CREST
Accredited company & testers
Where AI multiplies coverage
These are the jobs our researchers used to spend three days on. AI copilots compress them to hours. The researcher spends the freed time on exploit chaining and impact analysis.
10k subdomains, certs, exposed admins, leaked credentials. AI ranks the 50 worth a human-day, with a reason per row. Replaces a researcher burning a week on manual sweep.
Minified bundle to behaviour map. Endpoint inventory, role hints, hidden parameters, cred patterns. The researcher-grade JS analysis a traditional pentester routinely skips.
Working note to triager-ready write-up. Title, reproduction steps, named bug class, severity rationale. The researcher rewrites for clarity and signs.
Two users, two responses, diffed. Object IDs mapped across workflows. Authorization bugs surfaced as candidate findings before the researcher chains them.
Where a researcher ships the bug
The jobs AI-only vendors quietly skip, and a freelance bug bounty hunter running Claude Code cannot deliver to a CISO. Our CREST-accredited researchers do.
AI doesn't know your invariants. Roles, asset graph, money flow. A researcher reads your app like an attacker and chains primitives into a kill chain.
A finding without a PoC is a guess. The researcher runs the chained exploit, captures the request trail, ships the video your dev team can replay.
Severity is not CVSS alone. The researcher maps each finding to the asset it threatens and writes the line your auditor and CFO both read.
Every report leaves with a CREST-accredited researcher's name on it. No AI signature. No auto-published findings. One throat to choke.
AI-assisted pentest runs on
The AI / researcher boundary applies the same way across every pentest we ship. Pick the engagement that matches your scope. The methodology is identical.
Auth bypass, IDOR, business-logic flaws, SSRF, deserialization. AI maps endpoints and diffs tenant responses, the researcher chains the kill chain.
iOS + Android, native + Flutter + React Native. AI maps the bundle and IPC surface, the researcher drives the runtime exploit.
IMDSv1 SSRF, IAM role-chain abuse, Lambda over-privilege, AKS pod-identity. AI inventories the control plane, the researcher chains identity.
AI surfaces pattern matches across the codebase, including AI-generated-code drift. The researcher audits invariants and signs off on severity.
AI handles open-source recon, lookalike domains, and leaked-credential checks. The researcher drives stealth, detection bypass, and the objective chain.
AI mines invariant-violation patterns across Solidity, Rust, and Move. The researcher writes the working PoC on a forked mainnet.
Where AI multiplies coverage
These are the jobs our researchers used to spend three days on. AI copilots compress them to hours. The researcher spends the freed time on exploit chaining and impact analysis.
10k subdomains, certs, exposed admins, leaked credentials. AI ranks the 50 worth a human-day, with a reason per row. Replaces a researcher burning a week on manual sweep.
Minified bundle to behaviour map. Endpoint inventory, role hints, hidden parameters, cred patterns. The researcher-grade JS analysis a traditional pentester routinely skips.
Working note to triager-ready write-up. Title, reproduction steps, named bug class, severity rationale. The researcher rewrites for clarity and signs.
Two users, two responses, diffed. Object IDs mapped across workflows. Authorization bugs surfaced as candidate findings before the researcher chains them.
Where a researcher ships the bug
The jobs AI-only vendors quietly skip, and a freelance bug bounty hunter running Claude Code cannot deliver to a CISO. Our CREST-accredited researchers do.
AI doesn't know your invariants. Roles, asset graph, money flow. A researcher reads your app like an attacker and chains primitives into a kill chain.
A finding without a PoC is a guess. The researcher runs the chained exploit, captures the request trail, ships the video your dev team can replay.
Severity is not CVSS alone. The researcher maps each finding to the asset it threatens and writes the line your auditor and CFO both read.
Every report leaves with a CREST-accredited researcher's name on it. No AI signature. No auto-published findings. One throat to choke.
AI-assisted pentest runs on
The AI / researcher boundary applies the same way across every pentest we ship. Pick the engagement that matches your scope. The methodology is identical.
Auth bypass, IDOR, business-logic flaws, SSRF, deserialization. AI maps endpoints and diffs tenant responses, the researcher chains the kill chain.
iOS + Android, native + Flutter + React Native. AI maps the bundle and IPC surface, the researcher drives the runtime exploit.
IMDSv1 SSRF, IAM role-chain abuse, Lambda over-privilege, AKS pod-identity. AI inventories the control plane, the researcher chains identity.
AI surfaces pattern matches across the codebase, including AI-generated-code drift. The researcher audits invariants and signs off on severity.
AI handles open-source recon, lookalike domains, and leaked-credential checks. The researcher drives stealth, detection bypass, and the objective chain.
AI mines invariant-violation patterns across Solidity, Rust, and Move. The researcher writes the working PoC on a forked mainnet.
What we test
Each provider gets a manual, threat-modelled review against its real attack surface, control plane, identity, network, and workload. Intensity tunes per scope.
IMDSv1 SSRF, IAM role chaining, public S3 enumeration, Lambda over-privilege, EKS cluster-role abuse, KMS key-policy misuse, Cognito user-pool misconfig, Secrets Manager exposure.
Managed identity over-scope, Storage Account SAS leak, Function App env exposure, AKS pod-identity abuse, Key Vault access policy bypass, Azure AD application consent, Logic App secret reuse.
Workload-identity confusion, service-account impersonation, Cloud Run scope abuse, GKE node pool escape, Secret Manager IAM gaps, Cloud Storage bucket policy bypass, Cloud Functions trigger replay.
Pod escape via privileged container, RBAC bypass, etcd exposure, kubelet API abuse, sidecar/init container attack paths, NetworkPolicy gaps, admission-controller bypass, ServiceAccount token theft.
What we test —
Every layer of the Microsoft estate gets a manual, threat-modelled review against its real attack surface — identity, infrastructure, productivity, devices, business apps, and pipelines. Intensity tunes per scope.
Illicit OAuth consent-grant phishing, nOAuth cross-tenant token replay, Primary Refresh Token theft via TPM/SSO key extraction, Conditional Access bypass through legacy auth (IMAP/SMTP/POP3), MFA-fatigue chained with device-code phishing, application-permission over-scope on Graph, Service Principal credential rotation gaps, and B2B guest-user privilege escalation via dynamic-group injection.
Managed-identity over-scope at subscription root, Storage Account SAS leakage and over-permissive lifetimes, Function App environment-variable exposure, Key Vault access-policy bypass, AKS pod-identity abuse and node-to-control-plane pivot, NSG misconfiguration with JIT-VM bypass, ARM/Bicep template parameter injection, and role-definition assignment-scope drift across management groups.
Exchange Online OAuth-app phishing, SharePoint app-only Sites.Selected over-scope, OneDrive token reuse across guest tenants, Teams external-federation chat and tab injection, Power Automate Office-365 connector abuse, transport-rule and mail-flow-rule tampering for silent exfiltration, BEC pivot from compromised mailbox to vendor invoice fraud, and eDiscovery / Compliance role abuse.
Device-compliance bypass via local-admin escalation, Conditional Access compliant-device spoofing, MDM certificate reuse and silent re-enrolment, App Protection Policy bypass on rooted/jailbroken devices, Autopilot enrolment abuse for tenant join, configuration-profile drift between OU rings, and Win32-app deployment weaponised as a SYSTEM payload.
Record-level security bypass via teams and business-unit hierarchies, Power Platform connector abuse where HTTP-with-Azure-AD is reused across environments, Power Automate flow ownership take-over, custom-connector secret reuse, Dataverse plug-in code injection, Power Pages web-role spoofing with anonymous portal SQL access, and Copilot Studio (formerly Power Virtual Agents) prompt injection into downstream connectors.
Service-connection abuse pivoting cross-pipeline, secret leakage in YAML pipelines and variable groups, OIDC federated workload-identity over-scope, branch-protection bypass via push-options and required-reviewer gaps, self-hosted build-agent escape to host, package-feed dependency confusion, GitHub App token-permission over-scope, and Personal Access Token reuse across orgs.
What we review —
Each surface is read off the diagram, then walked with the operators who run it. Findings score on attacker reachability, not on policy compliance alone.
VLAN boundaries, firewall rule density, east-west controls, and the segments that have quietly grown flat through years of exception rules.
VPN tunnels, MPLS hand-offs, SaaS connectors, and the partner-tenant paths that bypass your perimeter via a vendor’s allowlist.
Active Directory trust direction, RADIUS/TACACS scope, jump-host policy, service-account reachability across segments.
Internet-facing posture, DMZ tenancy, NAT/PAT semantics, IPv6 dual-stack assumptions, management-plane exposure.
Firewalls, IDS/IPS, NDR, segmentation tooling, secrets vaults, EDR coverage map. Each control read for what it sees and what it does not.
Failover paths and DR sites tested as live network surface. A clean primary network with a flat DR path is one disaster from being flat-attacked.
What gets tested —
Engagements follow the attack the way an intruder would: web to API to identity to internal, not one isolated checklist at a time.
Authn/z bypass, business-logic abuse, injection, and SSRF chained to internal access.
BOLA, BFLA, mass assignment, and broken auth across REST, GraphQL, and gRPC.
Post-foothold lateral movement, privilege escalation, and domain compromise.
Over-privileged roles, token replay, federation tampering, and metadata-service pivots.
Insecure storage, certificate-pinning bypass, hardcoded secrets, and client-side API abuse.
Code-informed testing where you grant access. A faster path to the flaw that matters.
What we test —
Every layer of the SAP landscape gets a manual, threat-modelled review against its real attack surface — kernel, database, presentation, transport, custom code, and authorization. Intensity tunes per scope.
RECON-class unauth user creation (CVE-2020-6287 family), ICMAD memory corruption (CVE-2022-22536 family), authority-object bypass against S_TCODE / S_DEVELOP / S_RFC, ABAP code injection in dynamic CALL TRANSACTION and EXECUTE IMMEDIATELY, transport-request abuse, message server unauthenticated registration.
SQL injection in custom procedures, SYSTEM privilege escalation, cross-schema access via shared CDS views, _SYS_REPO mis-grants, encryption-at-rest verification, audit-policy gaps, XSA tenant boundary bypass, replication-route abuse on system replication.
Segregation-of-duties chains that move money — vendor master maintenance + invoice posting + payment release in one user; F110 payment program abuse via spoofed bank master; MIRO three-way-match bypass; goods-receipt reversal-and-repost flows that paper over inventory shrink.
OData service authorisation gaps, CSRF token reuse across sessions, UI5 mock-data leakage, Launchpad role-hiding bypass, Gateway service /sap/opu/odata/ exposure, web-dispatcher header-rewrite abuse, BSP application chained-XSS to ABAP RFC.
Gateway ACL bypass (reginfo / secinfo gaps), unauthenticated RFC server registration, message-server SXM access, SAProuter route-permission leakage, DIAG / RFC protocol replay where TLS isn't terminated, exposure of internal load-balancer behind public listener.
Z-program authority-check omissions, hardcoded SAP* / DDIC credentials in customer transports, ABAP open-SQL injection in customer namespaces, role/profile drift between DEV and PROD landscapes, derived-role inheritance abuse, GRC mitigations that whitelist the chain rather than break it.
What we test
These are the surfaces SecureLayer7's app-sec practice operates across. Every surface in scope by default; intensity tunes per engagement.
Login bypass, session fixation, token prediction, password reset flaws, MFA weaknesses, federation bypass, OAuth/OIDC misconfig.
IDOR, broken object-level auth, privilege escalation, multi-tenant bleed, role/scope-checking gaps in API + UI.
Price manipulation, workflow abuse, state-machine bypass, race conditions, the chained exploits unique to your application.
REST + GraphQL, BOLA, mass assignment, query-cost, schema introspection. gRPC, protobuf field abuse, reflection leaks, streaming-method DoS, mTLS misconfig. MQTT, broker auth, ACL bypass, retained-message exposure, topic-injection across IoT/real-time brokers.
Local storage exposure, key management, encryption-at-rest verification, transit ciphers, certificate pinning.
SQLi, XXE, SSTI, command injection, deserialization, prototype pollution, tested manually with chained exploits, not just signatures.
Exposed admin panels, misconfigured headers, leaked secrets in JS bundles, third-party SDK exposure, server-side config drift.
Solidity audit (reentrancy, integer over/underflow, access-control gaps, unchecked external calls, gas-griefing, oracle manipulation), EIP-712 signature reuse, wallet-connect phishing flows, multicall + delegatecall abuse, ERC-20/ERC-721 approve-and-drain, bridge replay, MEV / front-running on dApp UX.
What we test
Every AWS pentest is threat-modelled to your Org structure, IAM graph, and account topology, then exercised by hand against named bug classes across identity, compute, data, and posture controls.
IAM role chaining, sts:AssumeRole over-scope, IAM Identity Center / SSO permission-set drift, Cognito user-pool ID-token confusion, instance-profile credential reuse, federated-role trust-policy bypass, IAM Access Analyzer blind spots, root-account fallback paths.
EC2 IMDSv2-bypass via SSRF, Lambda execution-role over-scope, EKS service-account abuse, ECS task-role chaining, Fargate trust-policy reuse, EBS snapshot exfil, AMI-based persistence, Systems Manager Session Manager impersonation.
S3 bucket-policy bypass, Object Ownership confusion, KMS key-policy misuse, Secrets Manager rotation drift, RDS IAM-auth gap, DynamoDB stream replay, EBS snapshot public exposure, Glue catalog data leakage.
CloudTrail trail-tampering, GuardDuty finding suppression, AWS Config rule drift, AWS Organizations SCP gaps, CloudWatch log-group ACL bypass, EventBridge rule reuse, Audit Manager evidence drift, IAM Access Analyzer false-clean.
What we test
Each provider gets a manual, threat-modelled review against its real attack surface, control plane, identity, network, and workload. Intensity tunes per scope.
IMDSv1 SSRF, IAM role chaining, public S3 enumeration, Lambda over-privilege, EKS cluster-role abuse, KMS key-policy misuse, Cognito user-pool misconfig, Secrets Manager exposure.
Managed identity over-scope, Storage Account SAS leak, Function App env exposure, AKS pod-identity abuse, Key Vault access policy bypass, Azure AD application consent, Logic App secret reuse.
Workload-identity confusion, service-account impersonation, Cloud Run scope abuse, GKE node pool escape, Secret Manager IAM gaps, Cloud Storage bucket policy bypass, Cloud Functions trigger replay.
Pod escape via privileged container, RBAC bypass, etcd exposure, kubelet API abuse, sidecar/init container attack paths, NetworkPolicy gaps, admission-controller bypass, ServiceAccount token theft.
What we cover
Each surface scoped against named bug classes, not generic checklists. One pod chains findings across surfaces, so a phishing foothold can follow into AD and then into the cloud on the same SOW.
Subdomain takeover, exposed admin panels on edge devices, default credentials on appliances, leaked credentials in paste sites and code repos. Inventory feeds the internal phase.
SMB relay, Kerberoasting, NTLM hash capture, lateral movement via WMI and PsExec, unconstrained delegation paths. Assumed-breach foothold, then chain to identity.
ADCS ESC1–ESC8 abuse, constrained delegation, DCSync, BloodHound paths to Domain Admin, Entra ID conditional-access bypass. Identity is treated as its own surface, not a footnote.
IMDSv1 SSRF, IAM role-chain abuse, S3 enumeration and policy gaps, Lambda over-privilege, AKS pod-identity abuse, GCP service-account impersonation across projects.
Authentication bypass, IDOR, business-logic flaws, SSRF into cloud metadata, deserialization, GraphQL introspection abuse, broken object-property authorization on REST.
Sender spoofing on misconfigured SPF/DMARC, MFA fatigue, browser-in-browser pretexts, OAuth consent grant abuse against M365 and Workspace tenants.
How an enterprise engagement runs ,
A written plan before traffic flows, four execution phases that chain findings across surfaces, and a consolidated report with a free re-test on the same scope. No phase ends until its evidence is in the report.
Enumerate the surfaces in scope, the business-critical assets behind each, the attacker objectives that matter to the board, and the rules of engagement. Output: a written engagement plan with named bug classes per pillar, signed off by your security lead before a single packet flows.
Subdomain enumeration, certificate-transparency mining, leaked-credential checks across paste sites and breach corpora, exposed-admin discovery on edge devices and SaaS tenants. The inventory and any initial footholds are handed cleanly to the internal phase.
Assumed-breach foothold on a workstation segment, then Active Directory path discovery, Kerberoasting, ADCS ESC8, unconstrained delegation, BloodHound graphs to Domain Admin. Lateral movement is chained against business assets, not isolated as a finding count.
The same pod pivots from on-prem identity into AWS, Azure, and GCP control planes, then into the web and API attack surface above them. Findings chain across, phish to AD to cloud to app, and are written as one kill chain, not four bullet lists.
One consolidated report with chained-finding narratives, code-level remediation, CREST-mapped severity, and PoC artifacts your dev team can replay. A free re-test on the same scope once fixes land, with a delta report for the auditor.
What we review —
Each surface is read for intent against the live config, then probed by hand for the chain that survived the policy. Vendor-specific guidance for ASA, Cisco IOS, Palo Alto Networks, FortiGate, Check Point, pfSense, and Juniper SRX.
Any/any ranges, shadowed and preempted rules, dead policy, stale comments, source/destination group drift, NAT translation chains, log-scope coverage, asymmetric-routing exposure.
Zone map and blast-radius from each zone, redundant placement, fail-open vs fail-close behaviour, management-plane isolation, jump-host enforcement, out-of-band path scope.
SSH cipher and KEX policy, HTTPS-mgmt scope, SNMPv2 community strings, TFTP and HTTP exposure, AAA · RADIUS · TACACS+ scope, two-factor on admin paths, session-timeout policy.
OS train versus vendor advisories, IPS signature freshness, AV pattern coverage, EOL-hardware risk, planned-upgrade gaps, vulnerability-feed staleness.
What we test
Each surface scoped against named bug classes. We chain across them. A Workload Identity token misuse can land in BigQuery, exfiltrating data tagged for VPC Service Controls.
VPC Service Controls bypass, firewall egress oversight, Identity-Aware Proxy misconfig, Cloud NAT exposure. Lateral movement chained inside the perimeter.
Service account impersonation via iam.serviceAccounts.actAs, allow-policy plus deny-policy interaction gaps, Organization policy drift, custom-role privilege creep.
Node pool escape via privileged pod, GKE Autopilot constraint bypass, Workload Identity binding abuse, metadata API exposure inside the pod.
Cloud Storage bucket IAM, signed-URL leakage, Secret Manager accessor scope, Cloud KMS key policy bypass, Firestore unauth read.
What we test
IoT is a stack, a board, a firmware, a radio, a mobile companion, a backend the device dials home to. Each layer is reviewed by hand against the real attack surface, in the protocols and tools your team ships in.
Enclosure opened. Test points probed with a logic analyzer. Debug interfaces brought up under OpenOCD / J-Link. SPI flash desoldered or read in-circuit, then dumped. Boot ROM and bootloader behaviour exercised against fault-injection where in scope.
Image carved with binwalk, root filesystem mounted, init scripts and busybox binaries reviewed by hand. Hardcoded API tokens, TLS keys, and PEM blobs extracted. Weak secure-boot anchors and unsigned bootloader-stage upgrades reported with the patch path.
Packet captures with HackRF, Ubertooth, RFCat. BLE GATT walked for unauth read / write. Pairing bypass under Just Works mishandling. Zigbee key-establishment replay. LoRa join-accept tampering. Wi-Fi WPS and EAP downgrade where the device exposes them.
Companion app pulled from the store, instrumented under Frida, the pairing flow and deeplink handlers walked end to end. Hardcoded device secrets, weak certificate pinning to the cloud, and OAuth-state mishandling in account-linking flows.
Broker authentication walked for client-id reuse and topic over-subscription. Topic tree walked from a low-priv account for tenant isolation gaps. OTA update channel tested for unsigned image acceptance, downgrade attacks, and roll-back to a vulnerable build.
Local admin UI, mDNS / SSDP service, and any cloud portal tested for default credentials, CSRF on state-changing endpoints, exposed /debug or /diag routes, command injection in network-config forms, and authentication-bypass via unauth API parity.
on record ,
CREST is the standard for offensive security execution. CERT-In, SOC 2 Type II, and ISO/IEC 27001 cover how SecureLayer7 handles your cluster evidence, Kubernetes artefacts, and your engagement record.
Accredited company & testers
Empanelled auditor
Independently audited
Information Security Management
Mapped to audit requirements across
Scope ,
Most cluster reviews stop at isolated findings. We chain control plane exposure, workload breakout, identity and secrets, and supply-chain trust in one engagement, mapped to your topology and exercised manually against the bug classes that appear once an attacker already has a foothold.
kube-apiserver anonymous-auth, etcd 2379 exposure, kubelet 10250 unauth, scheduler / controller-manager metrics leak, admission-webhook race, audit-policy gap, /healthz info disclosure, in-cluster API server SSRF.
Privileged-container escape, hostPath / hostNetwork / hostPID abuse, SYS_ADMIN & NET_RAW capability misuse, missing seccomp / AppArmor, PodSecurityStandards bypass, NetworkPolicy default-allow, sidecar trust-boundary leak, ConfigMap secrets leak.
ServiceAccount token theft and replay, escalate / impersonate / bind verb chaining, over-scoped ClusterRoleBinding, projected-token reuse across namespaces, IRSA / Workload-Identity confusion, External-Secrets misconfig, kubectl auth can-i blind spots.
Mutating-webhook abuse, unsigned-image admission, ImagePullSecret leak, base-image typosquat, SBOM tampering, GitOps repo and pipeline takeover, Helm-chart values injection, registry-credential reuse across clusters.
What we cover
Mobile is a stack: the binary, the runtime, the IPC, the network, the backend it actually calls. We test each layer in the language and toolchain your team ships in.
Keychain access-control mishandling, ATS bypass via NSAllowsArbitraryLoads, URL-scheme hijack, Universal Links validation gaps, App Group leakage, jailbreak-detection bypass under Frida.
Exported-activity hijack, intent injection, ContentProvider authority abuse, insecure SharedPreferences, Keystore mishandling, root-detection bypass, Smali patch under MOBSF / objection.
JS-bridge exposure, deserialised props from native to JS, asset bundle tampering, hot-reload server abuse on dev builds shipped to prod, Flutter snapshot reverse-engineering.
addJavascriptInterface RCE, file:// URI access from a remote origin, mixed content, intent:// scheme abuse, JS-to-native bridge auth gaps, cookie scope leakage between WebView and host app.
Android intents, iOS URL schemes, Universal Links, App Links, broadcast receivers, deep-link OAuth-state mishandling, activity-stack tampering, share-sheet payload injection.
REST and GraphQL endpoints called only by the mobile client, broken object-level authZ, mass assignment, mobile-only auth flows, refresh-token rotation gaps, abuse of mobile-specific headers as trust signals.
Third-party SDKs (analytics, payments, in-app messaging) audited for over-permission and data exfiltration. JNI / NDK native libs reviewed for buffer overflow, format-string, use-after-free, and unsafe FFI boundaries.
Mach-O / DEX / Smali disassembly under IDA, Ghidra, jadx. Hardcoded API keys, signing material, and crypto secrets extracted from the binary. Control-flow obfuscation and tamper-detection tested against real bypasses, not vendor claims.
What we test
Each boundary gets a manual, threat-modelled review against its real attack surface, perimeter, AD-joined estate, wireless edge, and the devices that route between them. Intensity tunes per scope.
Subdomain takeover, exposed RDP/SSH/SMB, vendor-portal SSRF, VPN-appliance CVE chains, perimeter mail-relay abuse, exposed git/CI endpoints, ASN-wide cert-transparency mining, and credential-leak correlation against the perimeter login surface.
SMB-signing NTLM relay, kerberoasting and AS-REProasting, mitm6 + WPAD coercion, ADCS ESC1–ESC8 abuse, LAPS-password reuse, Group Policy preference passwords, BloodHound-mapped attack paths to Domain Admin and Tier-0 hosts.
WPA2/WPA3 handshake capture and crack, EAP-TLS cert-pinning bypass, PEAP/MSCHAPv2 relay, rogue-AP and KARMA, 802.1X NAC bypass via MAC spoof, guest-network pivot, captive-portal credential harvest.
Exposed management interfaces (SSH/HTTPS/SNMP), default and stale credentials, ACL bypass via spoofed source, SNMPv2 community brute-force, IPv6-routing override, firmware-CVE pivot to lateral access.
What we test on-demand
Web, mobile, API, network, internal, brought under one delivery model. You don’t have to pick a discipline before you scope; we right-size the team and the depth to your target.
Single SPA, multi-tenant, e-commerce, internal portal. Auth flows, RBAC, business logic, payment-stage integrity, manually walked, not scanner-rubber-stamped.
OWASP API Top 10 mapped. BOLA, mass assignment, broken object-level authZ, rate-limit bypass, schema introspection abuse, refresh-token rotation gaps.
Native, hybrid, and cross-platform builds. Static + runtime instrumentation under Frida, deeplink hijack, Keychain / Keystore mishandling, addJavascriptInterface RCE.
Service enumeration, exposed admin panels, weak auth chains, default-credential pivots, RCE chains into the application stack, walked by hand, not just nmap output.
VPN-gated, SSO-fronted, role-segmented apps. Same auth depth as external surfaces, mapped to your insider threat model and least-privilege contract.
AWS, Azure, GCP, Kubernetes, IAM mishandling, managed-identity over-scope, IMDSv1 SSRF, pod-to-host RBAC bypass under your real workload identity model.
What the crew brings
These are the surfaces SecureLayer7's red team operates across. Black Box engagements run all seven. Assumed Breach and Threat-Led include the digital surfaces by default; physical, social, and wireless are scoped in when the engagement narrative requires them, not bolted on as upsells.
External reconnaissance, internet-facing service exploitation, then internal east-west pivoting once foothold is established. Mapped to ATT&CK Initial Access + Lateral Movement.
Active Directory trust abuse, Kerberoasting, delegation paths, cloud-IAM lateral movement, credential theft chains, and the misconfigurations checklists never reach.
Chained business-logic exploits, authentication confusion, multi-step flow abuse, and the auth boundaries scanners cannot model. Web, API, and SaaS-tenant boundaries.
AWS / Azure / GCP IAM misuse, metadata-service abuse, secrets-manager pivoting, cross-account trust paths, and SaaS-tenant trust escalation. Scoped to the cloud surface area you actually run.
On-site reconnaissance, tailgating, badge cloning, lock bypass, and covert-access device placement on a wired network drop. Once inside, the digital crew picks up from the physical foothold. Engagement is consent-bounded, recorded, and de-escalated on first detection by your team.
Spear phishing, vishing, pretexting against helpdesk / IT support, MFA-fatigue prompts, and supply-chain personas (vendors, contractors, recruiters). Targets the humans your security awareness training assumes are trained.
Rogue access points, evil-twin captive portals, EAP-credential capture, and segmentation-bypass paths from guest VLAN to corporate. Tested at your physical perimeter and inside acquired tenants.
What we test
Every layer of the SAP landscape gets a manual, threat-modelled review against its real attack surface, kernel, database, presentation, transport, custom code, and authorization. Intensity tunes per scope.
RECON-class unauth user creation (CVE-2020-6287 family), ICMAD memory corruption (CVE-2022-22536 family), authority-object bypass against S_TCODE / S_DEVELOP / S_RFC, ABAP code injection in dynamic CALL TRANSACTION and EXECUTE IMMEDIATELY, transport-request abuse, message server unauthenticated registration.
SQL injection in custom procedures, SYSTEM privilege escalation, cross-schema access via shared CDS views, _SYS_REPO mis-grants, encryption-at-rest verification, audit-policy gaps, XSA tenant boundary bypass, replication-route abuse on system replication.
Segregation-of-duties chains that move money, vendor master maintenance + invoice posting + payment release in one user; F110 payment program abuse via spoofed bank master; MIRO three-way-match bypass; goods-receipt reversal-and-repost flows that paper over inventory shrink.
OData service authorisation gaps, CSRF token reuse across sessions, UI5 mock-data leakage, Launchpad role-hiding bypass, Gateway service /sap/opu/odata/ exposure, web-dispatcher header-rewrite abuse, BSP application chained-XSS to ABAP RFC.
Gateway ACL bypass (reginfo / secinfo gaps), unauthenticated RFC server registration, message-server SXM access, SAProuter route-permission leakage, DIAG / RFC protocol replay where TLS isn't terminated, exposure of internal load-balancer behind public listener.
Z-program authority-check omissions, hardcoded SAP* / DDIC credentials in customer transports, ABAP open-SQL injection in customer namespaces, role/profile drift between DEV and PROD landscapes, derived-role inheritance abuse, GRC mitigations that whitelist the chain rather than break it.
What we harden
Each tier is brought to a defensible baseline against its real attack surface, then probed by hand for the path that survived. Intensity tunes per scope.
Ubuntu · Debian · RHEL · CentOS · Alma · Rocky. Kernel sysctl, ssh key & cipher policy, sudo & PAM, /tmp & /var noexec, fail2ban, auditd, AppArmor / SELinux, package-manager hygiene.
Server 2016 / 2019 / 2022. SMB signing, LSA & credential guard, RDP NLA, GPO baseline (CIS / STIG), AppLocker / WDAC, Defender ASR, audit policy, scheduled-task review.
Apache · Nginx · IIS · LiteSpeed. server-tokens, mod_status, request limits, TLS / HSTS / OCSP, ModSecurity rule set, .htaccess audit, PHP-FPM pool isolation, fastcgi cache scope.
MySQL · MariaDB · Postgres · MSSQL · Mongo · Redis. Default-creds review, least-privilege grants, network ACLs, audit logging, backup encryption at rest, secrets-manager binding, replication-account scope.
on record ,
CREST accredits our organisation and every tester on your engagement. CERT-In empanelment plus SOC 2 Type II and ISO/IEC 27001 controls govern how source artefacts, secrets, and engagement records are stored, accessed, and handed back.
Mapped to audit requirements across
Scope ,
Auditors who still ship production code in these stacks review yours by hand. We throttle depth based on trust boundaries and data sensitivity, with authentication surfaces, deserialisation paths, parsers, query builders, and IPC earning mandatory deep dives every time.
Jackson polymorphic-typing gadgets (CVE-2017-7525 lineage), Spring SpEL / EL injection, JNDI / Log4Shell-style lookups, JDBC string concatenation, lock-order races on shared state, Servlet filter-bypass chains.
Data races on shared maps and channels, `unsafe.Pointer` arithmetic across cgo bridges, raw-string SQL in `database/sql`, JWT `alg=none` acceptance, `text/template` over `html/template`, dependency-confusion in `go.mod` proxies.
`pickle.loads` on user input, SSTI in Jinja / Mako templates, `eval` / `exec` reachable from request handlers, f-string SQL interpolation, `yaml.load` without `SafeLoader`, `subprocess(shell=True)` argument injection, path traversal via `os.path.join`.
Prototype pollution through `lodash.merge` / `Object.assign`, ReDoS via catastrophic backtracking on user-controlled patterns, `child_process.exec` argument injection, JWT `alg` confusion, sandbox escape in `vm` / `node-serialize` patterns.
Buffer overflows, format-string bugs, use-after-free, double-free, OOB reads, integer / sign-conversion overflow in parsers and codecs · Rust `unsafe` audited for aliasing and invariant breaks across FFI boundaries.
LFI / RFI through `include` paths, object injection via `unserialize`, PHAR deserialisation gadgets, type-juggling (`==`) auth bypass, raw-SQL in legacy modules, `extract()` variable overwrites in framework caches.
Mass assignment through `permit` gaps, `YAML.load` on user input, dynamic dispatch via `send` / `public_send`, raw-SQL in scope chains and `find_by_sql`, `Marshal.load` in cache stores, `constantize` on user input.
Telecom security ,
Attacks on telecom rarely stay in one layer, they cross signaling, core elements, and access edges. We scope around those boundaries so findings map to engineering work with clear risk, not scattered vulnerabilities on a spreadsheet.
Since 2012 we’ve tested operator-adjacent systems alongside enterprise apps and infrastructure, experience we use to model realistic paths, rank impact, and write remediation network teams can ship.
Reference scope: core, SS7/SIGTRAN interconnect, signaling trunk, RAN/LTE access
Coverage ,
We group telecom work into four themes, signaling, core stack, access edge, and enterprise voice, so planning stays readable. Pick what matches your risk focus; we tailor tasks inside each theme.
SS7 and SIGTRAN exposure, interconnect abuse paths, and protocol-level risks across peering, modeled for real operator handoffs, not generic scanning.
GSM/3G core and LTE architecture reviews, segmentation and NE configuration, including MBSS-style baselines, so paths into HLR, SMSC-class systems and peers are explicit.
Air-interface penetration testing and SIM / USIM application security, where bypass, cloning, and misuse scenarios often show up before they touch core nodes.
IP-PBX, PSTN, and switching-adjacent environments reviewed for configuration drift, trunk abuse, and paths into the wider org.
Adjacent services ,
Pick the surface that matches your wider risk story.
What we test
Each runtime gets a manual reverse-engineering pass against its real attack surface, binary on disk, process in memory, IPC channels, and the backend it pairs with. Intensity tunes per scope.
DLL search-order hijacking, COM hijacking, Authenticode bypass, named-pipe and RPC ACL abuse, service / scheduled-task permission writes, registry hijacks, AppLocker / WDAC bypass, signed-installer write-paths to NT AUTHORITY\SYSTEM.
dnSpy / ILSpy round-trip, hardcoded keys and connection strings in /resources, BinaryFormatter and ObjectStateFormatter deserialization gadgets, Json.NET TypeNameHandling abuse, reflection bypass, Strong-Name forgery, ClickOnce manifest tampering.
JD-GUI / CFR decompile, signed-JAR replacement, classpath shadowing, Spring / Beanshell injection, JMX management exposure, Java RMI deserialization, native-library (JNI) hijack, hardcoded JDBC credentials in /META-INF.
DYLD_INSERT_LIBRARIES, weak-dylib hijack, codesign and hardened-runtime bypass, XPC service ACL abuse, TCC / privacy-prompt evasion, Keychain ACL misuse, sandbox escape via privileged helpers (SMJobBless, installerd).
LD_PRELOAD on SUID binaries, RPATH / RUNPATH abuse, .got and .plt write paths, systemd unit override, capability misuse, world-writable shared libraries, D-Bus policy bypass, namespace and cgroup escape.
ASAR unpack, nodeIntegration leak across renderer-to-main IPC, contextIsolation bypass, custom-protocol handler abuse, autoUpdate signature bypass, Chromium-extension prototype pollution into Node, hardcoded tokens lifted from app.asar.
What we test ,
Each layer gets a manual, threat-modelled review against its real attack surface, signalling, media, infrastructure, and the trunk edge. Intensity tunes per scope.
REGISTER hijacking, INVITE flooding, BYE/CANCEL race conditions, SDP rewriting, ALG bypass, digest-auth replay, contact-header rewrite, and presence-leak via SUBSCRIBE/NOTIFY.
RTP eavesdropping, ZRTP/SRTP downgrade, DTMF injection, codec confusion, replay across the media stream, comfort-noise abuse, and media-relay bypass.
Asterisk AMI/CLI exposure, FreeSWITCH event-socket misconfiguration, Cisco CUCM AXL credential leak, dialplan logic abuse, voicemail PIN brute force, IVR fingerprinting and option escape.
SBC peering misconfiguration, voice-VLAN hopping, SIP trunk toll fraud, IAX2 brute force, NAT/ALG traversal abuse, peer-spoofed call replays, and geo-routing rule override.
What we test
Each layer of your wireless estate is reviewed by hand against its real attack surface, corporate Wi-Fi, 802.1X / RADIUS, the rogue-AP boundary, and the BYOD / guest edge. Intensity tunes per scope.
PMKID capture via hcxdumptool, 4-way handshake collection under deauth, offline crack with hashcat, WPS PIN brute force (Pixie Dust), WPA3 SAE downgrade (Dragonblood), MFP / 802.11w not enforced, PMF-not-required client trap.
Server-cert validation off on clients, PEAP outer-tunnel bypass, EAP-MSCHAPv2 cleartext relay, EAP-TLS cert-pinning gaps, RADIUS shared-secret re-use across SSIDs, MAC-RADIUS bypass, NPS / FreeRADIUS misconfig.
Same-SSID rogue stood up with hostapd-mana, broadcast-PROBE-RESPONSE KARMA, captive-portal harvest of corporate creds, MAC randomization detection bypass, Wireless IDS / WIPS evasion, deauth flood under MFP-off.
Captive-portal UAM bypass, guest-to-corporate VLAN escape via DHCP / IPv6 abuse, NAC posture-check bypass, MDM-issued client cert lift, BYOD MAC-allowlist spoof, Wi-Fi Direct lateral pivot, hidden-SSID probe-leak reveal.
What we test
These are the surfaces SecureLayer7's app-sec practice operates across. Every surface in scope by default; intensity tunes per engagement.
Login bypass, session fixation, token prediction, password reset flaws, MFA weaknesses, federation bypass, OAuth/OIDC misconfig.
IDOR, broken object-level auth, privilege escalation, multi-tenant bleed, role/scope-checking gaps in API + UI.
Price manipulation, workflow abuse, state-machine bypass, race conditions, the chained exploits unique to your application.
REST + GraphQL, BOLA, mass assignment, query-cost, schema introspection. gRPC, protobuf field abuse, reflection leaks, streaming-method DoS, mTLS misconfig. MQTT, broker auth, ACL bypass, retained-message exposure, topic-injection across IoT/real-time brokers.
Local storage exposure, key management, encryption-at-rest verification, transit ciphers, certificate pinning.
SQLi, XXE, SSTI, command injection, deserialization, prototype pollution, tested manually with chained exploits, not just signatures.
Exposed admin panels, misconfigured headers, leaked secrets in JS bundles, third-party SDK exposure, server-side config drift.
Solidity audit (reentrancy, integer over/underflow, access-control gaps, unchecked external calls, gas-griefing, oracle manipulation), EIP-712 signature reuse, wallet-connect phishing flows, multicall + delegatecall abuse, ERC-20/ERC-721 approve-and-drain, bridge replay, MEV / front-running on dApp UX.
What we test
Every AWS pentest is threat-modelled to your Org structure, IAM graph, and account topology, then exercised by hand against named bug classes across identity, compute, data, and posture controls.
IAM role chaining, sts:AssumeRole over-scope, IAM Identity Center / SSO permission-set drift, Cognito user-pool ID-token confusion, instance-profile credential reuse, federated-role trust-policy bypass, IAM Access Analyzer blind spots, root-account fallback paths.
EC2 IMDSv2-bypass via SSRF, Lambda execution-role over-scope, EKS service-account abuse, ECS task-role chaining, Fargate trust-policy reuse, EBS snapshot exfil, AMI-based persistence, Systems Manager Session Manager impersonation.
S3 bucket-policy bypass, Object Ownership confusion, KMS key-policy misuse, Secrets Manager rotation drift, RDS IAM-auth gap, DynamoDB stream replay, EBS snapshot public exposure, Glue catalog data leakage.
CloudTrail trail-tampering, GuardDuty finding suppression, AWS Config rule drift, AWS Organizations SCP gaps, CloudWatch log-group ACL bypass, EventBridge rule reuse, Audit Manager evidence drift, IAM Access Analyzer false-clean.
What we test
Each provider gets a manual, threat-modelled review against its real attack surface, control plane, identity, network, and workload. Intensity tunes per scope.
IMDSv1 SSRF, IAM role chaining, public S3 enumeration, Lambda over-privilege, EKS cluster-role abuse, KMS key-policy misuse, Cognito user-pool misconfig, Secrets Manager exposure.
Managed identity over-scope, Storage Account SAS leak, Function App env exposure, AKS pod-identity abuse, Key Vault access policy bypass, Azure AD application consent, Logic App secret reuse.
Workload-identity confusion, service-account impersonation, Cloud Run scope abuse, GKE node pool escape, Secret Manager IAM gaps, Cloud Storage bucket policy bypass, Cloud Functions trigger replay.
Pod escape via privileged container, RBAC bypass, etcd exposure, kubelet API abuse, sidecar/init container attack paths, NetworkPolicy gaps, admission-controller bypass, ServiceAccount token theft.
What we cover
Each surface scoped against named bug classes, not generic checklists. One pod chains findings across surfaces, so a phishing foothold can follow into AD and then into the cloud on the same SOW.
Subdomain takeover, exposed admin panels on edge devices, default credentials on appliances, leaked credentials in paste sites and code repos. Inventory feeds the internal phase.
SMB relay, Kerberoasting, NTLM hash capture, lateral movement via WMI and PsExec, unconstrained delegation paths. Assumed-breach foothold, then chain to identity.
ADCS ESC1–ESC8 abuse, constrained delegation, DCSync, BloodHound paths to Domain Admin, Entra ID conditional-access bypass. Identity is treated as its own surface, not a footnote.
IMDSv1 SSRF, IAM role-chain abuse, S3 enumeration and policy gaps, Lambda over-privilege, AKS pod-identity abuse, GCP service-account impersonation across projects.
Authentication bypass, IDOR, business-logic flaws, SSRF into cloud metadata, deserialization, GraphQL introspection abuse, broken object-property authorization on REST.
Sender spoofing on misconfigured SPF/DMARC, MFA fatigue, browser-in-browser pretexts, OAuth consent grant abuse against M365 and Workspace tenants.
How an enterprise engagement runs ,
A written plan before traffic flows, four execution phases that chain findings across surfaces, and a consolidated report with a free re-test on the same scope. No phase ends until its evidence is in the report.
Enumerate the surfaces in scope, the business-critical assets behind each, the attacker objectives that matter to the board, and the rules of engagement. Output: a written engagement plan with named bug classes per pillar, signed off by your security lead before a single packet flows.
Subdomain enumeration, certificate-transparency mining, leaked-credential checks across paste sites and breach corpora, exposed-admin discovery on edge devices and SaaS tenants. The inventory and any initial footholds are handed cleanly to the internal phase.
Assumed-breach foothold on a workstation segment, then Active Directory path discovery, Kerberoasting, ADCS ESC8, unconstrained delegation, BloodHound graphs to Domain Admin. Lateral movement is chained against business assets, not isolated as a finding count.
The same pod pivots from on-prem identity into AWS, Azure, and GCP control planes, then into the web and API attack surface above them. Findings chain across, phish to AD to cloud to app, and are written as one kill chain, not four bullet lists.
One consolidated report with chained-finding narratives, code-level remediation, CREST-mapped severity, and PoC artifacts your dev team can replay. A free re-test on the same scope once fixes land, with a delta report for the auditor.
What we review
Each surface is read for intent against the live config, then probed by hand for the chain that survived the policy. Every finding ships with the exact rule, the proof it passes traffic, and the fix. Vendor-specific for ASA, Cisco IOS, Palo Alto Networks, FortiGate, Check Point, pfSense, and Juniper SRX.
Any/any ranges, shadowed and preempted rules, dead policy, stale comments, source/destination group drift, NAT translation chains, log-scope coverage, asymmetric-routing exposure.
Zone map and blast-radius from each zone, redundant placement, fail-open vs fail-close behaviour, management-plane isolation, jump-host enforcement, out-of-band path scope.
SSH cipher and KEX policy, HTTPS-mgmt scope, SNMPv2 community strings, TFTP and HTTP exposure, AAA · RADIUS · TACACS+ scope, two-factor on admin paths, session-timeout policy.
OS train versus vendor advisories, IPS signature freshness and drift, AV pattern coverage, SSL-inspection coverage and decryption-bypass gaps, TLS 1.3 visibility, EOL-hardware risk, planned-upgrade gaps, vulnerability-feed staleness.
What we test
Each surface scoped against named bug classes. We chain across them. A Workload Identity token misuse can land in BigQuery, exfiltrating data tagged for VPC Service Controls.
VPC Service Controls bypass, firewall egress oversight, Identity-Aware Proxy misconfig, Cloud NAT exposure. Lateral movement chained inside the perimeter.
Service account impersonation via iam.serviceAccounts.actAs, allow-policy plus deny-policy interaction gaps, Organization policy drift, custom-role privilege creep.
Node pool escape via privileged pod, GKE Autopilot constraint bypass, Workload Identity binding abuse, metadata API exposure inside the pod.
Cloud Storage bucket IAM, signed-URL leakage, Secret Manager accessor scope, Cloud KMS key policy bypass, Firestore unauth read.
What we test
IoT is a stack, a board, a firmware, a radio, a mobile companion, a backend the device dials home to. Each layer is reviewed by hand against the real attack surface, in the protocols and tools your team ships in.
Enclosure opened. Test points probed with a logic analyzer. Debug interfaces brought up under OpenOCD / J-Link. SPI flash desoldered or read in-circuit, then dumped. Boot ROM and bootloader behaviour exercised against fault-injection where in scope.
Image carved with binwalk, root filesystem mounted, init scripts and busybox binaries reviewed by hand. Hardcoded API tokens, TLS keys, and PEM blobs extracted. Weak secure-boot anchors and unsigned bootloader-stage upgrades reported with the patch path.
Packet captures with HackRF, Ubertooth, RFCat. BLE GATT walked for unauth read / write. Pairing bypass under Just Works mishandling. Zigbee key-establishment replay. LoRa join-accept tampering. Wi-Fi WPS and EAP downgrade where the device exposes them.
Companion app pulled from the store, instrumented under Frida, the pairing flow and deeplink handlers walked end to end. Hardcoded device secrets, weak certificate pinning to the cloud, and OAuth-state mishandling in account-linking flows.
Broker authentication walked for client-id reuse and topic over-subscription. Topic tree walked from a low-priv account for tenant isolation gaps. OTA update channel tested for unsigned image acceptance, downgrade attacks, and roll-back to a vulnerable build.
Local admin UI, mDNS / SSDP service, and any cloud portal tested for default credentials, CSRF on state-changing endpoints, exposed /debug or /diag routes, command injection in network-config forms, and authentication-bypass via unauth API parity.
on record ,
CREST is the standard for offensive security execution. CERT-In, SOC 2 Type II, and ISO/IEC 27001 cover how SecureLayer7 handles your cluster evidence, Kubernetes artefacts, and your engagement record.
Accredited company & testers
Empanelled auditor
Independently audited
Information Security Management
Mapped to audit requirements across
Scope ,
Most cluster reviews stop at isolated findings. We chain control plane exposure, workload breakout, identity and secrets, and supply-chain trust in one engagement, mapped to your topology and exercised manually against the bug classes that appear once an attacker already has a foothold.
kube-apiserver anonymous-auth, etcd 2379 exposure, kubelet 10250 unauth, scheduler / controller-manager metrics leak, admission-webhook race, audit-policy gap, /healthz info disclosure, in-cluster API server SSRF.
Privileged-container escape, hostPath / hostNetwork / hostPID abuse, SYS_ADMIN & NET_RAW capability misuse, missing seccomp / AppArmor, PodSecurityStandards bypass, NetworkPolicy default-allow, sidecar trust-boundary leak, ConfigMap secrets leak.
ServiceAccount token theft and replay, escalate / impersonate / bind verb chaining, over-scoped ClusterRoleBinding, projected-token reuse across namespaces, IRSA / Workload-Identity confusion, External-Secrets misconfig, kubectl auth can-i blind spots.
Mutating-webhook abuse, unsigned-image admission, ImagePullSecret leak, base-image typosquat, SBOM tampering, GitOps repo and pipeline takeover, Helm-chart values injection, registry-credential reuse across clusters.
What we cover
Mobile is a stack: the binary, the runtime, the IPC, the network, the backend it actually calls. We test each layer in the language and toolchain your team ships in.
Keychain access-control mishandling, ATS bypass via NSAllowsArbitraryLoads, URL-scheme hijack, Universal Links validation gaps, App Group leakage, jailbreak-detection bypass under Frida.
Exported-activity hijack, intent injection, ContentProvider authority abuse, insecure SharedPreferences, Keystore mishandling, root-detection bypass, Smali patch under MOBSF / objection.
JS-bridge exposure, deserialised props from native to JS, asset bundle tampering, hot-reload server abuse on dev builds shipped to prod, Flutter snapshot reverse-engineering.
addJavascriptInterface RCE, file:// URI access from a remote origin, mixed content, intent:// scheme abuse, JS-to-native bridge auth gaps, cookie scope leakage between WebView and host app.
Android intents, iOS URL schemes, Universal Links, App Links, broadcast receivers, deep-link OAuth-state mishandling, activity-stack tampering, share-sheet payload injection.
REST and GraphQL endpoints called only by the mobile client, broken object-level authZ, mass assignment, mobile-only auth flows, refresh-token rotation gaps, abuse of mobile-specific headers as trust signals.
Third-party SDKs (analytics, payments, in-app messaging) audited for over-permission and data exfiltration. JNI / NDK native libs reviewed for buffer overflow, format-string, use-after-free, and unsafe FFI boundaries.
Mach-O / DEX / Smali disassembly under IDA, Ghidra, jadx. Hardcoded API keys, signing material, and crypto secrets extracted from the binary. Control-flow obfuscation and tamper-detection tested against real bypasses, not vendor claims.
What we test
Each boundary gets a manual, threat-modelled review against its real attack surface, perimeter, AD-joined estate, wireless edge, and the devices that route between them. Intensity tunes per scope.
Subdomain takeover, exposed RDP/SSH/SMB, vendor-portal SSRF, VPN-appliance CVE chains, perimeter mail-relay abuse, exposed git/CI endpoints, ASN-wide cert-transparency mining, and credential-leak correlation against the perimeter login surface.
SMB-signing NTLM relay, kerberoasting and AS-REProasting, mitm6 + WPAD coercion, ADCS ESC1–ESC8 abuse, LAPS-password reuse, Group Policy preference passwords, BloodHound-mapped attack paths to Domain Admin and Tier-0 hosts.
WPA2/WPA3 handshake capture and crack, EAP-TLS cert-pinning bypass, PEAP/MSCHAPv2 relay, rogue-AP and KARMA, 802.1X NAC bypass via MAC spoof, guest-network pivot, captive-portal credential harvest.
Exposed management interfaces (SSH/HTTPS/SNMP), default and stale credentials, ACL bypass via spoofed source, SNMPv2 community brute-force, IPv6-routing override, firmware-CVE pivot to lateral access.
What we test on-demand
Web, mobile, API, network, internal, brought under one delivery model. You don’t have to pick a discipline before you scope; we right-size the team and the depth to your target.
Single SPA, multi-tenant, e-commerce, internal portal. Auth flows, RBAC, business logic, payment-stage integrity, manually walked, not scanner-rubber-stamped.
OWASP API Top 10 mapped. BOLA, mass assignment, broken object-level authZ, rate-limit bypass, schema introspection abuse, refresh-token rotation gaps.
Native, hybrid, and cross-platform builds. Static + runtime instrumentation under Frida, deeplink hijack, Keychain / Keystore mishandling, addJavascriptInterface RCE.
Service enumeration, exposed admin panels, weak auth chains, default-credential pivots, RCE chains into the application stack, walked by hand, not just nmap output.
VPN-gated, SSO-fronted, role-segmented apps. Same auth depth as external surfaces, mapped to your insider threat model and least-privilege contract.
AWS, Azure, GCP, Kubernetes, IAM mishandling, managed-identity over-scope, IMDSv1 SSRF, pod-to-host RBAC bypass under your real workload identity model.
What the crew brings
These are the surfaces SecureLayer7's red team operates across. Black Box engagements run all seven. Assumed Breach and Threat-Led include the digital surfaces by default; physical, social, and wireless are scoped in when the engagement narrative requires them, not bolted on as upsells.
External reconnaissance, internet-facing service exploitation, then internal east-west pivoting once foothold is established. Mapped to ATT&CK Initial Access + Lateral Movement.
Active Directory trust abuse, Kerberoasting, delegation paths, cloud-IAM lateral movement, credential theft chains, and the misconfigurations checklists never reach.
Chained business-logic exploits, authentication confusion, multi-step flow abuse, and the auth boundaries scanners cannot model. Web, API, and SaaS-tenant boundaries.
AWS / Azure / GCP IAM misuse, metadata-service abuse, secrets-manager pivoting, cross-account trust paths, and SaaS-tenant trust escalation. Scoped to the cloud surface area you actually run.
On-site reconnaissance, tailgating, badge cloning, lock bypass, and covert-access device placement on a wired network drop. Once inside, the digital crew picks up from the physical foothold. Engagement is consent-bounded, recorded, and de-escalated on first detection by your team.
Spear phishing, vishing, pretexting against helpdesk / IT support, MFA-fatigue prompts, and supply-chain personas (vendors, contractors, recruiters). Targets the humans your security awareness training assumes are trained.
Rogue access points, evil-twin captive portals, EAP-credential capture, and segmentation-bypass paths from guest VLAN to corporate. Tested at your physical perimeter and inside acquired tenants.
What we test
Every layer of the SAP landscape gets a manual, threat-modelled review against its real attack surface, kernel, database, presentation, transport, custom code, and authorization. Intensity tunes per scope.
RECON-class unauth user creation (CVE-2020-6287 family), ICMAD memory corruption (CVE-2022-22536 family), authority-object bypass against S_TCODE / S_DEVELOP / S_RFC, ABAP code injection in dynamic CALL TRANSACTION and EXECUTE IMMEDIATELY, transport-request abuse, message server unauthenticated registration.
SQL injection in custom procedures, SYSTEM privilege escalation, cross-schema access via shared CDS views, _SYS_REPO mis-grants, encryption-at-rest verification, audit-policy gaps, XSA tenant boundary bypass, replication-route abuse on system replication.
Segregation-of-duties chains that move money, vendor master maintenance + invoice posting + payment release in one user; F110 payment program abuse via spoofed bank master; MIRO three-way-match bypass; goods-receipt reversal-and-repost flows that paper over inventory shrink.
OData service authorisation gaps, CSRF token reuse across sessions, UI5 mock-data leakage, Launchpad role-hiding bypass, Gateway service /sap/opu/odata/ exposure, web-dispatcher header-rewrite abuse, BSP application chained-XSS to ABAP RFC.
Gateway ACL bypass (reginfo / secinfo gaps), unauthenticated RFC server registration, message-server SXM access, SAProuter route-permission leakage, DIAG / RFC protocol replay where TLS isn't terminated, exposure of internal load-balancer behind public listener.
Z-program authority-check omissions, hardcoded SAP* / DDIC credentials in customer transports, ABAP open-SQL injection in customer namespaces, role/profile drift between DEV and PROD landscapes, derived-role inheritance abuse, GRC mitigations that whitelist the chain rather than break it.
What we harden
Each tier is brought to a defensible baseline against its real attack surface, then probed by hand for the path that survived. Intensity tunes per scope.
Ubuntu · Debian · RHEL · CentOS · Alma · Rocky. Kernel sysctl, ssh key & cipher policy, sudo & PAM, /tmp & /var noexec, fail2ban, auditd, AppArmor / SELinux, package-manager hygiene.
Server 2016 / 2019 / 2022. SMB signing, LSA & credential guard, RDP NLA, GPO baseline (CIS / STIG), AppLocker / WDAC, Defender ASR, audit policy, scheduled-task review.
Apache · Nginx · IIS · LiteSpeed. server-tokens, mod_status, request limits, TLS / HSTS / OCSP, ModSecurity rule set, .htaccess audit, PHP-FPM pool isolation, fastcgi cache scope.
MySQL · MariaDB · Postgres · MSSQL · Mongo · Redis. Default-creds review, least-privilege grants, network ACLs, audit logging, backup encryption at rest, secrets-manager binding, replication-account scope.
on record ,
CREST accredits our organisation and every tester on your engagement. CERT-In empanelment plus SOC 2 Type II and ISO/IEC 27001 controls govern how source artefacts, secrets, and engagement records are stored, accessed, and handed back.
Mapped to audit requirements across
Scope ,
Auditors who still ship production code in these stacks review yours by hand. We throttle depth based on trust boundaries and data sensitivity, with authentication surfaces, deserialisation paths, parsers, query builders, and IPC earning mandatory deep dives every time.
Jackson polymorphic-typing gadgets (CVE-2017-7525 lineage), Spring SpEL / EL injection, JNDI / Log4Shell-style lookups, JDBC string concatenation, lock-order races on shared state, Servlet filter-bypass chains.
Data races on shared maps and channels, `unsafe.Pointer` arithmetic across cgo bridges, raw-string SQL in `database/sql`, JWT `alg=none` acceptance, `text/template` over `html/template`, dependency-confusion in `go.mod` proxies.
`pickle.loads` on user input, SSTI in Jinja / Mako templates, `eval` / `exec` reachable from request handlers, f-string SQL interpolation, `yaml.load` without `SafeLoader`, `subprocess(shell=True)` argument injection, path traversal via `os.path.join`.
Prototype pollution through `lodash.merge` / `Object.assign`, ReDoS via catastrophic backtracking on user-controlled patterns, `child_process.exec` argument injection, JWT `alg` confusion, sandbox escape in `vm` / `node-serialize` patterns.
Buffer overflows, format-string bugs, use-after-free, double-free, OOB reads, integer / sign-conversion overflow in parsers and codecs · Rust `unsafe` audited for aliasing and invariant breaks across FFI boundaries.
LFI / RFI through `include` paths, object injection via `unserialize`, PHAR deserialisation gadgets, type-juggling (`==`) auth bypass, raw-SQL in legacy modules, `extract()` variable overwrites in framework caches.
Mass assignment through `permit` gaps, `YAML.load` on user input, dynamic dispatch via `send` / `public_send`, raw-SQL in scope chains and `find_by_sql`, `Marshal.load` in cache stores, `constantize` on user input.
Telecom security ,
Attacks on telecom rarely stay in one layer, they cross signaling, core elements, and access edges. We scope around those boundaries so findings map to engineering work with clear risk, not scattered vulnerabilities on a spreadsheet.
Since 2012 we’ve tested operator-adjacent systems alongside enterprise apps and infrastructure, experience we use to model realistic paths, rank impact, and write remediation network teams can ship.
Reference scope: core, SS7/SIGTRAN interconnect, signaling trunk, RAN/LTE access
Coverage ,
We group telecom work into four themes, signaling, core stack, access edge, and enterprise voice, so planning stays readable. Pick what matches your risk focus; we tailor tasks inside each theme.
SS7 and SIGTRAN exposure, interconnect abuse paths, and protocol-level risks across peering, modeled for real operator handoffs, not generic scanning.
GSM/3G core and LTE architecture reviews, segmentation and NE configuration, including MBSS-style baselines, so paths into HLR, SMSC-class systems and peers are explicit.
Air-interface penetration testing and SIM / USIM application security, where bypass, cloning, and misuse scenarios often show up before they touch core nodes.
IP-PBX, PSTN, and switching-adjacent environments reviewed for configuration drift, trunk abuse, and paths into the wider org.
Adjacent services ,
Pick the surface that matches your wider risk story.
What we test
Each runtime gets a manual reverse-engineering pass against its real attack surface, binary on disk, process in memory, IPC channels, and the backend it pairs with. Intensity tunes per scope.
DLL search-order hijacking, COM hijacking, Authenticode bypass, named-pipe and RPC ACL abuse, service / scheduled-task permission writes, registry hijacks, AppLocker / WDAC bypass, signed-installer write-paths to NT AUTHORITY\SYSTEM.
dnSpy / ILSpy round-trip, hardcoded keys and connection strings in /resources, BinaryFormatter and ObjectStateFormatter deserialization gadgets, Json.NET TypeNameHandling abuse, reflection bypass, Strong-Name forgery, ClickOnce manifest tampering.
JD-GUI / CFR decompile, signed-JAR replacement, classpath shadowing, Spring / Beanshell injection, JMX management exposure, Java RMI deserialization, native-library (JNI) hijack, hardcoded JDBC credentials in /META-INF.
DYLD_INSERT_LIBRARIES, weak-dylib hijack, codesign and hardened-runtime bypass, XPC service ACL abuse, TCC / privacy-prompt evasion, Keychain ACL misuse, sandbox escape via privileged helpers (SMJobBless, installerd).
LD_PRELOAD on SUID binaries, RPATH / RUNPATH abuse, .got and .plt write paths, systemd unit override, capability misuse, world-writable shared libraries, D-Bus policy bypass, namespace and cgroup escape.
ASAR unpack, nodeIntegration leak across renderer-to-main IPC, contextIsolation bypass, custom-protocol handler abuse, autoUpdate signature bypass, Chromium-extension prototype pollution into Node, hardcoded tokens lifted from app.asar.
What we test ,
Each layer gets a manual, threat-modelled review against its real attack surface, signalling, media, infrastructure, and the trunk edge. Intensity tunes per scope.
REGISTER hijacking, INVITE flooding, BYE/CANCEL race conditions, SDP rewriting, ALG bypass, digest-auth replay, contact-header rewrite, and presence-leak via SUBSCRIBE/NOTIFY.
RTP eavesdropping, ZRTP/SRTP downgrade, DTMF injection, codec confusion, replay across the media stream, comfort-noise abuse, and media-relay bypass.
Asterisk AMI/CLI exposure, FreeSWITCH event-socket misconfiguration, Cisco CUCM AXL credential leak, dialplan logic abuse, voicemail PIN brute force, IVR fingerprinting and option escape.
SBC peering misconfiguration, voice-VLAN hopping, SIP trunk toll fraud, IAX2 brute force, NAT/ALG traversal abuse, peer-spoofed call replays, and geo-routing rule override.
What we test
Each layer of your wireless estate is reviewed by hand against its real attack surface, corporate Wi-Fi, 802.1X / RADIUS, the rogue-AP boundary, and the BYOD / guest edge. Intensity tunes per scope.
PMKID capture via hcxdumptool, 4-way handshake collection under deauth, offline crack with hashcat, WPS PIN brute force (Pixie Dust), WPA3 SAE downgrade (Dragonblood), MFP / 802.11w not enforced, PMF-not-required client trap.
Server-cert validation off on clients, PEAP outer-tunnel bypass, EAP-MSCHAPv2 cleartext relay, EAP-TLS cert-pinning gaps, RADIUS shared-secret re-use across SSIDs, MAC-RADIUS bypass, NPS / FreeRADIUS misconfig.
Same-SSID rogue stood up with hostapd-mana, broadcast-PROBE-RESPONSE KARMA, captive-portal harvest of corporate creds, MAC randomization detection bypass, Wireless IDS / WIPS evasion, deauth flood under MFP-off.
Captive-portal UAM bypass, guest-to-corporate VLAN escape via DHCP / IPv6 abuse, NAC posture-check bypass, MDM-issued client cert lift, BYOD MAC-allowlist spoof, Wi-Fi Direct lateral pivot, hidden-SSID probe-leak reveal.