We find the gaps.
Together we
close them.
sec/friends tests your systems through the eyes of a real attacker. Unlike one, we follow industry standards, document everything in a final report and present the risks as equals. No jargon, no scaremongering. Just clear findings and a team that explains rather than lectures.
sec/friends — Testing aligned with OWASP, PTES, BSI recommendations & others. Strictly with written authorisation.
Different ways to put your defences to an honest test
Every project starts with a clear scope and ends with a report your management understands too – closing presentation included.
Vulnerability Scans
Regular automated scans of your external and internal systems – set up and run by us and, above all, reviewed by humans. You get triaged, prioritised results instead of a flood of raw data.
- One-off or as a recurring service (monthly/quarterly)
- Manual triage – we filter out false positives wherever possible before they reach you
- Trend overview: is your attack surface growing or shrinking?
- The ideal entry point before a first penetration test
Cloud & Configuration Audits
Review of your Azure, AWS or GCP environment: identities, network paths, permissions, hardening.
- Windows Active Directory (AD) & Microsoft Entra ID
- IAM & permission analysis
- Comparison against CIS benchmarks
- Prioritised, actionable list of measures
Penetration Testing
In-depth manual testing of your web applications, mobile apps, APIs and infrastructure – supported by tooling, never replaced by it.
- OWASP WSTG, PTES & beyond
- Authentication, session & permission models, multi-tenancy and more
- Retest after remediation included
Social Engineering
Testing the "human vulnerability" while observing every legal and ethical obligation.
- Agreed scenarios, works council option available
- Evaluation at team level, never per individual
- Combinable with our live hacking & training offerings
Red Teaming
Realistic attack scenarios spanning (up to) several weeks – tailored to your threat landscape and optionally involving your blue team.
- Breach emulation
- Scenarios based on MITRE ATT&CK
- Purple team workshops for the debrief if desired
- Measurable maturity level of your detection
Live Hacking & Training
Making security tangible: we show live how attacks really unfold – from board-level events to hands-on workshops for your developers and admins.
- Live hacking demos for events, executives & staff
- Secure coding & hardening workshops with hands-on exercises
- Awareness training that sticks – without the wagging finger
- Content tailored to your systems and your daily work
Five phases. No surprises.
At any moment you know what we are doing, why we are doing it and what comes next. No surprises. No hidden costs.
Scoping & Kickoff
Objectives, systems, time windows and emergency contacts – put in writing before anything begins.
Reconnaissance
We gather what an attacker would find out about you – making the attack surface visible.
Active Testing
Controlled attacks within the agreed scope. Critical findings are reported immediately, not first in the report.
Report & Debrief
Management summary plus a technical section with reproduction steps and concrete fixes – presented in person.
Retest
After your remediation we test again. A finding is closed only once the gap is effectively fixed.
What a finding looks like with us
Extract from an anonymised sample report: every finding has a criticality, a plain-language description and a concrete recommendation.
| ID | Finding | Criticality | Recommendation |
|---|---|---|---|
| SF-01 | Outdated software component with known vulnerabilities in the login areaAn attacker could exploit publicly documented flaws. | high | Update to a supported version, then retest. |
| SF-02 | Overly broad permissions for service accounts in the cloud environmentCompromising one account would have an unnecessarily large impact. | medium | Apply the least privilege principle, split up roles. |
| SF-03 | Missing security headers on the public websiteDoes not enable attacks, but makes them easier than necessary. | low | Add the recommended HTTP headers (template in the appendix). |
Our passion is not a buzzword
Offensive security runs on trust. That is why we work the way we would want to be tested ourselves.
Understandable, not cryptic
Reports your developers can act on and your management understands. Questions never cost extra with us.
No scaremongering
We do not sell panic. A low finding stays a low finding – and a clean result is something we celebrate with you.
Clean & documented
We test only with written authorisation, within the agreed scope, with an emergency contact and a complete log.
Let's talk about your attack surface
In a free intro call we work out which assessment makes sense for you – and which does not. Sometimes the honest answer is: none yet.
Book an intro callhallo@secfriends.com · for all other enquiries