Discuție inițială de discovery
Initial discovery call
Înțelegem problema clientului, obiectivele, contextul de business și suprafața aproximativă de atac.
We understand the client's problem, goals, business context, and rough attack surface.
Atac, apărare și monitorizare - servicii reale pentru firme și locuințe care vor să știe unde sunt vulnerabile, nu doar să bifeze o căsuță.
Offense, defense and monitoring - real services for companies and homes that want to know where they're vulnerable, not just check a box.
Pachete & scoping
Packages & scoping
Fiecare angajament se construiește pe scope: ce testăm, cât durează și câți oameni sunt implicați. Mai jos vezi ce livrăm și ce ne trebuie de la tine ca să pornim.
Every engagement is built around scope: what we test, how long it takes and how many people are involved. Below you'll find what we deliver and what we need from you to start.
Scoping rapid
Fast scoping
Completează formularul pentru aplicații web, API-uri, infrastructură externă sau rețea internă. Informațiile ne ajută să estimăm corect durata, riscurile, accesul necesar și oferta finală.
Fill in the form for web applications, APIs, external infrastructure or internal networks. The details help us estimate duration, risk, required access and the final proposal accurately.
Ce facem concret
What we actually do
Nu vindem rapoarte automate generate în 10 minute. Fiecare evaluare e muncă manuală reală - găsim ce un scanner nu găsește.
We don't sell auto-generated reports done in 10 minutes. Every assessment is real manual work - we find what a scanner won't.
Atacăm controlat portalurile, magazinele online sau platformele interne. SQL injection, XSS, IDOR, broken auth, business logic - tot ce un hacker real ar căuta.
We perform controlled attacks on portals, online stores, and internal platforms. SQL injection, XSS, IDOR, broken authentication, business logic flaws - everything a real attacker would look for.
iOS și Android: stocare nesigură, trafic interceptabil, bypass biometrie, reverse engineering APK/IPA. Ce se întâmplă dacă un telefon e pierdut sau furat.
iOS and Android: insecure storage, interceptable traffic, biometric bypass, APK/IPA reverse engineering. What happens if a phone is lost or stolen.
Verificăm dacă cineva din parcare sau de pe internet poate intra în rețeaua voastră. Servere, firewall-uri, porturi deschise, servicii expuse.
We check if someone from the parking lot or the internet can get into your network. Servers, firewalls, open ports, exposed services.
Cel mai ignorat punct critic. Testăm escaladare privilegii, Kerberoasting, Pass-the-Hash, BloodHound paths - scenariul în care un cont de angajat preia tot domeniul.
The most overlooked critical point. We test privilege escalation, Kerberoasting, Pass-the-Hash, BloodHound paths - the scenario where one employee account takes over the whole domain.
Testăm on-site: WPA cracking, evil twin, rogue AP, izolare rețea guest. Dacă cineva conectat la Wi-Fi poate ajunge la servere sau date interne.
On-site testing: WPA cracking, evil twin, rogue AP, guest network isolation. Whether someone on Wi-Fi can reach servers or internal data.
Citim codul sursă manual. Găsim vulnerabilități de logică, criptografie slabă, secrete hardcodate, injection points - direct din rădăcină, înainte de lansare.
We read the source code manually. We find logic vulnerabilities, weak cryptography, hardcoded secrets, injection points - straight at the root, before launch.
Simulăm un atacator real de la zero: phishing țintit, acces fizic on-site, compromis rețea & AD, lateral movement, exfiltrare date. Cel mai complet și mai exclusiv angajament pe care îl oferim.
We simulate a real attacker from scratch: targeted phishing, physical on-site access, network & AD compromise, lateral movement, data exfiltration. The most complete and exclusive engagement we offer.
Evaluăm controlat riscurile fizice ale locuinței: acces uși și ferestre, interfon, camere, yale smart, poziționare senzori și zone ușor de ocolit.
We assess physical home risks in a controlled way: door and window access, intercom, cameras, smart locks, sensor placement and areas that are easy to bypass.
Verificăm routerul, Wi-Fi-ul, camerele IP, NAS-ul și device-urile smart. Separăm device-urile IoT de laptopuri și telefoane, închidem expunerile inutile.
We check the router, Wi-Fi, IP cameras, NAS and smart devices. We separate IoT devices from laptops and phones, and close unnecessary exposure.
Închidem ce nu trebuie să fie deschis. Revizuim configurații OS, servicii, firewall-uri și politici de acces pentru a reduce suprafața de atac.
We close what shouldn't be open. We review OS configurations, services, firewalls and access policies to reduce the attack surface.
Trimitem email-uri capcană simulate - vedem câți angajați dau click, câți cedează credențiale. Raport per persoană și sesiune de awareness după.
We send simulated phishing emails - we see how many employees click, how many submit credentials. Per-person report and an awareness session after.
Dacă ceva s-a întâmplat deja - intruziune, ransomware, date scurse - intrăm și investigăm: ce a intrat, cum, ce a atins, ce trebuie izolat.
If something already happened - intrusion, ransomware, data leak - we come in and investigate: what got in, how, what it touched, what needs to be isolated.
Monitorizăm evenimentele de securitate din infrastructura voastră non-stop. Detecție anomalii, corelare log-uri, alertare și răspuns rapid când ceva se mișcă.
We monitor security events from your infrastructure non-stop. Anomaly detection, log correlation, alerting and fast response when something suspicious happens.
Urmărim dacă datele sau credențialele companiei voastre au apărut pe dark web sau în breach-uri publice. Raportare lunară clară, fără jargon inutil.
We track whether your company's data or credentials have appeared on the dark web or in public breaches. Clear monthly reporting, no unnecessary jargon.
Cum lucrăm
How we work
Fiecare angajament începe cu înțelegerea problemei și se încheie cu remediere verificată. Clientul știe ce testăm, ce nu testăm, ce riscuri există și ce primește la final.
Every engagement starts by understanding the problem and ends with verified remediation. The client knows what we test, what we exclude, what risks exist, and what they receive at the end.
Înțelegem problema clientului, obiectivele, contextul de business și suprafața aproximativă de atac.
We understand the client's problem, goals, business context, and rough attack surface.
Trimitem un formular sau o listă specifică serviciului. Pentru securitate wireless, de exemplu, cerem detalii despre routere, switch-uri, access point-uri, IoT, locații, diagrame de rețea, credențiale unde e nevoie și constrângeri operaționale.
We send a service-specific form or checklist. For wireless security, for example, we ask for routers, switches, access points, IoT devices, locations, network diagrams, credentials where needed, and operational constraints.
Analizăm informațiile și stabilim clar ce intră în testare, ce este exclus, metodele de testare, durata estimată, riscurile și cerințele necesare.
We review the information and clearly define what will be tested, what is excluded, testing methods, estimated duration, risks, and requirements.
Pe baza scope-ului recomandăm pachetul potrivit: evaluare wireless, pentest rețea, pentest aplicație web, simulare red team, hardening, monitorizare sau o combinație între ele.
Based on the scope, we recommend the right package: wireless assessment, network pentest, web app pentest, red team simulation, hardening, monitoring, or a combination.
Semnăm contractul, NDA dacă este necesar, regulile de angajament, autorizarea de testare, calendarul și livrabilele.
We sign the contract, NDA if needed, rules of engagement, authorization to test, timeline, and deliverables.
Realizăm evaluarea conform scope-ului agreat, cu testare manuală, documentare pe parcurs și comunicare pentru situațiile care necesită decizie rapidă.
We perform the assessment according to the agreed scope, with manual testing, ongoing documentation, and communication for cases that need a quick decision.
Livrăm un raport structurat pentru decizie și remediere.
We deliver a structured report for decision-making and remediation.
Parcurgem constatările cu clientul, explicăm impactul real și răspundem la întrebări tehnice sau de business.
We walk the client through the findings, explain the real impact, and answer technical or business questions.
După remediere, verificăm dacă problemele au fost rezolvate și putem recomanda monitorizare, mentenanță sau testare recurentă.
After remediation, we verify that the issues were fixed and can recommend monitoring, maintenance, or recurring testing.
Intrăm fără nicio informație prealabilă despre sisteme - exact cum ar face un atacator real de pe internet. Cel mai realist scenariu.
We go in with zero prior information about the systems - exactly as a real attacker from the internet would. The most realistic scenario.
Testăm cu credențiale de utilizator normal sau informații parțiale. Ideal pentru scenariul angajat compromis sau cont spart.
We test with normal user credentials or partial information. Ideal for the compromised employee or hacked account scenario.
Acces complet la cod sursă, arhitectură, documentație. Cel mai eficient pentru code review și audit profund înainte de lansare.
Full access to source code, architecture, documentation. Most efficient for code review and deep audit before launch.
Înainte de orice ofertă, discutăm ce aveți, ce vreți să testăm și cât de adânc. Fără presiune, fără angajament.
Before any proposal, we talk about what you have, what you want tested and how deep. No pressure, no commitment.
Testare manuală cu proof-of-concept pentru fiecare vulnerabilitate găsită. Nu liste automate de CVE-uri.
Manual testing with proof-of-concept for every vulnerability found. Not automated CVE lists.
Raport executiv (ce risc, ce impact) + tehnic (cum să repari). Re-testare gratuită după ce ați remediat.
Executive report covering risk and impact + technical guidance on how to fix issues. Free re-test after you've remediated.
Servicii complementare
Complementary services
Construim site-uri și aplicații web moderne, cu securitate integrată din start - nu adăugată pe urmă. Ideal dacă vreți și securitate și dezvoltare de la același loc.
We build modern websites and web apps with security baked in from the start - not bolted on later. Ideal if you want both security and development from the same place.
Design modern, responsive, rapid. Cu CMS sau static, optimizat pentru viteză. Livrat în 1–3 săptămâni.
Modern, responsive, fast design. With CMS or static, speed optimized. Delivered in 1–3 weeks.
Platformă completă cu coș, plăți (Stripe, PayU), gestionare produse și dashboard admin. Securizat și rapid.
Full platform with cart, payments (Stripe, PayU), product management and admin dashboard. Secure and fast.
Platforme cu autentificare, roluri, API, dashboard-uri și integrări. Arhitectură scalabilă, securizată din cod.
Platforms with auth, roles, API, dashboards and integrations. Scalable architecture, secured from the code up.
Actualizări, monitoring uptime, backup automat, patch-uri de securitate. Abonament lunar fără bătăi de cap.
Updates, uptime monitoring, automatic backup, security patches. Monthly subscription without the headache.
Cunoaște echipa
Meet the Team
Hai să vorbim
Let's talk
Scoping-ul e gratuit și fără angajament. Scrie-ne ce vrei să testăm și îți răspundem în maxim 24h.
Scoping is free and with no commitment. Tell us what you want tested and we reply within 24h.