a proof of concept, CVSS scoring and remediation.

Request an audit

Team certifications and the platforms where we report

OSCP · OffSecOSCP+ · OffSeceJPT · INE SecurityeWPT · INE SecurityeWPTX · INE SecurityCRTO · Zero-Point SecurityCRTL · Zero-Point SecurityBSCP · PortSwiggerCISM · ISACAHackerOneBugcrowdYesWeHack

Individual credentials, verifiable on request.

METHODOLOGY

Audit phases

Five phases, each with a closed deliverable, and a single point of contact from start to finish. Testing follows the OWASP WSTG cases and the PTES phases. Techniques are mapped to MITRE ATT&CK and the testing approach to NIST SP 800-115.

See the full methodology
PHASE 01Scope statement and rules of engagement
  • Assets included and assets excluded
  • Rules of engagement in writing
  • Execution window, notification channel and NDA

Frequently asked questions

Can the audit affect service availability?

No. Exploitation is manual and stops before any damage is caused: the vulnerability is proven without affecting the service. Destructive testing is excluded unless authorised in writing and run in a prepared environment.

What happens if a critical finding appears during the audit?

Critical findings are reported immediately through the channel agreed in the rules of engagement, together with the minimum containment steps to reduce the risk. Notification does not wait for the final report.

Is the report valid for ENS or ISO 27001?

We prepare the report with the technical evidence these audits usually ask for: CVSS scoring, reproduction steps, evidence, remediation and a separate executive summary. The report can be submitted as evidence of the security testing carried out, although final acceptance rests with your auditor.

Do you sign an NDA?

Yes. We sign it before you send us any data and we can work from your own template. The report goes only to the recipients you name, and the NDA covers evidence storage, retention and destruction. Any analysis we publish is anonymised and needs your prior approval.

CONTACT

Request a proposal with the scope defined

Tell us which assets you want tested. We reply within 24 hours.

Request an auditCall