Penetration Testing

Our specialist offensive testing services include an extensive range of penetration testing capabilities at the application, network, and physical level.

  • Security Research as a Service
  • Red Teaming and Attacker Emulation
  • Web Application and API
  • External, Internal, and Wireless Networks
  • Host and SOE
  • Cloud Environments
  • Mobile Applications
  • Bespoke Systems and Applications

Security Review

Complementing our Penetration Testing we also perform network architecture and application review services. Helping your business achieve best practice design and secure-by-default approaches to your infrastructure.

  • Network Architecture Review
  • Application Architecture Review
  • Source Code Review
  • DevOps Review
  • General Security Consultancy

Incident Response

For when things go wrong, our experienced and qualified team will help with getting you back on track.

  • Incident Response Preparedness
  • Incident Management and Leadership
  • Forensic Investigations (GIAC Certified Forensic Analysts)
  • Malware Analysis

Featured Releases

After the Report is Delivered: Remediation and Confirmation Testing

You’ve received a penetration test or security review report. The summaries are read, the report read-out meeting has happened, and now the hard part begins! This article discusses what to do after you receive your report. We’ll talk about the process from reproducing findings and implementing fixes, through to engaging confirmation testing efficiently. Getting familiar with this process can have some sweet additional benefits, like implicit security upskilling!


An HTTP Intercepting Proxy with Chrome DevTools Protocol (CDP)

Intercepting proxies are something web application penetration testers, performance engineers and developers are likely fairly familiar with. Ever notice how a bunch of that functionality already exists in the browser’s DevTools, though? This article is going to show you how to implement an intercepting proxy by connecting to the browser over CDP (Chrome DevTools Protocol), eliminating the need for HTTP CONNECT, CA certificates, and TLS interception altogether.


What Makes a Quality Penetration Test

This article discusses what you can expect at each stage of a high quality security review, with the aim of helping folks understand what to look for when engaging penetration testers.

Get in touch

How can we help?

+64 4 889 4756