I test as if I were the attacker myself - realistic, methodical, and with a clear report as the result.
Web Application Pentesting
Thorough audit of web applications following OWASP methodology: SQL injection, XSS, broken access control (IDOR), authentication bypass, SSRF, path traversal and file upload vulnerabilities. Result: a clear report with findings, risk assessment and concrete remediation steps.
API Security Testing
Testing REST and other APIs against the OWASP API Security Top 10 - from endpoint recon and parameter pollution to JWT implementation flaws (algorithm confusion, weak signing).
Network Pentesting
Internal and external network audits: identifying misconfigurations, layer 2 vulnerabilities and attack paths within your network infrastructure.
Bug Bounty & Vulnerability Research
Active contribution to responsible disclosure programs. My experience as a bug bounty hunter (Intigriti) translates directly into sharper, more realistic pentests.
Not every organization needs a full pentest - sometimes it starts with insight.
Security Audit / Risk Assessment
Evaluation of your current security posture based on the CIA triad (confidentiality, integrity, availability), with attention to GDPR compliance.
NIS2 / CyFun® Guidance
Practical support in mapping out NIS2 obligations and the CyFun® framework - translated into achievable steps for SMEs, without unnecessary complexity.
Hardening & Configuration Review
Review of firewalls, IDS/IPS configurations and endpoint security, with concrete recommendations to reduce the attack surface.
- Organizations that want to know if their systems can withstand a real attack
- Companies that need to comply with NIS2 or start a CyFun® track
- Teams that need an independent security audit before an audit or certification