Skip to content
HACKTECH

Offensive security

We find what's already open.

Israel-based offensive security team. Web, mobile, cloud and network penetration testing with prioritized, developer-ready fixes — plus an open library of tooling, protocol and training references.

OSCPCEHeJPT

Every surface you ship

  • Web application testing

    Authenticated, role-aware testing of your application and its API surface. We chain findings the way an attacker would rather than reporting isolated low-severity noise.

  • Mobile application testing

    iOS and Android assessment covering the binary, local storage, transport and the backend the app actually talks to — which is usually where the real findings are.

  • Cloud configuration review

    An IAM-first review of AWS, Azure or GCP. We map what an attacker reaches after compromising one workload or one developer laptop, then close the paths that matter.

  • Network & infrastructure

    Internal and external network testing, including Active Directory. Where scope allows we go from unauthenticated foothold to domain-wide impact and document the whole chain.

  • Red team & purple team

    Objective-based adversary simulation against your live detection and response. Purple mode runs the same scenarios collaboratively with your defenders in the room.

  • Secure development training

    Hands-on workshops for engineers, run against a deliberately vulnerable copy of a codebase like yours. Developers exploit the bug before they fix it, which is what makes it stick.

Findings that mattered

What we know, published

22 protocol field guides, 111+ vetted tools, learning tracks and incident checklists — free to every practitioner in the open library.