NODUM

Offensive security consultancy

Madrid · remote

We findvulnerabilitiesand provethey are real.

Offensive security consultancy for small and mid-sized companies. We use AI tooling to cover more ground, and we verify every vulnerability by hand with a working proof of concept.

Approach

01

A scanner tells you what might be wrong. We show you what is wrong, and how it is exploited.

Automation covers ground. It finds the forgotten service, the unpatched version, the parameter that answers oddly. We use it, and we use it heavily: it is the only way to look at an entire surface without leaving gaps.

What automation does not do is tell a false positive from a way in, or chain three minor flaws into access to the database. That is done by a person sitting in front of the system.

So every finding in our reports has been reproduced by hand. If we could not exploit it, we do not call it a vulnerability.

Services

02

Four jobs. Each one ends in a report of vulnerabilities that can be reproduced.

Scope is agreed in writing before we start. Write to us and we will define it.

How we work

03

Five steps. The third is the one that sets us apart and the one that takes longest.

  1. 01

    Scope

    We define in writing what is in, what is out and where we attack from. Nothing is touched without signed authorisation.

  2. 02

    Reconnaissance

    We map the whole surface with heavy automation. This is where AI lets us cover more ground than one person would cover alone.

  3. 03

    Manual verification

    We sit down in front of every candidate and either exploit it or discard it. False positives die here, not in your inbox.

  4. 04

    Report

    Every vulnerability with its working proof of concept, the real impact and the concrete fix. Written so that whoever decides can follow it and whoever writes the code can apply it.

  5. 05

    Retest

    Once you have fixed it, we try again. Only then do we call a finding closed.

Who does it

04

A consultancy specialised in offensive security. We find vulnerabilities and verify them by hand.

Bug bounty · as a hobby

Programmes and platforms where the founder hunts for vulnerabilities in his spare time.

  • Google VRP
  • Microsoft MSRC
  • NVIDIA PSIRT
  • HackerOne
  • YesWeHack
  • Bugcrowd
  • Intigriti

Alan Ortega Álamo

Founder · technical work

Bug bounty is a hobby here, not the business: two vulnerabilities found in Google reward programmes —one fixed and rewarded by the VRP, the other fixed by a patch of his own merged upstream— and reports currently open with Microsoft MSRC and NVIDIA PSIRT.

Finding record

grpc-go
Google VRP · Insufficient check in the RBAC Authenticated matcher
Fixed · credited · rewarded by the VRP
See the PRRelease notes
protobuf-go
Google OSS VRP · Denial of service
Fixed · own patch merged upstream
See the patch

Only findings already fixed and public. Open reports are not detailed.

Open reports

There are reports in progress with Microsoft MSRC and with NVIDIA PSIRT. Pending resolution. Once they close and become public, they get counted here.

Co-founder · sales and operations

Claudia Ortega Álamo Handles the client relationship, the scope and the deadlines. Takes no part in the technical work.

FAQ

05

What is worth knowing before you commission a pentest.

All questions
  1. How is this different from a vulnerability scan?

    A scanner returns a list of candidates: things that might be wrong. We use those tools to cover the surface, and then we try to exploit every candidate by hand.

    Whatever we cannot reproduce stays out of the report, and whatever goes in comes with its proof of concept.

  2. How much does it cost?

    We do not publish rates because the work changes a great deal with scope: a single domain is not an internal network with Active Directory.

    We agree the scope in writing first, and the price is given for that specific scope, before we start.

  3. What do you need from us to start?

    Written authorisation from the owner of the systems and an agreed scope: which domains, ranges or applications are in and which are out. Without that, nothing is touched.

    Depending on the service, also: one user per role for the web application pentest, or a machine inside the network with an ordinary employee’s credentials for the internal test.

  4. Are you a certification body? Does the report count for ISO 27001, ENS or NIS2?

    We are not a certification body or an accredited organisation, and the report does not certify compliance with any standard.

    What it documents is what was tested, which vulnerabilities were verified and how to fix them. If a compliance process asks you for technical evidence, that is the information you can provide; whether you comply is decided by whoever audits that standard.

Contact

06

Tell us what you want us to look at. We answer if we can help, and we say so if we cannot.

contacto@nodumsec.com

Write with whatever you have: a URL, an IP range, or just the question. We settle the scope afterwards.

Language
Spanish · English
Scope
SMEs · Spain

After you write

  1. 01

    Reply

    We read every message and answer from a nodumsec.com address. If we cannot help, we say so.

  2. 02

    Scoping call

    A short call to understand what you want tested, from where and by when.

  3. 03

    Proposal

    We send you the scope, the dates and the price in writing. If you accept, the contract and the authorisation are signed before any system is touched.

Or write from here

We only work on systems whose owner authorises us in writing.