Technologies
The platforms we test — and the tools we test them with.
We work across the whole modern stack: cloud and identity, web and API, mobile and data. Here's what that covers, and the industry-standard tooling and frameworks behind our work.
Cloud & infrastructure
The cloud accounts, clusters and pipelines we assess for misconfiguration and exploitation.
- AWS
- Azure
- Google Cloud
- DigitalOcean
- Kubernetes
- Docker
- OpenShift
- Terraform
- Serverless (Lambda / Functions)
Operating systems & identity
The platforms and identity systems behind most internal compromise.
- Windows
- Active Directory
- Entra ID (Azure AD)
- Linux
- macOS
- Okta / SSO
- Kerberos
- LDAP
Web, API & application stacks
The frameworks, protocols and auth standards we test by hand.
- REST
- GraphQL
- SOAP
- OAuth2 / OIDC
- SAML
- JWT
- WordPress
- React / Next.js
- Node.js
- Django
- Laravel
- Spring
- ASP.NET
Mobile
Native and cross-platform mobile apps, client and server side.
- iOS
- Android
- React Native
- Flutter
Data & messaging
The datastores and brokers that hold and move the data attackers want.
- PostgreSQL
- MySQL
- MSSQL
- MongoDB
- Redis
- Elasticsearch
- Kafka
Tools we test with
Industry-standard offensive tooling, alongside the tools we build ourselves.
- Burp Suite
- Nmap
- Metasploit
- BloodHound
- Nessus
- sqlmap
- ffuf
- Ghidra
- Frida
- Nuclei
- Responder
Standards & frameworks
The methodologies and scoring systems our work is built on.
- OWASP WSTG
- OWASP MASTG
- OWASP API Top 10
- MITRE ATT&CK
- PTES
- OSSTMM
- NIST 800-115
- CVSS / EPSS
Working with something that isn't listed? We almost certainly test it too — tell us your stack.
Tell us about your stack.
Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.