Case Studies

Real engagements, real findings

No marketing stories. These are the actual numbers from actual projects, with client details redacted. Every case study links to the full report so you can verify the depth yourself.

PentestBlack-boxOWASP

Web Platform Penetration Test

A full black-box penetration test of a production web platform. Two testers, no internal access, OWASP methodology. We found 8 vulnerabilities, 3 of them high risk, including issues that let an anonymous attacker pull private files and take down the API.

8findings
3high risk
26pages
  • Stored DOM-based XSS that bypassed Cloudflare protection
  • CloudFront bypass exposing the origin server
  • No rate limit on verification codes, enabling brute force
  • Session hijacking through weak session management
Read the full report online Download the full report
Cover of the redacted web platform penetration testing report
CloudGCPConfiguration

Cloud Infrastructure Audit

A configuration audit of a production GCP environment covering IAM, networking, databases, logging, and key management. We mapped 25 misconfigurations by risk and gave the team a concrete fix for each one, no generic advice.

25misconfigurations
3medium risk
52pages
  • IAM roles granted at project level instead of least privilege
  • VPC with unrestricted inbound access and logging disabled
  • Cloud SQL instances with public IPs and no enforced encryption
  • No log metric filters or alerts for critical events
Read the full report online Download the full report
Cover of the redacted GCP cloud infrastructure audit report
Finding Spotlight

What a High-risk finding looks like

Finding High Risk
Unauthorized Access to API Endpoints
Exploit complexityLow
OWASP ReferenceWSTG-ATHZ-02
Location5 API endpoints

Business impact: Access control was enforced on the client side only. Any authenticated user could see comments on files from other projects, enumerate files and user names across the platform, and users with a privileged non-admin role could freely call admin endpoints.

The fix: Enforce project membership checks server-side on every API route, restrict user-identifier lookups to projects the caller belongs to, and move from sequential integer IDs to unpredictable UUIDs.

ResearchRCEDisclosure

TinyCheck Vulnerability Research

Our research team examined TinyCheck, Kaspersky’s network analysis tool. We found 3 high-severity vulnerabilities that chained together into remote code execution: hard-coded credentials gave us a token, command injection let us plant code, and SSRF triggered it. Full disclosure was coordinated with the vendor.

3vulnerabilities
RCEfinal impact
14pages
Cover of the TinyCheck vulnerability research report

Want results like these on your systems? Talk to us.