49.18°N 0.37°W · Caen Pentest · Audit · Training · Research

Your defences, tested from the other side.

Penetration tests and audits run like a real attack: reproducible, ranked by severity, and delivered with a fix your teams can actually apply.
Then a retest.

Concrete goal: find what is actually exploitable before an attacker does, and hand you security evidence you can show your clients, insurers and auditors.

4 areas

What I do

core

Penetration testing

Web and API, Android, cloud infrastructure, Linux systems, hardware, attack simulation.

Details →
teach

Training & mentoring

Higher education, in-company training, mentoring people starting out.

Topics →
defend

Consulting

Incident response, forensics, hardening, vulnerability management.

Details →
research

Research & open source

Public tools, CVEs, coordinated disclosure.

The work →
how it works

Three steps, the same framework every time.

1

Scoping & rules of engagement

Objectives, scope, time windows and written authorisation. Nothing starts without them.

2

Testing & actionable report

Each finding: proof, severity, reproduction, fix. Critical issues flagged in real time.

3

Debrief & retest

I present, you fix, I verify again and update the report.

The detailed engagement walkthrough →

why an independent

One contact, from scoping to retest.

No salesperson, no junior quietly subcontracted: the person who tests is the one who scopes, writes the report and presents it to you. You know who is involved, and why.

Framework

Written authorisation and rules of engagement, every time.

Confidentiality

GDPR, encryption, NDA on request. No reference without consent.

Method

Written rules of engagement: targets, windows, stop conditions.

Area

Caen, Normandy and western France. Remote testing anywhere.

Publicly verifiablePublic
credibility

No client logos. Verifiable facts.

Engagements are confidential: no reference without written consent. So here is proof you can verify yourself. Have a specific question? The FAQ.

Open source · Wireless

Evil-M5Project

Wi-Fi exploration and audit tool on M5Stack / ESP32 hardware. Over 2 700 stars on GitHub.

Open source · Network audit

RaspyJack

Network toolkit on Raspberry Pi, with its own community. Over 1 200 stars on GitHub.

Coordinated disclosure

3 published CVEs

Including a critical SQL injection (CVSS 9.8), a privilege escalation in GLPI and a subscriber identifier leak. Plus 2 reserved IDs.

Teaching

Teaching & training

I teach in higher education and run in-company training.

security firms & peers

Are you a security firm?

Pentest reinforcement as a subcontractor: web, API, cloud, Linux, Android and hardware scopes, reports in your format. Published CVEs and open source to back it up. Single day rate of €1,100 (excl. VAT).

Let’s discuss availability →

Let's discuss your needs

Describe the context, the intended scope and your timeline. I answer personally. Single day rate of €1,100 (excl. VAT).

Reply within a few business days, no commitment.