Mauritius · Offensive Security · 2026

OWASPAligned
PTES · CISNIST sp 800-115
HumanLed testing
Cloud · AI · ADWeb · API · Network

offensive

Penetration Testing

01 ——

AI / LLM Security Assessment

Security testing of LLM-backed applications: prompt injection, jailbreaks, insecure output handling, sensitive data leakage, and tool/agent abuse. Aligned to the OWASP Top 10 for LLM Applications.

OWASP LLM Top 10 Prompt Injection Jailbreaks Insecure Output Agent Abuse
02 ——

Web & API Penetration Test

OWASP-aligned deep manual testing across web apps and REST/GraphQL APIs: IDOR, injection, auth bypass, business logic flaws, mass assignment. Includes a complimentary attack surface report.

OWASP Aligned IDOR REST · GraphQL Logic Flaws + Attack Surface Report
03 ——

Assumed Breach & Network Penetration Test

Assumed-breach and network testing across Windows and Linux estates. We escalate privileges, move laterally, and reach your crown jewels using real Active Directory and *nix attack chains.

Assumed Breach Active Directory Kerberoasting Lateral Movement Windows · Linux
04 ——

Cloud Penetration Test

Active exploitation of your cloud estate across Microsoft 365, Azure, and AWS. We attack identity, escalate through roles and managed identities, steal tokens, and pivot between cloud and on-prem to reach real access.

Active Exploitation Identity Attacks Privilege Escalation Token Theft Cloud → On-Prem

DEFENSIVE

Security hardening

01 ——

Azure & O365 Configuration Review

Tenant-wide review of Azure and Microsoft 365:
Entra ID, Conditional Access, privileged roles, exposed storage, and the identity misconfigurations attackers pivot through.

CIS Benchmark Entra ID Conditional Access ScoutSuite
02 ——

AWS & GCP Configuration Review

Cloud posture review across AWS and GCP: IAM policy sprawl, public buckets, exposed metadata, over-permissive roles, and privilege escalation paths through the control plane.

CIS Benchmark IAM Public Buckets Prowler ScoutSuite
03 ——

Security Hardening

Benchmark-driven hardening for Windows and Linux servers: CIS baselines, attack surface reduction, service and privilege lockdown, and logging & detection uplift. Verified, not just recommended.

CIS Benchmark Windows · Linux Attack Surface Reduction Detection Uplift
04 ——

OSINT & Attack Surface Report

Zero-knowledge external reconnaissance: shadow assets, subdomains, exposed services, leaked credentials, and metadata. We map everything an attacker can see before they act.

Black Box OSINT Subdomain Discovery Leaked Credentials Attack Surface Mapping

Credentials & training

Backed by industry-recognized certifications.

Because continuous training is essential to staying ahead of evolving attack techniques and modern threat landscapes.

GPEN GSEC CPSA eWPTXv2 eMAPT Hack The Box PortSwigger PentesterLab

Start with a free scoping call

We will understand your environment, identify the right engagement type, and provide a clearly scoped proposal. No commitment required.

📍 Beau-Bassin, Mauritius 📞 +230 57505480 🔗 Hack The Box