Dark Web Monitoring
We continuously check whether data from your company or your social accounts is exposed on the dark web: credentials, documents and sensitive information.
Request an assessmentRed Team · Threat Intelligence · Attack Surface · Offensive Security
Terms with a dotted underline have an explanation: hover, tap or navigate with the keyboard.
We combine an offensive mindset with proactive defense. Every service is designed to anticipate and neutralize real threats.
We continuously check whether data from your company or your social accounts is exposed on the dark web: credentials, documents and sensitive information.
Request an assessmentOur team runs real intrusion tests on networks, applications and infrastructure to identify and exploit vulnerabilities before the adversary does.
Request an assessmentWe analyze and reverse engineer malware to identify the origin of the attack, the behavior of the malicious code and the indicators of compromise.
Request an assessmentTechnical investigation of cyber incidents to determine how the attack happened, collect evidence and support legal action.
Request an assessmentFull protection for your accounts on Instagram, LinkedIn, Facebook and other platforms against cloning, takeover, phishing and profile hijacking.
Request an assessmentComplete APT attack simulations, with social engineering and physical and digital intrusion, to assess your organization's real resilience.
Request an assessmentWhen the attack happens, we move fast: containment, eradication, recovery and a full forensic report of the incident.
Get help nowCollection and analysis of open source information to map the attack surface, track threat actors and protect your digital exposure.
Request an assessmentTabletop exercises and realistic crisis simulations to train technical and executive teams for the worst-case scenario.
Request an assessmentWe do not sell theory. Every service is grounded in real incidents resolved over more than 13 years.
We have reverse engineered ransomware such as STOP/DJVU and REvil and restored operations for pulp and paper, metallurgy and financial companies in Canada. When the situation is serious, you want people who have been there.
We prioritize critical incidents. We start containment and the remote strategy while others are still scheduling calls.
Strict NDAs and encrypted communication channels (Signal and PGP) are standard on every engagement. Your crisis, our confidentiality.
A 9-phase methodology aligned with NIST and CISA standards, from the first alert to continuous improvement.
Activation of the incident response plan, notification to legal and insurance and preservation of evidence.
Scope confirmation, log preservation and identification of the Patient Zero, the first compromised system.
Network isolation, disabling of compromised accounts and interruption of lateral movement.
Root cause analysis, attacker mapping and assessment of exposed data.
Breach assessment, notification to authorities (ANPD and LGPD) and compliance verification.
Malware removal, system rebuild and reset of compromised credentials.
Data restoration, validation with the business and activation of enhanced monitoring.
Internal guidance, notification of affected customers and management of the public message.
Post-incident analysis, security hardening and updates to policies and playbooks.
Nocera Information Security ME® brings together more than 13 years of experience in offensive security, incident response and cyber intelligence. We serve companies, governments and people who need real protection, always under NDA and with a method.
Vulnerabilities, investigations and threats analyzed with technique.
In-depth technical analysis of the CitrixBleed 2 vulnerability, demonstrating the memory dump, the exploitation vectors and the detection techniques. Original research published by Guilherme Nocera.
A critical flaw in the STDoctor system exposes patient data (tax IDs, exam photos and payment details) circulating in criminal groups on Telegram.
A trojan stealer captured credentials from city hall employees, granting access to the internal dashboard and exposing 55 thousand residents to targeted attacks.
Fast response, total confidentiality and field execution. No fluff.