We model the
adversary
your tooling
is built to miss.
Full-scope red teaming, penetration testing, and malware development. Scoped, evidenced, and reproducible. Every finding ships with a working proof-of-concept and the exact path to close it.
Six disciplines. One objective: find it before they do.
Red team operations
Full-scope, objective-driven intrusion modeled on a named threat actor — not a checklist. We earn the foothold, then prove what it's worth.
- Threat-model scoping
- Assumed-breach & full-scope
- Detection-evasion tradecraft
Penetration testing
Cloud, infrastructure, and application testing. Every finding ships with a working PoC and blast radius.
Engagement detailMalware development
Bespoke implants and loaders for realistic emulation — built, documented, and burned on completion.
Engagement detailDetection engineering
We sit shoulder-to-shoulder with your blue team and turn every finding into a durable, tested detection.
Engagement detailCloud security
AWS, Azure, and GCP attack paths — identity, misconfiguration, and the privilege chain that ends in your data.
Engagement detailAI security
Adversarial testing for LLM and ML systems — prompt injection, tool and agent abuse, training-data and model-supply-chain exposure. We attack the model, its context, and everything it is allowed to touch.
- Prompt injection & jailbreak chains
- Agent / tool-use abuse
- RAG & data-exfil paths
- Model supply-chain review
A repeatable operation, not a one-off scan.
Five phases, one standard of proof. The shape of the work never changes — frame it, get hands on the system, evidence what we find, hand over the fix, then verify it died. Only the second phase changes with the discipline.
Aligned to
- MITRE ATT&CK
- PTES
- TIBER-EU
- TLPT
- DORA
Frame
Week 0Objectives, boundaries, and rules of engagement — agreed and signed before a single packet moves. We pick the named threat actor your regulators actually worry about.
[ artifact ] Signed ROE · named threat actor · crown-jewel asset map
Emulate
Weeks 1–3We operate like the actor in your threat model: patient, quiet, and creative. Custom tooling where off-the-shelf trips EDR. Tradecraft, not noise.
[ artifact ] Campaign log — every action timestamped, deconflicted, attributable
Evidence
Weeks 3–4Every step is logged as we go. Findings arrive with reproducible PoC, blast radius, and screenshots — not a CVSS sticker.
[ artifact ] Ranked findings · working PoC per finding · critical-path graph
Hand-off
Week 4We hand the blue team the exact fix and the detection rule that would have caught us — mapped to MITRE ATT&CK, ready to deploy.
[ artifact ] Fix path + tested detection per finding
Verify
Week 6A working session with your engineers: reproduce, close, verify. We re-run the attack path until it dies.
[ artifact ] Re-test report · closed-path confirmation
One operator. No bench, no handoff.
The person who scopes your engagement is the person who runs it and writes the report. No account manager in between, no junior on the keyboard, no findings you cannot get an answer about.
- 100+ engagements delivered
- MITRE ATT&CK · PTES · TIBER-EU · TLPT · DORA
- Coordinated disclosure, every time
// Operator certifications
Certified across three disciplines
The credentials behind the work. Select a badge to inspect it.
Pablo RuizFounder · Lead operatorOffensive security since 2018 — Madrid, Oslo, Amsterdam. Runs the intrusion, then writes the report you can act on.

Offensive security since 2018, across Spain, Norway, and the Netherlands.
The certification path is deliberate rather than decorative: OSCP first, then the full OSCE³ chain — OSEP for evasion, OSWE for the web layer, OSED for exploit development — with GPEN and GCIH covering the defensive side, CRTO for red-team operations, and AWS Security Specialty for the cloud work.
Read for his degree at Universidad de León part-time while working full-time, finishing with first-class honours.
The practice operates from the Netherlands and works remotely, worldwide.
Spanish · English · Norwegian
11 held across offensive, defensive and cloud disciplines
Trusted where the blast radius is real
- Railway
- Public sector
- Financial
- Entertainment
- Critical infrastructure
Schedule a scoping call.
Tell us what keeps you up. We come back with a threat model, a proposed scope, and a price — inside 48 hours.
- Aligned to TIBER-EU · TLPT · DORA
- Mutual NDA before scoping
- 48h response





