Important notice: BSides Curitiba 2026 · October 17 · PUCPR · Get your ticket
← All services// Services · Offensive

Pentest and Intrusion Testing

Our team runs real intrusion tests on networks, applications and infrastructure to identify and exploit vulnerabilities before the adversary does.

// What it is

What it is about

Pentest is an authorized test in which specialists try to break into systems, networks or applications to find flaws before a criminal exploits them. It is not an automated scan: every finding is validated and exploited in a controlled way, to show the real impact.

We test the external perimeter, internal network and Active Directory, web applications and APIs, mobile apps and social engineering, in black box, gray box or white box modes, depending on the objective.

// When to hire

When it makes sense

  • Before putting a system or application into production.
  • After relevant changes to infrastructure, cloud or integrations.
  • To meet client, audit, insurer or standard requirements.
  • When you want evidence of what an attacker could achieve today.
// How we do it

From first contact to delivery

A predictable flow, under NDA, with the client informed at every step.

01

Agreement and scope

Bilateral NDA and proposal with scope, rules of engagement and windows defined in writing. Nothing starts without authorization.

02

Reconnaissance and exploitation

Mapping of the attack surface and controlled exploitation of the flaws, following OWASP, PTES, MITRE ATT&CK and NIST SP 800-115.

03

Reporting

Executive and technical reports with evidence, risk rating, impact and remediation guidance, delivered over an encrypted channel.

04

Closeout

Secure destruction of data and access per NIST SP 800-88, with written confirmation and post-delivery support.

// Deliverables

What you get

  • Executive report for the board, with risk in business language.
  • Technical report with evidence, reproduction steps and risk rating for each finding.
  • Prioritized remediation guidance.

Every engagement starts with a bilateral NDA. We do not disclose client names, vulnerabilities or incidents without written authorization, and sensitive communication uses encrypted channels (Signal and PGP).

// Related services

You may also like

Offensive

Red Team Operations

Complete APT attack simulations, with social engineering and physical and digital intrusion, to assess your organization's real resilience.

See the service
Intelligence

OSINT and Intelligence

Collection and analysis of open source information to map the attack surface, track threat actors and protect your digital exposure.

See the service
Intelligence

Dark Web Monitoring

We continuously check whether data of your company or your social accounts is exposed on the dark web: credentials, documents and sensitive information.

See the service
// Ready to act?

Let's protect what is yours.

Fast response, total confidentiality and field execution. No fluff.

Cookies and privacy

NecessaryAlways on
Metrics