Adversary simulation for you.
Penetration testing and red team operations by a small team of senior operators. The person who scopes your engagement is the person who runs it, start to finish. Fixed scope, published prices, and a report your engineers can act on.
Start small: Attack Surface Review, €1,900, two days, credited against a full engagement.
OSEP and OSCP certified. Ten published CVEs. Head of Security at AuditOne. Formerly Telefónica Tech. Registered in Cyprus, EU.
Authentication bypass on the customer portal via unsigned session token
Host portal..com
Impact Any unauthenticated user can mint a valid session for any account, including administrators.
Reproduction
- Request
/api/v2/sessionwith an emptyAuthorizationheader. - Set
algtononein the returned token and re-sign nothing. - Replay against
/admin. The response is200and the admin dashboard renders.
Track record
Every name, with the public sourceWhere we have worked, in-house and as a vendor. Public audit reports where the client agreed to publish; the rest under NDA and available as references on request.
The person you talk to is the person who tests.
Senior only.
A small team, all senior, all OSEP or OSCP certified. Every engagement is executed end to end by the same operator. No juniors learning on your network.
Manual depth.
Business logic, chained exploitation, custom tooling. The vulnerabilities scanners miss are the ones attackers find.
A report you can act on.
Reproduction steps that work against your setup, CVSS scored honestly, remediation written for your stack. Free retest within 30 days.
Fixed scope. Published prices.
Every package includes the scoping call, execution, a written report, and a remediation walkthrough. Prices in EUR, excluding VAT.
Start here: Attack Surface Review
External perimeter, up to 3 root domains. Two days. What is exposed, outdated, misconfigured, or leaked, validated and prioritized. Full amount credited against a full engagement within 90 days.
- Web Application Pentest
Manual testing of web apps and APIs. Auth, business logic, authorization, injection chains.
from €5,900 - External Network Pentest
Your internet-facing infrastructure from an attacker’s seat. Recon, enumeration, exploit validation.
from €5,900 - Internal Network Pentest
Assumed breach to Domain Admin. AD attack chains, segmentation, lateral movement.
quoted after scoping - Active Directory Assessment
Assumed foothold to Domain Admin. Kerberos, ACL abuse, relay, lateral movement.
from €8,900 - Mobile Application Pentest
iOS and Android, static and dynamic. Local storage, pinning, and the backend API.
quoted after scoping - Red Team Operations
Objective-based adversary simulation with EDR evasion. Tests prevention and detection together.
quoted after scoping - Cloud Security Assessment
AWS, Azure, GCP. IAM escalation paths, exposed storage, hybrid cloud-to-on-prem routes.
quoted after scoping
Why teams pick this over a Big4.
Mid-market teams usually get two options: enterprise pricing with juniors doing the work, or boutiques with nothing to verify. This is the third.
| Industry default | REDOPS | |
|---|---|---|
| Who does the work | Juniors, supervised remotely by a senior selling five other projects | A senior operator, the same one from kickoff to retest. No juniors, no handoffs |
| The report | Mostly boilerplate, CVSS inflated to justify the invoice | Written for your environment, scored honestly, remediation for your stack |
| Communication | An account manager in the middle; answers take days | A direct channel to the operator; answers in hours |
| Procurement | Forty-page MSAs, weeks of onboarding, change-order fees | NDA in 24 hours, proposal in 48, testing within three weeks |
| Pricing | On request, after a sales cycle | Published, bundles and terms included |
| After delivery | A PDF in a shared folder | A walkthrough with your team and a free retest within 30 days |
Credentials you can check before signing anything: OSEP on the OffSec verification page, CVEs with MITRE and INCIBE identifiers, public audit reports on the clients page, research at blog.redghostops.com.
Thirty minutes is enough to scope it.
Pick a slot. A mutual NDA goes out before the call, so we can talk about your actual environment. You get a written proposal within 48 hours, and only if you ask for one.