We assess applications, systems and people from an attacker's perspective. Every test begins with explicit authorisation and focuses on confirming real risks without creating unnecessary impact.
SaaS and digital productsEcommerce and customer portalsCompanies preparing a launchOrganisations that need to validate their exposure
Services
What we do within Red Team.
Every service is adapted to the asset, the required depth and the decision you need to make. The details below explain what each service covers before scope is agreed.
01
Red Team
Web application assessment and pentesting
We assess web applications to detect and validate vulnerabilities in authentication, sessions, permissions, input handling and business logic. OWASP provides a reference point, while testing is adapted to how the application actually works.
When it fits
Public or private applications, customer portals, ecommerce platforms and products approaching production or following significant changes.
What it includes
Public attack surface, authentication and session management
Roles, permissions and access controls
Input handling, business logic and sensitive workflows
Configuration, headers and information exposure
Automated analysis combined with manual validation
What the client receives
Confirmed findings with reproducible evidence
Technical and business impact
Prioritised remediation guidance
02
Red Team
CMS assessment and pentesting
A CMS (Content Management System) is software used to manage a website without developing every piece of content from scratch. We assess platforms such as WordPress, PrestaShop and Joomla, as well as other content management systems, together with their extensions, templates, users and configuration.
When it fits
Corporate websites, online stores and portals managed through a CMS, especially when they use many extensions, integrations or administrator accounts.
What it includes
CMS core, extensions, modules and templates
Users, roles, administrative access and sessions
Configuration, sensitive files and exposed backups
Account, order and ecommerce workflows where present
Relationship between the CMS, hosting and public components
What the client receives
Inventory of relevant components and exposure
Confirmed risks separated from version-only warnings
Recommendations for the CMS, its components and hosting
03
Red Team
API pentesting
We analyse REST and GraphQL APIs to determine how they identify users, enforce permissions, protect data and execute sensitive operations. The assessment covers complete workflows, not only isolated endpoints.
When it fits
Web or mobile backends, B2B integrations, SaaS products and architectures with multiple roles, organisations or tenants.
What it includes
Endpoint inventory and behaviour
Authentication, tokens and sessions
Object-, function- and property-level authorisation
Input validation, limits and data exposure
Business logic and operation sequences
What the client receives
Assessed surface and reproducible requests
Impact by affected role, data and operation
Remediation plan for the development team
04
Red Team
Source code analysis and SAST
We review source code to identify vulnerabilities, insecure patterns and implementation errors before they reach production or to investigate an existing assessment in greater depth.
When it fits
Development teams that need to review a repository, a critical component or a defined part of an application before deployment.
What it includes
Manual analysis of sensitive components and workflows
SAST tools used to support coverage
Finding validation and false-positive reduction
Secrets, dependencies and configuration when in scope
Recommendations adapted to the language and architecture
What the client receives
Findings located and explained in the code
Secure remediation examples where useful
Prioritisation to plan remediation
05
Red Team
Ethical phishing campaigns
We run controlled phishing simulations to measure the organisation's response, identify opportunities for improvement and guide awareness activity without unnecessarily exposing individuals.
When it fits
Organisations that want to assess processes and habits around fraudulent email using previously authorised objectives, participants and communications.
What it includes
Authorised scenario and message design
Controlled delivery and safety criteria
Open, interaction and reporting metrics
Data protection and minimisation of personal information
Follow-up guidance for affected groups
What the client receives
Aggregated results and behavioural analysis
Identified process and communication risks
Training and improvement recommendations
06
Red Team
Advanced pentesting
We perform in-depth penetration testing across systems, networks and applications to identify attack paths that may combine external exposure, privilege escalation and lateral movement.
When it fits
Environments with multiple assets, internal networks, cloud infrastructure or validation needs broader than an assessment of a single application.
What it includes
Internal, external or cloud surface defined in scope
Controlled exploitation of vulnerabilities
Authorised privilege escalation and lateral movement
Attack-path and existing-control analysis
Immediate communication of critical risks
What the client receives
Documented attack chain with evidence
Impact on critical assets and processes
Phased remediation plan
Before
Scope and authorisation
Included assets, accounts and environments
Objective and depth of the work
Testing windows, contacts and stop criteria
Handling of information and evidence
Delivery
What the client receives
Written scope, authorisation, rules and exclusions
Executive summary and technical report
Reproducible evidence and contextual severity
Actionable recommendations and delivery meeting
Follow-up validation when included in the proposal
Limits
What remains out of scope
Denial-of-service and destructive testing unless specifically authorised
Third-party assets without authorisation
Production changes without explicit approval
Expanding scope after a finding without client validation
First step
Tell us what you need to protect.
You do not need to select a service in advance. We will review the context and define the smallest engagement that can answer your need.