Services
Penetration testing, alarm tests, offensive development and audits
Four clearly scoped services. Every assessment ends with findings assessed in the context of your organisation and rated by risk.
Penetration testing
In a penetration test we examine your IT infrastructure – applications, networks, clients and servers – for typical misconfigurations and vulnerabilities. We take a holistic approach: every finding is assessed in the context of your organisation and receives a risk rating based on threat-actor profiles.
Our test areas:
- Microsoft Entra (Azure AD) and Active Directory: attack paths, privilege escalation, lateral movement, group policies and trust relationships between domains.
- Web applications and APIs: security analysis of web applications and REST/SOAP APIs following the OWASP Web Security Testing Guide – from authorisation and authentication flaws to SQL injection and cross-site scripting.
- Mobile apps (Android and iOS): security analysis following OWASP MASVS – local data storage, protection mechanisms, app permissions and backend communication.
- Infrastructure and external attack surface: what an attacker can see from outside and reach from inside.
So that your systems end up lastingly better than before the assessment, a short retest is always part of the engagement.
Alarm tests
Does your SOC detect an ongoing attack – or only the damage afterwards? As a service partner of RedMimicry we emulate threat actors realistically and validate your detection and response capabilities across SOC, EDR, NDR and SIEM.
We replay selected attacker techniques in a coordinated sequence and vary how conspicuous they are. The whole chain gets measured: which actions are logged, which raise an alert, which actually trigger a response – and how fast.
Afterwards you receive a complete timeline of the executed actions mapped to MITRE ATT&CK, a comparison of generated versus observed events, and concrete recommendations for telemetry, rules and escalation paths.
Attack paths are reproducible: you can measure every improvement to your detection against the same attack again. Alarm tests are a good fit when your detection processes are in place and you want to prove their effectiveness without commissioning a full red-team engagement. Optionally combinable with a penetration test and usable in a DORA context.
Offensive development
We build tailored software for pentest, red-team and internal security teams: automation, operator and helper tooling, integration components and the complex edge cases standard products do not cover – from idea to maintainable code.
- Custom tools and extensions for your existing toolchain
- Close alignment with your technical requirements and compliance constraints
Application & code security audits
Some vulnerabilities no blackbox test will find – they live in the code. We offer:
- Application security audits: architecture, common vulnerability classes, and the critical and complex areas of your application.
- Source code audits: focused analysis of security-relevant paths and data flows – for common frameworks such as Spring Boot, Laravel and Django as well as custom codebases.
We examine the weaknesses and attack paths attackers actually use.
Frequently asked questions
Answers to the questions we hear most often before an engagement.
- Do you automate or test manually?
- Both. We automate common scenarios and basic checks for reliable coverage. The actual analysis is individual: for that we write our own code and work by hand – on chained privilege escalation, bypassed authentication or business-logic flaws that no scanner finds.
- How do you set scope and price?
- The starting point is not your server count, but what a realistic attacker could achieve against you. In an initial call we define objectives and testing depth. On that basis you receive a fixed-price offer, with no hidden costs.
- Do you just work through a checklist?
- No. Recognised methodologies – OWASP WSTG for web, MASVS for mobile, MITRE ATT&CK for infrastructure and Active Directory – give us traceable coverage. The real value comes beyond them: from the attacker's perspective we chain vulnerabilities and question assumptions no checklist captures. Every finding receives a risk rating based on threat-actor profiles.
- Do you use AI or LLMs?
- Yes, but narrowly. At Wisp, LLMs only generate code for automation; client data is never handed to them. The analysis, the chaining of vulnerabilities and the judgement stay human. And where a model is used, only via zero-retention providers.
- Is a retest included?
- Yes. So that your systems end up lastingly better than before the assessment, a short retest is always part of the engagement.
- What is an alarm test?
- An alarm test emulates a threat actor realistically in your environment and measures whether your SOC, EDR, NDR and SIEM detect and respond to the attack. Attack paths are reproducible, can optionally be combined with a penetration test, and are usable in a DORA context.
Which assessment fits your systems?
Describe your environment – we will tell you honestly which service makes sense and which does not.