services · 01 · core

Penetration testing &
audit.

I look for what an attacker would find on your system, demonstrate it without breaking anything, and explain how to fix it.
Engagements in Caen, Normandy and remotely.

Discuss the scope → or ask to be called back

scopes

Scopes

Web applications and APIs

Authentication, session and permission handling, business logic, injections, data exposure, REST and GraphQL API security.

Android applications

Local storage, server communications, client-side controls, and the API the app relies on.

Cloud infrastructure

Cloud account configuration, identity and access management, service exposure, images and orchestrators.

Linux systems

Server and workstation hardening, permissions and privilege escalation, exposed services, compromise paths.

Hardware and reverse engineering

Connected and embedded devices, firmware analysis and reverse engineering. The ground my open-source projects are built on.

OSINT and reconnaissance

What an attacker learns about you from open sources: exposure, leaks, external attack surface.

attack simulation

Attack simulation: phishing and physical intrusion

These tests measure how your organisation reacts to a realistic attack: a booby-trapped email, or an attempt to access your premises. They require a stricter framework than technical tests.

  • Written authorisation signed by the organisation’s legal representative, for each physical site involved.
  • An authorisation letter is carried at all times during any physical intrusion, with a contact reachable at any moment.
  • Phishing campaigns measure behaviours, not people. No real password is kept.
  • Results serve to improve procedures and awareness, never to penalise an employee.
  • Campaigns involving employees are subject to prior information (works council where applicable) and a GDPR framework defined with you.

The legal framework

No test is carried out without written authorisation and a validated scope (rules of engagement).

Accessing a computer system without authorisation is an offence (articles 323-1 et seq. of the French Criminal Code), even with good intentions.

If you ask me to test a system you do not own, the agreement of its owner or host is also required.

deliverables

What you receive

  • An executive summary: the risk level and priorities, no jargon.
  • A technical report: each finding with its proof, severity, reproduction steps and a fix recommendation.
  • A debrief meeting with the teams involved.
  • A retest of the fixes, and an updated report.

Data collected during the engagement is encrypted. Operational data is deleted at the end; only the report and necessary evidence are kept, encrypted, for the duration set in the contract.

out of scope

What I don’t do

Denial-of-service testing is not part of the offering.

Let's discuss your needs

A system to test? Let's talk scope and schedule. Single day rate of €1,100 (excl. VAT).

Reply within a few business days, no commitment.