What we test, and what you get back
Six disciplines, from full-scope red team operations to adversarial testing of AI systems. Each one is scoped in writing before it starts and lands as evidence your team can reproduce.
Red team operations
Full-scope, objective-driven red team engagement modelled on a named threat actor. Scoped in writing, evidenced end to end, reproducible by your team.
- Threat actor modeled to your sector and exposure
- Full kill chain: recon through objective
- Memory-only execution where tradecraft permits
Penetration testing
Cloud, infrastructure, and application penetration testing. Every finding ships with a working proof of concept, blast radius, and a fix path.
- Cloud (AWS · Azure · GCP), infra, and application in scope
- CVSS-scored findings with working PoC
- Chained vulnerabilities documented to max blast radius
Malware development
Bespoke implants and loaders built and tested against your EDR stack, documented in full, held in escrow, and burned on engagement completion.
- Built and tested against your target EDR stack
- Mapped to named threat actor TTPs
- Source held in secure escrow throughout engagement
Detection engineering
Purple-team detection engineering: every technique replayed with full telemetry, then shipped as a tested Sigma, KQL, or YARA rule with a runbook.
- Shoulder-to-shoulder with your blue team and SIEM engineers
- Detection-first replay — every event observable before rule authoring
- Sigma, KQL, YARA output in your stack's native format
Cloud security
AWS, Azure, and GCP attack-path testing. IAM privilege graphs walked end to end, with a policy diff you can apply for every finding.
- Full IAM privilege graph enumeration and attack-path modeling
- Cross-account and cross-service lateral movement chains
- External exposure: public APIs, storage buckets, snapshot sharing
AI security
Adversarial testing for LLM, agent, and RAG systems: prompt injection, tool abuse, data exposure, and a regression eval suite that proves the fix.
- Direct and indirect prompt injection through retrieved and user content
- Agent and tool-use abuse: confused deputy, over-scoped tokens, unbounded actions
- RAG data exposure: cross-tenant retrieval, embedding leakage, index poisoning
// next step
Start with the objective, not the discipline.
Scoping call first — we map the objective, then propose the work that tests it.