FIELD-PROVED OFFENSIVE SECURITY

Know what you paid for.

You have a SOC, an MDR subscription, a WAF and a policy document. We are the ones who tell you which of them actually stops an attack.

Book a 4-day Recon See a sample report
Penetration testing · Cloud & pipeline · Adversary simulation · Social engineering training
Ukraine · Europe · UK & Ireland
01

You bought defences.

Nobody ever proved they stop an attack. The dashboard is green because nothing has tested it.

02

Your test returned a list.

Forty findings of medium severity. Not one of them shows how an attacker actually reaches your data.

03

The report arrived late.

Two weeks past the date, written for no one in particular, and read by nobody on your side.

QUIET QUESTIONS

Before you buy another tool, ask three of your own

Security assembled from internet reviews is not security. It is hope.

01

Is your SOC awake at 03:40 on a Saturday?

That is when we schedule the loud part of the test. If nobody calls you, that is a finding.

02

When did anyone last read all 1,200 firewall rules?

The box is six years old, and somewhere around rule 400 there is an allow-any. There usually is.

03

Whom did your accountant just accept on LinkedIn?

Sometimes it is us, rehearsing the real thing — politely, and with signed permission. People are an entry point; we test that too.

THE ATTACK PATH

The chain, not the catalogue

We follow the whole attack path — from the first way in to your production environment — and show how one step becomes the next. Not every company has a public repository. Every company has people, code and a perimeter.

THREE OF MANY WAYS IN — EVERY COMPANY HAS AT LEAST ONE
ENTRY · PEOPLE
Your employee
the email they click
ENTRY · CODE
Public repo
exposed token
ENTRY · PERIMETER
Edge service
unpatched VPN
1
Initial access
first foothold
2
CI / CD
build injection
3
Cloud IAM
role escalation
4
Production
lateral move
5
Your data
objective
WHAT MOST REPORTS GIVE YOU

A severity-sorted list. Each item true, none of them connected.

WHAT WE GIVE YOU

One page showing how step 1 becomes step 5 — and the single cheapest place to break the chain.

SERVICES

Six products, fixed scope

RECON4 days

Basalt Recon

One full attack path, outside in.

from €2 500
PROBE8 days

Basalt Probe

Web applications and APIs, fixed scope. The report your client's procurement asks for.

from €6 000
PIPELINE10 days

Basalt Pipeline

Cloud, CI/CD and supply chain. Infrastructure as code, secrets, artefacts, role chains.

from €9 000
PROOF10 days

Basalt Proof

Validation of your SOC or MDR. Eight to ten ATT&CK scenarios against your live detection stack.

from €10 000
RECORDretainer

Basalt Record

Quarterly retest and continuous attack-surface monitoring.

from €1 000/mo
RANGE2–3 days

Basalt Range

Hands-on training. Your engineers break a deliberately vulnerable application, then fix it.

from €3 000

Everything we do, in the words you would search for

OFFENSIVE TESTING
External perimeter · internal network and Active Directory · web · API · mobile · adversary simulation · purple team · social engineering and phishing · OSINT and organisational footprint · attack surface monitoring
CLOUD, PIPELINE, SUPPLY CHAIN
AWS · Azure · GCP · Kubernetes and containers · CI/CD · infrastructure as code · secrets and key management · privilege chains and identity federation
AI, TRAINING, ASSURANCE
LLM application testing · ML supply chain · secure development workshops · social-engineering resilience · blue-team attack-chain review · quarterly retest and auditor evidence
METHOD

We do not ask you to trust a logo

Every engagement runs on public standards. All of them are free to read. What is scarce is the discipline to follow them the same way every time.

PTES OWASP WSTG OWASP MASTG NIST SP 800-115 MITRE ATT&CK

Signed authorization first

No packet leaves our side before the letter of authorization and the rules of engagement are signed by someone entitled to sign them.

Your data dies in 30 days

Everything we collect is destroyed thirty days after the engagement closes, retest included. The obligation is written into the contract.

Two pairs of eyes

No report reaches you without review by a second member of the core team.

The date is the promise

If the report is late, you pay ten percent less. That clause is in the contract.

THE DELIVERABLE

You are buying the report.

So we treat it as the product, not as the paperwork that follows the work.

Executive summary

One page. No jargon. The business consequence of each finding, in the language your board uses.

The attack path

The chain, drawn. The page people actually look at.

Findings

CVSS, proof, reproduction steps, and a fix that names the file.

What held

What we could not get past. Almost nobody writes this section, and it is the fastest way we know to earn your trust.

Retest included

Thirty days to fix. We verify and reissue the report clean for your auditor.

Annexes

Scope, methodology, timeline, limitations, tooling.

Start with one attack path.

Four days. Fixed price. One complete chain from the outside in, written up for your board and for your engineers.

Book a Recon
hello@basaltsec.com · PGP key at /.well-known/security.txt