Offensive security
Audit & offensive security
We assess your security posture using the same techniques as real attackers. Our deliverables are immediately actionable by your teams, not a CVE catalogue sorted by automated score.
Assessment scopes
Identification and qualification of vulnerabilities on a defined scope. Each vulnerability is manually verified, ranked by business criticality and cross-referenced with your infrastructure context. No raw scanner output is delivered without analysis.
Simulation of an external or internal attacker depending on the agreed scope: passive and active reconnaissance, exploitation of exposures, privilege escalation, lateral movement, access to sensitive data. Black box, grey box or white box scenarios depending on your objectives.
Assessment of web applications and exposed programming interfaces. Coverage of logic flaws, access control vulnerabilities, injection and authentication weaknesses. Business flow taken into account, not just technical parameters.
Review of cloud environment configuration and segmentation. Identification of authorisation errors, exposed resources and escalation paths linked to identity and access management policies.
Advanced multi-vector attack simulation over a defined period. The red team operates without the internal security teams being informed of the specifics. The objective is to evaluate actual detection and response capabilities, not resistance to a known scenario.
Targeted phishing campaigns, phone impersonation, unauthorised physical access attempts. Tests are conducted within a contractually defined and pre-documented scope.
Manual review of operating system, network service, equipment and application configurations. Verification of hardening against established benchmarks. Identification of deviations and unjustified exceptions.
Analysis of segmentation, filtering and defence-in-depth choices. Identification of implicit security assumptions and excessive trust zones. Recommendations on reducing the attack surface.
Methodology
Contractual definition of scope, objectives, rules of engagement and test windows. Designation of client-side points of contact for emergency situations.
Information gathering about the scope without direct interaction with target systems. Analysis of unintentional exposures.
Active testing across defined vectors. Each identified vulnerability is verified and its exploitability confirmed before being documented.
Executive summary (one to two pages, no technical jargon), detailed technical report with proof of concept, remediation table prioritised by criticality and estimated effort.
Debrief session with technical teams and, if requested, a separate session for management. Questions on prioritisation and remediation approach are answered.
Deliverables
Executive summary
One to two pages. Overall risk, key vulnerabilities and potential impact. Written for management with no technical prerequisites.
Technical report
Detailed description of each vulnerability, reproducible proof of concept, CVE or CWE reference where applicable, realistic exploitation scenario.
Remediation table
Each finding ranked by criticality and estimated remediation effort. Enables informed prioritisation between competing priorities and available resources.
Post-audit support
Available on request: verification that identified vulnerabilities have been correctly remediated after your teams complete their fixes.