Adversary simulation for you.

Penetration testing and red team operations by a small team of senior operators. The person who scopes your engagement is the person who runs it, start to finish. Fixed scope, published prices, and a report your engineers can act on.

Start small: Attack Surface Review, €1,900, two days, credited against a full engagement.

OSEP and OSCP certified. Ten published CVEs. Head of Security at AuditOne. Formerly Telefónica Tech. Registered in Cyprus, EU.

CRITICAL CVSS 9.8 AV:N/AC:L/PR:N/UI:N

Authentication bypass on the customer portal via unsigned session token

Host  portal.redactedclient.com

Impact  Any unauthenticated user can mint a valid session for any account, including administrators.

Reproduction

  1. Request /api/v2/session with an empty Authorization header.
  2. Set alg to none in the returned token and re-sign nothing.
  3. Replay against /admin. The response is 200 and the admin dashboard renders.
Illustrative finding, in the format every report uses.

Where we have worked, in-house and as a vendor. Public audit reports where the client agreed to publish; the rest under NDA and available as references on request.

The person you talk to is the person who tests.

Senior only.

A small team, all senior, all OSEP or OSCP certified. Every engagement is executed end to end by the same operator. No juniors learning on your network.

Manual depth.

Business logic, chained exploitation, custom tooling. The vulnerabilities scanners miss are the ones attackers find.

A report you can act on.

Reproduction steps that work against your setup, CVSS scored honestly, remediation written for your stack. Free retest within 30 days.

Fixed scope. Published prices.

Every package includes the scoping call, execution, a written report, and a remediation walkthrough. Prices in EUR, excluding VAT.

Start here: Attack Surface Review

External perimeter, up to 3 root domains. Two days. What is exposed, outdated, misconfigured, or leaked, validated and prioritized. Full amount credited against a full engagement within 90 days.

€1,900
Book a free scoping call
  • Web Application Pentest

    Manual testing of web apps and APIs. Auth, business logic, authorization, injection chains.

    from €5,900
  • External Network Pentest

    Your internet-facing infrastructure from an attacker’s seat. Recon, enumeration, exploit validation.

    from €5,900
  • Internal Network Pentest

    Assumed breach to Domain Admin. AD attack chains, segmentation, lateral movement.

    quoted after scoping
  • Active Directory Assessment

    Assumed foothold to Domain Admin. Kerberos, ACL abuse, relay, lateral movement.

    from €8,900
  • Mobile Application Pentest

    iOS and Android, static and dynamic. Local storage, pinning, and the backend API.

    quoted after scoping
  • Red Team Operations

    Objective-based adversary simulation with EDR evasion. Tests prevention and detection together.

    quoted after scoping
  • Cloud Security Assessment

    AWS, Azure, GCP. IAM escalation paths, exposed storage, hybrid cloud-to-on-prem routes.

    quoted after scoping

Full catalog, tiers, retainers, and terms

Why teams pick this over a Big4.

Mid-market teams usually get two options: enterprise pricing with juniors doing the work, or boutiques with nothing to verify. This is the third.

Industry default REDOPS
Who does the work Juniors, supervised remotely by a senior selling five other projects A senior operator, the same one from kickoff to retest. No juniors, no handoffs
The report Mostly boilerplate, CVSS inflated to justify the invoice Written for your environment, scored honestly, remediation for your stack
Communication An account manager in the middle; answers take days A direct channel to the operator; answers in hours
Procurement Forty-page MSAs, weeks of onboarding, change-order fees NDA in 24 hours, proposal in 48, testing within three weeks
Pricing On request, after a sales cycle Published, bundles and terms included
After delivery A PDF in a shared folder A walkthrough with your team and a free retest within 30 days

Credentials you can check before signing anything: OSEP on the OffSec verification page, CVEs with MITRE and INCIBE identifiers, public audit reports on the clients page, research at blog.redghostops.com.

Thirty minutes is enough to scope it.

Pick a slot. A mutual NDA goes out before the call, so we can talk about your actual environment. You get a written proposal within 48 hours, and only if you ask for one.