Skip to content

Pillar 01

Offensive Security.

We find what scanners miss. Reports engineers can act on immediately. No checklists, no theatre.

Services

01
OWASPGraphQLSession

Web Application Pentest

Authentication, authorization, and business logic. We probe flows scanners miss: GraphQL alias abuse and introspection smuggling, alias-based rate-limit bypass, session rotation gaps, cross-tenant IDOR, CORS configuration drift.

Deliverable

Executive summary plus detailed finding report with CVSS 3.1, proof of concept per finding, remediation guidance, re-test after fix.

02
Fridamitmproxysmali

Mobile App Pentest (iOS + Android)

Static and dynamic. TLS-pinning bypass (Frida plus Cronet-layer disable), exported-component audit for activities, services, and broadcast receivers, deep-link hijack, APK patching for network-security-config and license verifiers, verified-boot context validation.

Deliverable

Finding bundle with PoC APK or Frida scripts, screenshot and video evidence, root-cause analysis in smali context.

03
RESTGraphQLEnum Oracles

API Security Review

REST and GraphQL. Rate-limit bypass via alias batching, IDOR classes, enumeration oracles via differential error responses, auth-flow audit (JWT alg confusion, audience mismatch, refresh rotation), webhook signature validation.

Deliverable

List of actionable oracle instances, repro scripts, recommended server-side mitigations.

04
IAMSSRF→SACloud SQL

Cloud Security Audit (GCP · AWS · Azure)

IAM and service-account review, metadata-SSRF chains via proxy and webhook deployments, exposed Cloud SQL instances (`authorizedNetworks: []`), Secrets-Manager access paths, BigQuery dataset permissions, Cloud Storage bucket inventory. Concrete: a real 2026 engagement produced an SSRF → GCP SA token → 19 GCS buckets, 71 Secret-Manager secrets, 5 Cloud SQL instances.

Deliverable

Full cloud inventory, finding chain with exploit steps, IAM remediation plan to least-privilege, re-test after hardening.

05
Prompt InjectionRAG LeakGuardrails

AI System Security Assessment

Prompt injection via tool use and RAG context, jailbreak resistance against current public research, data leakage through embedding similarity, guardrail validation, sandbox escape at the tool layer, supply-chain risks in model serving.

Deliverable

Attack taxonomy for your system, reproducible exploits, guardrail and eval recommendations with examples.

06
Rogue APPhishingPhysical

Red Team & Security Awareness

Targeted attack simulation that tests the human factor, not just the tech. Fake-WiFi / rogue AP with captive portals for in-office credential capture. Spearphishing campaigns with landing pages and realistic pretexts. Vishing via spoofed caller ID, USB drops in reception areas, physical pretext for tailgating. All with clean documentation, measurable KPIs (click rate, credential-submit rate, report rate), and zero disruption to production processes.

Deliverable

Execution plan with opt-in list, executive summary with KPIs, awareness-training module built from real findings, optional repeat engagements to track trends.

Methodology

How an engagement runs

  1. 01

    Scoping

    Assets, boundaries, testing window, communication channel, emergency protocol.

  2. 02

    Recon

    Public and authorized internal mapping, attack-surface catalog.

  3. 03

    Exploitation

    Manual exploits with clean documentation of every attempt.

  4. 04

    Reporting

    Technical report plus executive summary plus Slack/email daily updates.

  5. 05

    Remediation support

    Re-test after fix, code-review assistance, secure-by-default consulting.

Ready for a real assessment?

Short scoping call, clear proposal, kick-off in two to four weeks.

Start the conversation

Newsletter

Substance over noise

One email every two weeks with a new blog post or a technical deep dive. No clickbait.