Skip to content
HACKTECH

Services

Every surface you ship, tested the way it will be attacked.

Six disciplines, one method: manual, chained, adversarial testing with findings your engineers can reproduce and fix. Fixed quotes, daily updates, and a free retest of every fixed finding within 30 days.

OSCPCEHeJPT~10-day typical turnaround

Web application testing

Authenticated, role-aware testing of your application and its API surface. We chain findings the way an attacker would rather than reporting isolated low-severity noise.

Best for: SaaS products preparing for enterprise procurement, a funding round, or a first external assessment.

Duration: 5–10 working days

Standards: OWASP ASVS 4.0 · OWASP Testing Guide v4 · OWASP API Top 10

You receive

  • Executive summary written for non-engineers
  • Per-finding reproduction steps with request/response captures
  • Severity scored with CVSS 4.0 plus business-context adjustment
  • Developer-ready remediation guidance, not generic OWASP links
  • Free retest of every fixed finding within 30 days

Representative coverage

  • Broken access control and multi-tenant isolation (IDOR, horizontal and vertical escalation)
  • Authentication, session handling, password reset and MFA bypass paths
  • Injection: SQL, NoSQL, command, template and deserialization
  • SSRF, XXE and file-upload handling
  • Business-logic abuse: pricing, quotas, workflow state and race conditions
  • Client-side: DOM XSS, prototype pollution, CSP and postMessage handling

Mobile application testing

iOS and Android assessment covering the binary, local storage, transport and the backend the app actually talks to — which is usually where the real findings are.

Best for: Consumer or fintech apps handling payments, health data or identity documents.

Duration: 6–10 working days

Standards: OWASP MASVS · OWASP MASTG

You receive

  • Static and dynamic analysis findings with annotated evidence
  • Runtime instrumentation notes (Frida scripts where relevant)
  • Backend API findings folded into the same report
  • Platform-specific hardening checklist
  • Free retest of every fixed finding within 30 days

Representative coverage

  • Insecure local storage: keychain, keystore, shared preferences, SQLite
  • Certificate pinning implementation and bypass resistance
  • Root/jailbreak detection and anti-tamper effectiveness
  • Hardcoded secrets, API keys and endpoint discovery in the binary
  • Deep-link and inter-process communication handling
  • Backend authorization from a mobile client's perspective

Cloud configuration review

An IAM-first review of AWS, Azure or GCP. We map what an attacker reaches after compromising one workload or one developer laptop, then close the paths that matter.

Best for: Teams that grew their cloud footprint faster than their permissions model.

Duration: 4–8 working days

Standards: CIS Benchmarks · MITRE ATT&CK for Cloud

You receive

  • Privilege-escalation graph showing reachable paths to sensitive data
  • Prioritized misconfiguration inventory with blast-radius notes
  • Terraform or policy snippets for the fixes we recommend
  • Detection gaps: what your logging would have missed
  • Free retest of every fixed finding within 30 days

Representative coverage

  • IAM roles, trust policies, cross-account access and privilege escalation chains
  • Public exposure: buckets, snapshots, registries, managed databases
  • Secrets handling in CI/CD, environment variables and image layers
  • Network segmentation, security groups and egress control
  • Workload identity: instance metadata, service accounts, pod identity
  • Logging and detection coverage against common cloud attack paths

Network & infrastructure

Internal and external network testing, including Active Directory. Where scope allows we go from unauthenticated foothold to domain-wide impact and document the whole chain.

Best for: Organisations with on-premises infrastructure, hybrid AD, or an office network that has never been tested.

Duration: 5–12 working days

Standards: MITRE ATT&CK · PTES · NIST SP 800-115

You receive

  • Attack path narrative from initial access to maximum impact
  • Host-level findings with affected asset inventory
  • Active Directory hardening plan ranked by effort against risk
  • Detection opportunities mapped to MITRE ATT&CK techniques
  • Free retest of every fixed finding within 30 days

Representative coverage

  • External perimeter: exposed services, credential spraying, VPN and gateway flaws
  • Active Directory: Kerberoasting, AS-REP roasting, delegation abuse, ACL paths
  • Lateral movement, credential harvesting and privilege escalation
  • Segmentation validation between corporate, production and guest networks
  • Legacy protocol exposure: SMB signing, LLMNR/NBT-NS, NTLM relay
  • Patch and configuration drift across the estate

Red team & purple team

Objective-based adversary simulation against your live detection and response. Purple mode runs the same scenarios collaboratively with your defenders in the room.

Best for: Teams with an existing security function who need to know whether it actually works under pressure.

Duration: 3–6 weeks

Standards: MITRE ATT&CK · TIBER-EU informed

You receive

  • Objective outcome: what was reached, how, and how long it took
  • Full timeline correlated against your SIEM and alert history
  • Detection gap analysis mapped to ATT&CK techniques
  • Tuned detection rules for the gaps we exercised
  • Debrief workshop with the blue team

Representative coverage

  • Initial access simulation: phishing, exposed services, supply-chain paths
  • Command and control over realistic, defensible channels
  • Privilege escalation and lateral movement toward defined objectives
  • Data staging and exfiltration simulation against DLP controls
  • Alert-response timing: what fired, what was triaged, what was missed
  • Purple mode: live technique replay with defenders tuning in real time

Secure development training

Hands-on workshops for engineers, run against a deliberately vulnerable copy of a codebase like yours. Developers exploit the bug before they fix it, which is what makes it stick.

Best for: Engineering teams that keep reintroducing the same class of vulnerability.

Duration: 1–3 days on site or remote

Standards: OWASP ASVS · OWASP SAMM

You receive

  • Tailored curriculum built from findings in your own codebase
  • Live lab environment each participant keeps for 30 days
  • Recorded sessions and written exercises
  • Pre and post assessment showing measurable change
  • Secure-coding checklist adapted to your stack

Representative coverage

  • Exploiting and then fixing the OWASP Top 10 in your language and framework
  • Threat modelling a real feature from your backlog
  • Secure code review practice on real pull requests
  • Secrets management and dependency risk in your CI/CD
  • Incident triage tabletop for engineers on call

How an engagement runs

The same spine every time — so you always know what happens next and nothing in the report is a surprise.

  1. 45 minutes

    Scoping call

    We walk your architecture, agree what matters most, and identify what must stay off-limits. You leave the call with a fixed price and a start date — no discovery invoice, no open-ended estimate.

    Written scopeFixed quoteConfirmed dates

  2. 1–2 days

    Rules of engagement

    Signed authorisation, escalation contacts, testing windows and traffic identifiers. If a critical issue appears mid-test we page you immediately rather than saving it for the report.

    Signed RoEEscalation pathTest account provisioning

  3. Core of the engagement

    Testing

    Manual, chained testing with automation used only for coverage — never as the assessment itself. You get a short written update at the end of each day so nothing is a surprise.

    Daily written updatesImmediate critical escalation

  4. 2–3 days

    Reporting

    Two audiences, one document: an executive summary a board can read, and per-finding detail an engineer can act on without asking follow-up questions.

    Full reportExecutive summaryPrioritized fix backlog

  5. Included

    Remediation support

    A working session with your engineers to walk the findings, plus a shared channel for questions while the fixes are being built. Most disputes about severity get settled here, in front of the evidence.

    Walkthrough sessionShared support channel

  6. Within 30 days

    Retest

    We re-test every finding you have fixed and reissue the report with updated status. Included in the original price, so a clean letter for your customers costs nothing extra.

    Updated reportAttestation letter

Questions teams actually ask

How quickly can you start?

Scoping calls are usually available within two working days. Most engagements start within two weeks of a signed scope, and we hold emergency capacity for teams responding to an incident or a blocked deal.

Will testing take down our production environment?

No. We agree testing windows and destructive-test boundaries in the rules of engagement before anything starts, and all our traffic carries an identifier your team can filter on. Where risk is genuinely unavoidable we test against staging and validate the finding in production only with your sign-off.

Do you test staging or production?

Production wherever it is safe, because staging environments rarely reproduce the real access control model, the real data volumes, or the real third-party integrations. Where production is off-limits we test staging and flag explicitly which findings could not be validated.

What do we actually receive at the end?

A report with an executive summary written for non-engineers, and per-finding detail with reproduction steps, evidence, severity scoring and specific remediation guidance. You also get a prioritized fix backlog, a walkthrough session, and an attestation letter you can share with customers and auditors.

Is the retest really included?

Yes. One retest of every fixed finding within 30 days of report delivery, included in the original price. We reissue the report with updated status so you have a clean document to send onward.

Can you sign our NDA and security requirements?

Yes. We work under client NDAs as standard and can meet common customer requirements around background checks, insurance and data handling. All engagement data is encrypted at rest and destroyed on a schedule you set.

Do you work outside Israel?

Yes. Remote engagements run worldwide, and we cover European timezones comfortably. On-site work — network testing, physical assessment and training — is arranged case by case.

We are pre-revenue. Is this worth it yet?

Often not yet, and we will tell you so. If you have no customers and no sensitive data, a threat model workshop and a secure-defaults review will do more for you than a penetration test. We would rather point you there than sell you a report you do not need.

Not sure which fits?

A 45-minute scoping call ends with a fixed quote and a start date.

Scope an engagement