CeretrixCeretrixContact
Services

Focused engagements. Real findings.

Every engagement is run by an operator who's done the work — not handed off to a junior after kickoff. You get findings your team can prioritize, action, and close. Not a 200-page PDF that lives on a shared drive.

External & Internal Penetration Testing

Perimeter, internal estate, Active Directory, cloud, applications — wherever your attack surface lives. Manual exploitation, not just scanner output.

  • Operator-led, PTES- and OWASP-aligned
  • Real exploitation chains, not raw scanner dumps
  • Remediation steps written for the engineers fixing it

Web & API Application Testing

Modern web apps and APIs broken down to their assumptions — auth, authorization, business logic, supply chain, and the glue between services.

  • OWASP WSTG / API Top 10 coverage with real test cases
  • Authenticated, multi-role test plans — not just unauthed scans
  • Source-assisted review for the parts you actually care about

Red Team & Adversary Simulation

We pick an objective — domain admin, code signing key, the crown jewel — and test whether your detection and response would catch us getting there.

  • Scenarios mapped to ATT&CK and your real threat model
  • Full chain: initial access through objective completion
  • Purple-team debrief — your detections leave sharper than they came

Custom Security Tooling

If the tool you need doesn't exist, we build it. Internal platforms, automation, agents, integrations — designed around your stack, not someone else's roadmap.

  • From single-purpose CLIs to full self-hosted platforms
  • Integrates with what you already run (Jira, GitHub, SIEM, chat)
  • Open-source or proprietary — your call, your IP
How we work
01
Scope

NDA-first. We define objectives, boundaries, and rules of engagement before anything else.

02
Execute

Operator-led testing tracked in PentestCompanion — full timeline, evidence, chain of custody.

03
Report

Findings written for the engineers fixing them. Repro steps, evidence, severity, fix guidance.

04
Retest

Targeted retest of remediated findings included. Closure isn't optional.

Not sure what you need? We'll help scope it.

Start a conversation →