Offensive Security · Penetration Testing · Red Teaming

We find the gaps.
Together we
close them.

sec/friends tests your systems through the eyes of a real attacker. Unlike one, we follow industry standards, document everything in a final report and present the risks as equals. No jargon, no scaremongering. Just clear findings and a team that explains rather than lectures.

sec/friends — Testing aligned with OWASP, PTES, BSI recommendations & others. Strictly with written authorisation.

Services

Different ways to put your defences to an honest test

Every project starts with a clear scope and ends with a report your management understands too – closing presentation included.

external · internal · recurring

Vulnerability Scans

Regular automated scans of your external and internal systems – set up and run by us and, above all, reviewed by humans. You get triaged, prioritised results instead of a flood of raw data.

  • One-off or as a recurring service (monthly/quarterly)
  • Manual triage – we filter out false positives wherever possible before they reach you
  • Trend overview: is your attack surface growing or shrinking?
  • The ideal entry point before a first penetration test
hardware · environment

Cloud & Configuration Audits

Review of your Azure, AWS or GCP environment: identities, network paths, permissions, hardening.

  • Windows Active Directory (AD) & Microsoft Entra ID
  • IAM & permission analysis
  • Comparison against CIS benchmarks
  • Prioritised, actionable list of measures
web · api · mobile · infra

Penetration Testing

In-depth manual testing of your web applications, mobile apps, APIs and infrastructure – supported by tooling, never replaced by it.

  • OWASP WSTG, PTES & beyond
  • Authentication, session & permission models, multi-tenancy and more
  • Retest after remediation included
physical · spear phishing · vishing

Social Engineering

Testing the "human vulnerability" while observing every legal and ethical obligation.

  • Agreed scenarios, works council option available
  • Evaluation at team level, never per individual
  • Combinable with our live hacking & training offerings
adversary simulation

Red Teaming

Realistic attack scenarios spanning (up to) several weeks – tailored to your threat landscape and optionally involving your blue team.

  • Breach emulation
  • Scenarios based on MITRE ATT&CK
  • Purple team workshops for the debrief if desired
  • Measurable maturity level of your detection
awareness · workshops · events

Live Hacking & Training

Making security tangible: we show live how attacks really unfold – from board-level events to hands-on workshops for your developers and admins.

  • Live hacking demos for events, executives & staff
  • Secure coding & hardening workshops with hands-on exercises
  • Awareness training that sticks – without the wagging finger
  • Content tailored to your systems and your daily work
Approach

Five phases. No surprises.

At any moment you know what we are doing, why we are doing it and what comes next. No surprises. No hidden costs.

01 / kickoff

Scoping & Kickoff

Objectives, systems, time windows and emergency contacts – put in writing before anything begins.

02 / recon

Reconnaissance

We gather what an attacker would find out about you – making the attack surface visible.

03 / test

Active Testing

Controlled attacks within the agreed scope. Critical findings are reported immediately, not first in the report.

04 / report

Report & Debrief

Management summary plus a technical section with reproduction steps and concrete fixes – presented in person.

05 / retest

Retest

After your remediation we test again. A finding is closed only once the gap is effectively fixed.

Report

What a finding looks like with us

Extract from an anonymised sample report: every finding has a criticality, a plain-language description and a concrete recommendation.

sample-report.pdf · extract · client: anonymisedstatus: completed ✓
IDFindingCriticalityRecommendation
SF-01Outdated software component with known vulnerabilities in the login areaAn attacker could exploit publicly documented flaws.highUpdate to a supported version, then retest.
SF-02Overly broad permissions for service accounts in the cloud environmentCompromising one account would have an unnecessarily large impact.mediumApply the least privilege principle, split up roles.
SF-03Missing security headers on the public websiteDoes not enable attacks, but makes them easier than necessary.lowAdd the recommended HTTP headers (template in the appendix).
All findings including reproduction steps, references and prioritisation – plus a one-page management summary in plain language.
Why sec/friends

Our passion is not a buzzword

Offensive security runs on trust. That is why we work the way we would want to be tested ourselves.

01 — plain talk

Understandable, not cryptic

Reports your developers can act on and your management understands. Questions never cost extra with us.

02 — fairness

No scaremongering

We do not sell panic. A low finding stays a low finding – and a clean result is something we celebrate with you.

03 — responsibility

Clean & documented

We test only with written authorisation, within the agreed scope, with an emergency contact and a complete log.

Contact

Let's talk about your attack surface

In a free intro call we work out which assessment makes sense for you – and which does not. Sometimes the honest answer is: none yet.

Book an intro callhallo@secfriends.com · for all other enquiries