NODUM
ESEN

Offensive security consultancy

Madrid · remote

We findvulnerabilitiesand provethey are real.

Offensive security consultancy for small and mid-sized companies. We use AI tooling to cover more ground, and we verify every vulnerability by hand with a working proof of concept.

Request a conversation
Verification
manual, with PoC

Approach

01

A scanner tells you what might be wrong. We show you what is wrong, and how it is exploited.

Automation covers ground. It finds the forgotten service, the unpatched version, the parameter that answers oddly. We use it, and we use it heavily: it is the only way to look at an entire surface without leaving gaps.

What automation does not do is tell a false positive from a way in, or chain three minor flaws into access to the database. That is done by a person sitting in front of the system.

So every finding in our reports has been reproduced by hand. If we could not exploit it, we do not call it a vulnerability.

Services

02

Four jobs. Each one ends in a report of vulnerabilities that can be reproduced.

Scope is agreed in writing before we start. Write to us and we will define it.

How we work

03

Five steps. The third is the one that sets us apart and the one that takes longest.

  1. 01

    Scope

    We define in writing what is in, what is out and where we attack from. Nothing is touched without signed authorisation.

  2. 02

    Reconnaissance

    We map the whole surface with heavy automation. This is where AI lets us cover more ground than one person would cover alone.

  3. 03

    Manual verification

    We sit down in front of every candidate and either exploit it or discard it. False positives die here, not in your inbox.

  4. 04

    Report

    Every vulnerability with its working proof of concept, the real impact and the concrete fix. Written so that whoever decides can follow it and whoever writes the code can apply it.

  5. 05

    Retest

    Once you have fixed it, we try again. Only then do we call a finding closed.

Who does it

04

We report vulnerabilities to the Google, Microsoft and NVIDIA programmes.

Programmes · status

  1. Google

    VRP · grpc-go

    Fixed and credited

  2. Microsoft

    MSRC · Not disclosed

    Report open

  3. NVIDIA

    PSIRT · Not disclosed

    Report open

Alan Ortega

Founder · technical work

Bug bounty is a hobby here, not the business: two vulnerabilities found and fixed in Google reward programmes —one of them with a cash award— and reports currently open with Microsoft MSRC and NVIDIA PSIRT.

Finding record

Target
grpc-go
Maintained by
Google
Type
Authentication flaw
Severity
CVSS 7.5
Status
Fixed
Attribution
Credited by name
Programme
Google VRP

Open reports

There are reports in progress with Microsoft MSRC and with NVIDIA PSIRT. Pending resolution. Once they close and become public, they get counted here.

Contact

05

Tell us what you want us to look at. We answer if we can help, and we say so if we cannot.

alanortega7312@gmail.com

Write with whatever you have: a URL, an IP range, or just the question. We settle the scope afterwards.

Language
Spanish · English
Scope
SMEs · Spain

Or write from here

We only work on systems whose owner authorises us in writing.