Offensive security consultancy
Madrid · remote
We findvulnerabilitiesand provethey are real.
Offensive security consultancy for small and mid-sized companies. We use AI tooling to cover more ground, and we verify every vulnerability by hand with a working proof of concept.
- Verification
- manual, with PoC
Approach
01
A scanner tells you what might be wrong. We show you what is wrong, and how it is exploited.
Automation covers ground. It finds the forgotten service, the unpatched version, the parameter that answers oddly. We use it, and we use it heavily: it is the only way to look at an entire surface without leaving gaps.
What automation does not do is tell a false positive from a way in, or chain three minor flaws into access to the database. That is done by a person sitting in front of the system.
So every finding in our reports has been reproduced by hand. If we could not exploit it, we do not call it a vulnerability.
01
Automated coverage
Our own tooling and third-party tooling to enumerate the whole surface, not a sample of it.
02
Manual verification
Every finding is reproduced by hand. What cannot be reproduced is not reported.
03
Proof of concept
A request, a script or a video. Something your team can run and watch fail.
04
Impact, explained
What is reached, with what privilege, and what happens next. No hollow risk scores.
Services
02
Four jobs. Each one ends in a report of vulnerabilities that can be reproduced.
- 01External perimeter testWe enumerate everything your organisation exposes to the internet and attack it from outside, with no credentials, the way someone who has just found you would.
- 02Authenticated web application pentestWe log in with a user for each role and look for what a scanner cannot tell apart: broken business logic and permissions that fail to separate what they should.
- 03Internal test / Active DirectoryWe start from a machine inside the network, with the credentials of any ordinary employee, and measure how far that gets.
- 04Fix verification retestWe go back over every finding in the previous report and check whether the fix holds. We reopen whatever is still exploitable.
Scope is agreed in writing before we start. Write to us and we will define it.
How we work
03
Five steps. The third is the one that sets us apart and the one that takes longest.
01
Scope
We define in writing what is in, what is out and where we attack from. Nothing is touched without signed authorisation.
02
Reconnaissance
We map the whole surface with heavy automation. This is where AI lets us cover more ground than one person would cover alone.
03
Manual verification
We sit down in front of every candidate and either exploit it or discard it. False positives die here, not in your inbox.
04
Report
Every vulnerability with its working proof of concept, the real impact and the concrete fix. Written so that whoever decides can follow it and whoever writes the code can apply it.
05
Retest
Once you have fixed it, we try again. Only then do we call a finding closed.
Who does it
04
We report vulnerabilities to the Google, Microsoft and NVIDIA programmes.
Programmes · status
Google
VRP · grpc-go
Fixed and credited
Microsoft
MSRC · Not disclosed
Report open
NVIDIA
PSIRT · Not disclosed
Report open
Alan Ortega
Founder · technical work
Bug bounty is a hobby here, not the business: two vulnerabilities found and fixed in Google reward programmes —one of them with a cash award— and reports currently open with Microsoft MSRC and NVIDIA PSIRT.
- Target
- grpc-go
- Maintained by
- Type
- Authentication flaw
- Severity
- CVSS 7.5
- Status
- Fixed
- Attribution
- Credited by name
- Programme
- Google VRP
Finding record
Open reports
There are reports in progress with Microsoft MSRC and with NVIDIA PSIRT. Pending resolution. Once they close and become public, they get counted here.
Contact
05
Tell us what you want us to look at. We answer if we can help, and we say so if we cannot.
alanortega7312@gmail.comOr write from here