01 Offensive security consultancy

Offensive security testing.

Find the exploit path, prove the impact, and leave engineering with a fix they can ship.

  • Web
  • API
  • Cloud
  • External exposure

Find the path.
Prove the impact.

1H Security tests the assumptions between users, applications, APIs, and infrastructure. The goal is not a longer finding list. It is a sharper view of what is reachable, what matters, and what to fix first.

Human-led / exploit-driven / fix-focused

Depth where automated checks stop.

01

Web applications

Identity, access control, business logic, session state, file handling, and privileged workflows.

02

APIs and integrations

Object-level authorisation, token handling, state manipulation, webhooks, schemas, and trust boundaries.

03

Cloud control paths

Internet-facing services, identity assumptions, storage exposure, deployment defaults, and management reachability.

04

External attack surface

Asset discovery, exposed services, forgotten hosts, weak entry points, and evidence-backed prioritisation.

05

Architecture-informed testing

Hands-on review shaped by data flows, system roles, sensitive operations, and the controls between them.

Specificity beats anonymous praise.

The report excerpt below is illustrative, not a claimed client result. It shows the standard: reproducible evidence, a defensible impact, and a fix an engineer can validate.

A finding should survive contact with engineering.

Clear preconditions. A short attack path. Enough evidence to reproduce the issue without reverse-engineering the report.

Illustrative Finding 04
High

Broken object-level authorisation

Cross-tenant invoice export through an unbound job identifier

A low-privileged user can retrieve an export created by another tenant because the download endpoint does not re-evaluate tenant ownership.

Precondition
Authenticated user
Affected route
GET /v1/exports/{job_id}
Impact
Cross-tenant billing data exposure

Attack path

  1. 01 Create an export as a low-privileged user.
  2. 02 Substitute a valid job identifier owned by another tenant.
  3. 03 Receive the completed export without an ownership check.
Fix direction

Bind export lookup to the caller's tenant, re-check access at download time, and add a cross-tenant regression test.

Tight scope. Open channel. Useful close-out.

  1. 01

    Shape

    Set targets, roles, test access, priorities, dates, and production constraints.

  2. 02

    Test

    Map the system, probe the controls, and chain weaknesses where the impact changes.

  3. 03

    Triage

    Raise serious findings early, confirm context, and keep engineers close to the evidence.

  4. 04

    Close

    Deliver the report, walk through priorities, and validate the critical repairs.

Built for the people who have to act.

Engineering report

Reproduction steps, preconditions, affected components, evidence, impact, and specific repair guidance.

Decision summary

A concise view of exposure, important attack paths, immediate actions, and systemic themes.

Retest record

A clear status for repaired findings, with any remaining conditions or follow-up work called out.

The useful unit is not a vulnerability count.

It is a decision: fix now, fix next, or accept the risk with eyes open.

Have a target in mind?

Send the systems in scope, preferred dates, production constraints, and the decision the test needs to support.

[email protected]