SysAlbania offensive security

We break it before someone else does

Penetration testing and incident response for teams that ship fast. Fixed scope, evidence in every finding, retest included.

How engagements are scoped and quoted
engagement -- recon phase
$
Web applicationsInternal networksCloud (AWS, Azure)APIsActive DirectoryMobile apps

Research-led, not scanner-led

Our team publishes security research and maintains a live CVE tracker. The techniques we test with come from that work, not from a vendor's rule pack.

296,161 CVEs tracked

View the CVE tracker

How an attacker gets from your edge to your domain

This is the chain we trace in an assessment. Each hop is a control that either held or did not.

Exposed serviceFootholdLateral movementDomain admin

Most engagements stop at the first hop that holds. The point of the test is finding which one that is, before someone else does.

How an engagement runs

No surprises. You know the scope, the window and the price before we start.

  1. 01

    Scope

    We agree targets, rules of engagement and a testing window in writing before anything is touched.

  2. 02

    Test

    Manual testing against the agreed surface, backed by tooling. You get a same-day call if we find something critical.

  3. 03

    Report

    Every finding carries reproduction steps, evidence and a CVSS rating, written so a developer can act on it.

  4. 04

    Retest

    Once you have fixed the findings we verify each one and reissue the report. Included, not billed separately.

What actually gets tested

Concrete technique coverage per surface, so you can check our scope against your estate before you talk to us.

Web applications

WEB
  • Authentication and session handling
  • Access control between tenants and roles
  • Injection into SQL, templates and commands
  • Business logic and payment flows

External network

NET
  • Service discovery across the public range
  • Exposed management and remote access
  • Known exploitable software versions
  • Credential spraying against exposed logins

Cloud

CLD
  • Identity and role assumption paths
  • Storage open to the public internet
  • Secrets in build pipelines and images
  • Network boundaries between environments

APIs

API
  • Authorisation on every endpoint, not just the gateway
  • Object level access between accounts
  • Rate limiting and enumeration
  • Schema validation and mass assignment

Active Directory

AD
  • Kerberos and delegation abuse
  • Privilege paths to domain administrator
  • Password policy and credential reuse
  • Group membership and ACL misconfiguration

Mobile

MOB
  • Tokens and credentials stored on the device
  • Certificate pinning and traffic interception
  • Backend endpoints reachable from the app
  • Secrets hardcoded into the package

What lands in your inbox

A report your developers can act on, not a tool dump with a logo on the cover.

  • Executive summary written for non-technical stakeholders
  • Every finding with reproduction steps, evidence and CVSS rating
  • Same-day disclosure call if anything critical surfaces mid-test
  • Remediation retest and a reissued report, included
report -- findings summary
$

Common questions

How long does a penetration test take?

A typical web application test runs five to ten working days including reporting. Scope drives the number, and we confirm it in writing before starting.

Do you need production access?

Not usually. Most tests run against a staging environment that mirrors production. Where production testing is genuinely required we agree a window and a rollback plan first.

What do we receive at the end?

A written report with an executive summary, every finding with reproduction steps and CVSS rating, and a remediation retest once fixes are in place.

Is retesting included?

Yes. Verifying that a fix actually works is part of the engagement, not a separate invoice.

Why teams choose us

Two working days

From enquiry to a fixed written quote. No discovery-call funnel.

Fixed price

Quoted before work starts. No hourly creep, no surprise invoice.

Retest included

We verify your fixes and reissue the report at no extra cost.

Authorised only

Written authorisation and rules of engagement before anything is touched.

Find out what an attacker would find

Tell us the target and the deadline. You get a fixed quote within two working days.

Book an assessment