Skip to main content
Red Team
  • Main role: Carries out simulated attacks against an organisation's systems and networks to identify vulnerabilities and weaknesses in its defences.
  • Objective: To discover security breaches before real attackers do, simulating real-world threats and testing the Blue Team's response capabilities.
  • Tools and techniques: Uses methodologies such as MITRE ATT&CK to plan attacks.
  • Certification: Certified Ethical Hacker. Certification Number: ECC4720538691.

Pentester

It consists of searching for vulnerabilities or weaknesses in a company's systems, applications, or networks. The purpose of this type of test is to analyse the robustness of the cybersecurity measures implemented, while identifying possible access points for cybercriminals.

Basic and advanced security audits
Basic and advanced security audits (with social engineering) are carried out, along with a report on vulnerabilities found and corresponding recommendations.
Environments
Penetration tests are carried out in the following environments: infrastructure (computers, printers, etc.), websites, mobile devices, IoT, LAN/VLAN networks (routers, switches, etc.) and Wi-Fi networks.
Methodologies
OWASP TOP10, OWASP ISTG, OWASP IotGoat, PTES (Penetration Testing Execution Standard), NIST SP 800-115, MITRE ATT&CK.
Types of tests
Black box, white box, grey box testing.
Tools
NIKTO, OpenVAS, Nessus, malware used with authorisation in the post-exploitation phase to gain persistence on the targeted computer (Trojans, worms, ransomware, etc.), Atomic RED team, NMAP NSE, USB Rubber Ducky, Bash Bunny, etc.

Note: The tools mentioned are used at an advanced or expert level. Only some of the many tools that are used are mentioned.

Social Engineering

Using social engineering techniques to manipulate employees of the organisation and gain unauthorised access to its systems in order to discover weaknesses in the systems.

Techniques
The techniques used are phishing and spear phishing.
Environments
The sectors in which they are used include transport, finance, administration, water, food, energy, chemicals, ICT, etc.
Tools
Gophish - Open Source Phishing Framework, Blackeye-im, etc.

Note: The tools mentioned are used at an advanced or expert level. Only some of the many tools that are used are mentioned.

Awareness Talks

Depending on the weaknesses found in the audited company at the cyber level, a specific awareness talk can be given so that all participants understand the importance of following the recommendations given in the penetration tests.

No-obligation quote

You can request a no-obligation quote.

  • Pentesting
  • Social Engineering
  • Awareness Talks