Pentest & Red Team
We attack the system the way somebody else would: from outside, over the air, without credentials you did not hand out. Then we give your engineers the exact path we took, in the order we took it.
- The system is built, deployed or about to ship
- It has a radio link nobody has attacked yet
- You want the attacker path, not a checklist
- A building or a vehicle is part of the target
- You need a design reviewed before it exists, that is an audit
- You want deep research on one protocol, that is vulnerability research
- Your team needs the skills in-house, that is a training
How it runs.
You hear from us during, not only at the end. A finding that matters does not wait for the report.
Scoping
A short call on what the system is, what it transmits, and what would hurt. We come back with a scope, a day count and a price you can put in a purchase order.
Reconnaissance
Passive first: what is on the air, what identifies itself, what talks without being asked. Most of the interesting findings start here.
Attack
Active testing against the agreed targets: replay, forgery, protocol abuse, physical access, whatever the surface allows. Anything high impact gets reported the same day.
Reporting
Findings ranked by what an attacker would actually do with them, with reproduction steps, captures and the fix we would apply.
Retest
Once your team has shipped the fixes, we come back and check them. Included, not billed separately.
What lands on your desk.
Something an engineer can act on and something a board can read, plus everything needed to reproduce a finding without calling us.
- Technical report
- Findings, impact, reproduction steps and remediation, per issue
- Executive summary
- Two pages a non-technical reader can act on
- Captures and scripts
- The raw material behind each finding, so you can reproduce it
- Debrief session
- A walkthrough with your engineers, questions included
- Retest report
- What was fixed, what was not, and what changed
What we can attack.
Pick the rows that apply and we will tell you the days each one costs.
All services| Target | What that involves |
|---|---|
| Wireless products | Consumer or industrial devices with any radio interface |
| Mobile and private networks | Devices, radio access and core, 2G through 5G SA |
| OT and industrial radio | Telemetry, remote command, LoRa and proprietary links |
| Vehicles | Key systems, telematics, charging links, bus access over radio |
| Buildings | Access control, gates, badge systems, physical intrusion over the air |
| Embedded hardware | Debug interfaces, firmware, secrets at rest |
| Full red team | An objective rather than a target list, radio as the entry path |
Questions we get asked.
Do you need our source code?
No. We work from the outside by default. If you give us firmware or source, we go further in the same number of days.
Will you break the device?
Sometimes. We agree beforehand which units are expendable and which must survive.
Can you test on a live deployment?
Often yes, with constraints agreed in writing. Where transmitting is a risk, we replicate in a shielded environment.
Who writes the report?
The consultants who did the work. There is no separate reporting team and no template padding.
Tell us what transmits. We will tell you what it leaks.
One call to scope it, a fixed proposal after. NDAs signed before we talk details, if that is how your procurement works.