CUSTOM PENTEST

Pentest, built around you

Individual security assessment

When no standard module fits, we build the test around you

Not every environment fits a ready-made package. Source code, mobile apps, Wi-Fi, passwords, the dark web, or the emergency itself: tell us what worries you, and we scope the test precisely around it. You talk to the testers directly, not to a sales desk.

How a custom test comes together

Scope first, then the test

A good penetration test starts with a clear question: what exactly should be tested, and what do you want to be protected against? In the scoping call we settle goals, systems, permitted attack depth, and conditions. The result is a written fixed-price offer, not a black-box estimate.

We base our work on the BSI penetration-testing methodology. It defines five phases, from preparation and information gathering through to analysis, and governs how aggressively we test. We reveal weaknesses and only exploit them as far as needed to prove the risk.

Level of knowledge

Black, grey or white box

How much we know about your system up front changes both the insight and the effort. We pick the level that fits the goal, often a mix.

01

Black box

We start with no prior knowledge, like an external attacker from the internet. Realistic, but slower, because much of the time goes into reconnaissance.

02

Grey box

You give us partial information, such as a test account or a network sketch. A good middle ground between realism and depth, and the one we recommend most often.

03

White box

Full insight including source code and architecture. Finds the most weaknesses per day, ideal for code review and critical systems.

What we deliver

Disciplines in detail

Clients request these building blocks most often, on their own or combined. Each one pairs with the standard modules in our portfolio.

Source code

Code review

In a code review we read your source code instead of only testing it from the outside. That surfaces logic and authorization flaws a pure black-box test never triggers, because the right path is never reached from outside. We combine manual review along the OWASP Code Review Guide with automated static analysis (SAST): the tools sift the mass, a human judges business logic and context.

  • Authentication, session handling and access control
  • Injection points (SQL, command, template) at the source
  • Handling of cryptography, secrets and keys in the code
  • Vulnerable dependencies and outdated libraries

Requires: read access to the repository (grey or white box).

Result: findings with the exact code location and a concrete fix.

iOS and Android

Mobile app pentest

Mobile apps store data locally, talk to backends, and can be studied on a device the attacker owns. We test iOS and Android apps against the OWASP MASVS (currently v2.1, eight categories) and work along the Mobile Application Security Testing Guide (MASTG v2.0, as of 2026). We combine static analysis of the app package with dynamic testing on a running device.

  • Local data storage: tokens, caches, logs, backups
  • Transport security including TLS and certificate pinning
  • Authentication and hardening of the backend interfaces
  • Reverse engineering, tamper protection and privacy

Requires: an app build and usually a test account.

Result: a report with findings mapped directly to the MASVS categories.

Wi-Fi

Wi-Fi pentest

Wireless networks do not stop at the office wall. In a Wi-Fi pentest we check on site whether your network can be taken over or bypassed, for WPA2 and WPA3, both with a password (PSK) and with company login (Enterprise). A common weak spot: clients that do not strictly verify the RADIUS server certificate and get lured onto a rogue access point (evil twin).

  • Capturing handshakes and PMKID, offline attack on the password
  • Evil twin against WPA2-Enterprise, harvesting credentials
  • Checking server certificate validation and the EAP configuration
  • Separation of guest and company network, rogue access point detection

Format: an on-site engagement at your locations.

Result: a report with attack paths and segmentation advice.

Active Directory

Password audit

A password audit shows how resilient your real passwords are, not just your policy on paper. We take the NTLM hashes from the Active Directory database (NTDS.dit) and test them offline with Hashcat against word lists, leak collections, and rules tailored to your company. The plaintext passwords never leave your premises.

  • A joint, clean extraction of the hashes from the domain controller
  • Offline analysis: weak, short and guessable passwords
  • Reuse and matching against known data breaches
  • Assessing your policy against the BSI guidance (ORP.4)

Requires: supervised access to a domain controller.

Result: anonymous statistics and a policy recommendation. Plaintext is destroyed after the test.

Leaked data

Dark web analysis

Much of what attackers know about you is already out in the open: in infostealer logs, on leak sites, in Telegram channels and combo lists. In a dark web analysis we search these sources specifically for your domains, accounts, and documents. You see which credentials and sessions are already circulating before someone uses them. We work purely passively and never buy illegal data.

  • Leaked credentials for your domains and employees
  • Infostealer logs (RedLine, Lumma, StealC) with passwords and cookies
  • Exposed documents, source code and API keys
  • Brand abuse, fake domains and typosquatting

Format: a one-off search or continuous monitoring.

Result: a list of findings with assessment and a clear recommendation.

In front of an audience

Live hacking

A live hacking session makes abstract risk visible. We run real attacks in front of your staff, your management, or at a trade fair, and explain every step so non-technical people follow along. Nothing shifts security awareness like a password that falls in seconds or a QR code that takes over a laptop.

  • Attacks on prepared demo systems, never on real client data
  • Hands-on phishing, Wi-Fi and hardware attacks
  • Scenarios and language tailored to your audience
  • A follow-up Q&A and practical tips for everyday work

Format: talk or workshop, 45 to 90 minutes, remote or on site.

Result: more awareness across the team, not a technical report.

Emergency

Incident response

When it is burning, every hour counts. In incident response we support you during an active incident and prepare you for the emergency. We work along the established phases from NIST SP 800-61 (preparation, detection, containment, recovery, lessons learned) and keep the NIS2 reporting deadlines in view: 24 hours for the early warning, 72 hours for the initial report, one month for the final report.

  • Immediate help and triage: what happened, what is affected?
  • Containment, evidence preservation and an orderly restart
  • Support with reporting to authorities under NIS2
  • Preparation: playbooks, emergency contacts and tabletop exercises

Format: acute first aid or prevention on a retainer.

Result: the incident under control, a documented cause and hardening.

What else?

More scenarios on request

We combine these building blocks as needed, on their own or as part of a larger project. Your topic missing? Just ask for it.

Cloud and hybrid

Configuration review for Azure, AWS and Microsoft 365, including identities and permissions.

OT, IoT and hardware

Controllers, connected devices and boards: analysis of firmware, interfaces and protocols.

Air-gap and special lab

Isolated or highly sensitive networks, tested in a setup that matches your reality.

LLM and AI security

Prompt injection, data leakage and attacks on agentic systems and AI integrations.

Product security

Security across a product's whole lifecycle, from the idea to the update.

Vulnerability scan

Automated, recurring scans as affordable baseline coverage between tests.

Purple teaming

Attack and defence at one table: we test, your team learns to read along live.

Workshops and awareness

Training for development, IT and staff, hands-on rather than slide-heavy.

How it runs

From the first call to the retest

  1. 1

    Scoping

    We settle goals, systems and permitted attack depth together. Free and without obligation.

  2. 2

    Offer and sign-off

    You get a written fixed-price offer and grant the formal test authorization.

  3. 3

    Testing

    We test in the agreed window and report critical findings at once, not only in the report.

  4. 4

    Report

    A clear report with risk rating, evidence and concrete measures. Usable for audits.

  5. 5

    Retest

    After your fixes we check specifically whether the gaps are really closed.

Common questions

Good to know

It depends on scope: systems, attack depth and duration set the price. That is why every engagement starts with a free scoping call. After that you get a written fixed-price offer, with no hidden costs and no call centre in between.
Black box is the most realistic view from outside, white box finds the most weaknesses in the same time because we can see code and architecture. In practice we often recommend grey box, a test account plus some context. We advise you on this during scoping.
In five steps: scoping, a written offer with formal sign-off, testing in the agreed window, the report and an optional retest. We always record the test authorization in writing so the boundaries are clear for both sides.
Only if you want a code review or a white-box test. For most other building blocks a test account and some context are enough. We never request more access than the agreed test truly needs.
Yes. We passively evaluate openly available and leaked sources and never buy illegal data. You learn which of your credentials and documents are already circulating and can react before someone uses them.
As fast as we can, and we will be honest: we are a specialised team, not a 24/7 large provider. If we are not the right fit, we say so openly. Best of all, prepare in advance with playbooks and a tabletop exercise, so the emergency runs in an orderly way.
Yes. Our report is built so you can use it as evidence for internal audits and for requirements from ISO 27001, TISAX and NIS2. On request we map the findings to the relevant control catalogue.
That is exactly what this page is for. The list above is a sample, not a fixed catalogue. Describe your topic and we will tell you honestly whether and how we can test it meaningfully.

Your scenario, our test

Tell us in a few sentences what is on your mind. We come back with an honest assessment and a clear next step, without sales pressure.