Skip to content
All systems nominal
OFFENSIVE SECURITYRED · PURPLE · BLUE

We model the
adversary
your tooling
is built to miss

Full-scope red teaming, penetration testing, and malware development. Scoped, evidenced, and reproducible. Every finding ships with a working proof-of-concept and the exact path to close it.

400+
Findings shipped
8+ yrs
In offensive security
100%
Reports with PoC
ragnarops@labs:~/eng/acme-finlive
ragnarops@labs:~/eng/acme-fin$recon --target acme.fin --scope full --quiet
[*] mapping external surface ............ done
[+] 41 hosts · 6 internet-exposed · 2 shadow IT
[i] forgotten staging VPN — no MFA, default creds
[~] pivoting via CI runner → internal registry
[!] path to Domain Admin in 3 hops
ragnarops@labs:~/eng/acme-fin$report --evidence --remediation
Live engagementRT-22911 critical
// 01 — Services

Six disciplines, each ending in evidence you can act on.

// 02 — Approach

A repeatable operation, not a one-off scan.

Five phases, one standard of proof. The same operator runs all five on every engagement, so the sequence holds and the discipline shows up in the second phase — emulate, exploit, build, enumerate, exercise, probe. Each phase ends in an artifact you keep.

// Verification is scoped and quoted separately

Aligned to

The full approach

typical: 6 weeks

  1. Frame

    Week 0

    [ artifact ] Signed ROE · named threat actor · crown-jewel asset map

    Objectives, boundaries, and rules of engagement — agreed and signed before a single packet moves. We pick the named threat actor your regulators actually worry about.

  2. Emulate

    Weeks 1–3

    [ artifact ] Campaign log — every action timestamped, deconflicted, attributable

    We operate like the actor in your threat model: patient, quiet, and creative. Custom tooling where off-the-shelf trips EDR. Tradecraft, not noise.

  3. Evidence

    Weeks 3–4

    [ artifact ] Ranked findings · working PoC per finding · critical-path graph

    Every step is logged as we go. Each finding carries a reproducible PoC, the blast radius had the actor kept going, and the screenshots to prove it.

  4. Hand-off

    Week 4

    [ artifact ] Fix path + observable per finding

    We hand the blue team the fix path and the observable each step should have produced, mapped to MITRE ATT&CK — the input a detection engineer needs, in the format they need it.

  5. Verify

    Week 6

    [ artifact ] Re-test report · closed-path confirmation

    A working session with your engineers: reproduce, close, verify. We re-run the attack path until it dies.

  1. Frame

    Days 0–2

    [ artifact ] Scope sheet · credentials issued · blackout windows

    Asset inventory, environment access, and test windows agreed. We define in-scope down to the hostname, and what counts as a blocking finding.

  2. Exploit

    Days 3–8

    [ artifact ] Test log · coverage matrix per surface

    Authenticated and unauthenticated passes across cloud, network, and application surface. Manual work where scanners stop: business logic, chaining, trust boundaries.

  3. Evidence

    Days 8–10

    [ artifact ] Ranked findings · PoC request per finding

    Each issue reproduced twice, with the request and response captured and blast radius established before it reaches the report.

  4. Hand-off

    Day 10

    [ artifact ] Fix path · regression condition per finding

    Remediation written for the team that owns the code: the patch-level fix, the trade-offs it carries, and the condition to assert in your own suite so it fails if the bug returns.

  5. Verify

    Week 3

    [ artifact ] Re-test report · verified-closed attestation

    Re-test of every closed item. The report is reissued with verified status per finding.

  1. Frame

    Week 0

    [ artifact ] Capability spec · containment rules · kill-switch design

    Capability spec, target EDR stack, and containment rules for the build: what it may touch, where it may run, and how it dies.

  2. Build

    Weeks 1–4

    [ artifact ] Built capability · build notes · detection-surface analysis

    Loaders and implants written for your environment and tested against the exact EDR you run. You get the built capability and the documentation to operate it; the source is ours and stays ours.

  3. Evidence

    Week 4

    [ artifact ] Behaviour report · IOC set · telemetry gap list

    Behavioural evidence: what the sample does, what it leaves behind, and what your telemetry actually saw at each stage.

  4. Hand-off

    Week 5

    [ artifact ] Detection content · technique notes that survive a rewrite

    Hand-off to detection engineering with what is needed to catch this class of tooling, not just this build.

  5. Verify

    Week 6

    [ artifact ] Destruction record · re-test against rebuild

    Sample and infrastructure destroyed on completion, confirmed in writing. Detections re-tested against a fresh rebuild.

  1. Frame

    Week 0

    [ artifact ] Detection backlog · telemetry inventory

    Detection goals taken from your real risk register, plus the telemetry we are allowed to read and the gaps you already suspect.

  2. Exercise

    Weeks 1–2

    [ artifact ] Technique run log · raw telemetry captures

    Techniques executed side by side with your SOC — announced, repeated, and tuned until the signal is clean and the noise is gone.

  3. Evidence

    Weeks 2–3

    [ artifact ] Coverage heatmap · true-positive corpus

    For each technique: what fired, what did not, and why. Coverage measured against ATT&CK rather than asserted.

  4. Hand-off

    Week 3

    [ artifact ] Tested rules · replay harness

    Rules written, tuned, and shipped in whichever format your stack consumes, each with a replay harness your team can re-run.

  5. Verify

    Week 5

    [ artifact ] Validation run · alert-fidelity report

    Re-run the technique set against the new rules and confirm every one fires in production, at the right severity.

  1. Frame

    Days 0–2

    [ artifact ] Scope sheet · audit roles · guardrails

    Accounts, subscriptions, and projects in scope. Read-only audit roles issued, production guardrails agreed in writing.

  2. Enumerate

    Days 3–9

    [ artifact ] IAM privilege graph · attack-path candidates

    Full identity-graph enumeration, then privilege-chain walking across accounts and services until a path reaches data.

  3. Evidence

    Days 9–11

    [ artifact ] Attack paths · API call trace per hop

    Every path walked end to end with the API calls recorded, so your team can replay it in a sandbox rather than take our word for it.

  4. Hand-off

    Day 11

    [ artifact ] Policy diff per finding · hardening roadmap

    Policy diffs, not advice: the exact statement to change, with blast-radius notes for the change itself.

  5. Verify

    Week 4

    [ artifact ] Re-enumeration diff · closed-path confirmation

    Re-run the graph after your changes. We confirm the chain is broken and that no new path opened behind it.

  1. Frame

    Week 0

    [ artifact ] Threat model · tool inventory · data-flow map

    Model, tool surface, and data boundaries mapped: what the system can be asked, what it can call, and what it can reach.

  2. Probe

    Weeks 1–2

    [ artifact ] Attack corpus · successful chain log

    Adversarial prompting, indirect injection through retrieved content, and agent tool-abuse chains run against the live stack.

  3. Evidence

    Week 2

    [ artifact ] Reproducible chains · impact per chain

    Each successful chain reproduced with the exact prompt, retrieved context, and tool calls that caused it.

  4. Hand-off

    Week 3

    [ artifact ] Guardrail diffs · regression eval suite

    Guardrail changes, tool-permission diffs, and evaluation cases that fail loudly if the behaviour returns.

  5. Verify

    Week 5

    [ artifact ] Re-run report · eval suite handed over

    Re-run the corpus against the patched system. Any regression re-opens the finding rather than closing the engagement.

operator@ragnarops — C2 beaconlive
Simulated operator console — C2, BloodHound, AFL++, semgrep and nmap captures. Output is illustrative, not engagement data.
100+Engagements delivered
400+Findings shipped
8+ yrsIn offensive security
100%Reports with PoC
// 03 — About

One operator. No bench, no handoff.

The person who scopes your engagement is the person who runs it and writes the report. No account manager in between, no junior on the keyboard, no findings you cannot get an answer about.

  • 100+ engagements delivered
  • MITRE ATT&CK · PTES · TIBER-EU · TLPT · DORA
  • Coordinated disclosure, every time

// Operator certifications

20+ certifications held

A selection of 11, across offensive, defensive and cloud disciplines.

Select a badge to inspect it

Pablo RuizFounder and Lead operatorOffensive security since 2018 — Madrid, Oslo, Amsterdam. Runs the intrusion, then writes the report you can act on.

Offensive security since 2018, across Spain, Norway, and the Netherlands.

The certification path is deliberate rather than decorative: OSCP first, then the full OSCE³ chain — OSEP for evasion, OSWE for the web layer, OSED for exploit development — with GPEN and GCIH covering the defensive side, CRTO for red-team operations, and AWS Security Specialty for the cloud work.

Read for his degree at Universidad de León part-time while working full-time, finishing with first-class honours.

OffSec lists him as an ambassador for its Netherlands chapter, where four of those credentials are published by the body that issued them. Certifications are a floor, not a finding — they say the method is sound, not that the work was.

Every engagement is run end to end by the person who scoped it. Nothing is subcontracted and no finding is handed to someone else to write up, so the operator who got in is the one who explains how, and the one your engineers sit with when it is time to close the path.

What is not covered by an NDA is published. The Labs carry the field notes, the teardowns and the live sessions — the same tradecraft, worked in the open rather than described after the fact.

The practice operates from the Netherlands and works remotely, worldwide.

LanguagesSpanish · English · Norwegian

Certifications20+ held, across offensive, defensive and cloud disciplines

Sectors where the blast radius is real

  • Railway
  • Public sector
  • Financial
  • Entertainment
  • Critical infrastructure
The long version
// 04 — Labs

We publish what we learn.

All field notes
// 05 — Contact

Schedule a scoping call.

Describe what you need proven. We come back with a threat model, a proposed scope, and a price — inside 48 hours.

  • Aligned to TIBER-EU · TLPT · DORA
  • Mutual NDA before scoping
  • 48h response

// Engagement request

scope://
Interested inRed teamPentestMalware devPurple teamCloud securityAI / ML

By submitting you agree to a mutual NDA before any technical detail is shared. We reply from contact@ragnaropsec.com.