We model the
adversary
your tooling
is built to miss
Full-scope red teaming, penetration testing, and malware development. Scoped, evidenced, and reproducible. Every finding ships with a working proof-of-concept and the exact path to close it.
Six disciplines, each ending in evidence you can act on.
Red team operations
Full-scope, objective-driven intrusion modelled on a named threat actor. We earn the foothold, then prove what it is worth.
- Threat-model scoping
- Assumed-breach & full-scope
- Detection-evasion tradecraft
Penetration testing
Cloud, infrastructure, and application testing. Every finding ships with a working PoC and blast radius.
Engagement detailMalware development
Bespoke implants and loaders for realistic emulation, built and documented, then burned on completion.
Engagement detailDetection engineering
We work alongside your blue team and turn every finding into a durable, tested detection.
Engagement detailCloud security
AWS, Azure, and GCP attack paths: identity, misconfiguration, and the privilege chain that ends in your data.
Engagement detailAI security
Adversarial testing for LLM and ML systems: prompt injection, tool and agent abuse, training-data and model-supply-chain exposure. We attack the model, its context, and everything it is allowed to touch.
- Prompt injection & jailbreak chains
- Agent / tool-use abuse
- RAG & data-exfil paths
- Model supply-chain review
A repeatable operation, not a one-off scan.
Five phases, one standard of proof. The same operator runs all five on every engagement, so the sequence holds and the discipline shows up in the second phase — emulate, exploit, build, enumerate, exercise, probe. Each phase ends in an artifact you keep.
// Verification is scoped and quoted separately
Aligned to
The full approachtypical: 6 weeks
Frame
Week 0[ artifact ] Signed ROE · named threat actor · crown-jewel asset map
Objectives, boundaries, and rules of engagement — agreed and signed before a single packet moves. We pick the named threat actor your regulators actually worry about.
Emulate
Weeks 1–3[ artifact ] Campaign log — every action timestamped, deconflicted, attributable
We operate like the actor in your threat model: patient, quiet, and creative. Custom tooling where off-the-shelf trips EDR. Tradecraft, not noise.
Evidence
Weeks 3–4[ artifact ] Ranked findings · working PoC per finding · critical-path graph
Every step is logged as we go. Each finding carries a reproducible PoC, the blast radius had the actor kept going, and the screenshots to prove it.
Hand-off
Week 4[ artifact ] Fix path + observable per finding
We hand the blue team the fix path and the observable each step should have produced, mapped to MITRE ATT&CK — the input a detection engineer needs, in the format they need it.
Verify
Week 6[ artifact ] Re-test report · closed-path confirmation
A working session with your engineers: reproduce, close, verify. We re-run the attack path until it dies.
Frame
Days 0–2[ artifact ] Scope sheet · credentials issued · blackout windows
Asset inventory, environment access, and test windows agreed. We define in-scope down to the hostname, and what counts as a blocking finding.
Exploit
Days 3–8[ artifact ] Test log · coverage matrix per surface
Authenticated and unauthenticated passes across cloud, network, and application surface. Manual work where scanners stop: business logic, chaining, trust boundaries.
Evidence
Days 8–10[ artifact ] Ranked findings · PoC request per finding
Each issue reproduced twice, with the request and response captured and blast radius established before it reaches the report.
Hand-off
Day 10[ artifact ] Fix path · regression condition per finding
Remediation written for the team that owns the code: the patch-level fix, the trade-offs it carries, and the condition to assert in your own suite so it fails if the bug returns.
Verify
Week 3[ artifact ] Re-test report · verified-closed attestation
Re-test of every closed item. The report is reissued with verified status per finding.
Frame
Week 0[ artifact ] Capability spec · containment rules · kill-switch design
Capability spec, target EDR stack, and containment rules for the build: what it may touch, where it may run, and how it dies.
Build
Weeks 1–4[ artifact ] Built capability · build notes · detection-surface analysis
Loaders and implants written for your environment and tested against the exact EDR you run. You get the built capability and the documentation to operate it; the source is ours and stays ours.
Evidence
Week 4[ artifact ] Behaviour report · IOC set · telemetry gap list
Behavioural evidence: what the sample does, what it leaves behind, and what your telemetry actually saw at each stage.
Hand-off
Week 5[ artifact ] Detection content · technique notes that survive a rewrite
Hand-off to detection engineering with what is needed to catch this class of tooling, not just this build.
Verify
Week 6[ artifact ] Destruction record · re-test against rebuild
Sample and infrastructure destroyed on completion, confirmed in writing. Detections re-tested against a fresh rebuild.
Frame
Week 0[ artifact ] Detection backlog · telemetry inventory
Detection goals taken from your real risk register, plus the telemetry we are allowed to read and the gaps you already suspect.
Exercise
Weeks 1–2[ artifact ] Technique run log · raw telemetry captures
Techniques executed side by side with your SOC — announced, repeated, and tuned until the signal is clean and the noise is gone.
Evidence
Weeks 2–3[ artifact ] Coverage heatmap · true-positive corpus
For each technique: what fired, what did not, and why. Coverage measured against ATT&CK rather than asserted.
Hand-off
Week 3[ artifact ] Tested rules · replay harness
Rules written, tuned, and shipped in whichever format your stack consumes, each with a replay harness your team can re-run.
Verify
Week 5[ artifact ] Validation run · alert-fidelity report
Re-run the technique set against the new rules and confirm every one fires in production, at the right severity.
Frame
Days 0–2[ artifact ] Scope sheet · audit roles · guardrails
Accounts, subscriptions, and projects in scope. Read-only audit roles issued, production guardrails agreed in writing.
Enumerate
Days 3–9[ artifact ] IAM privilege graph · attack-path candidates
Full identity-graph enumeration, then privilege-chain walking across accounts and services until a path reaches data.
Evidence
Days 9–11[ artifact ] Attack paths · API call trace per hop
Every path walked end to end with the API calls recorded, so your team can replay it in a sandbox rather than take our word for it.
Hand-off
Day 11[ artifact ] Policy diff per finding · hardening roadmap
Policy diffs, not advice: the exact statement to change, with blast-radius notes for the change itself.
Verify
Week 4[ artifact ] Re-enumeration diff · closed-path confirmation
Re-run the graph after your changes. We confirm the chain is broken and that no new path opened behind it.
Frame
Week 0[ artifact ] Threat model · tool inventory · data-flow map
Model, tool surface, and data boundaries mapped: what the system can be asked, what it can call, and what it can reach.
Probe
Weeks 1–2[ artifact ] Attack corpus · successful chain log
Adversarial prompting, indirect injection through retrieved content, and agent tool-abuse chains run against the live stack.
Evidence
Week 2[ artifact ] Reproducible chains · impact per chain
Each successful chain reproduced with the exact prompt, retrieved context, and tool calls that caused it.
Hand-off
Week 3[ artifact ] Guardrail diffs · regression eval suite
Guardrail changes, tool-permission diffs, and evaluation cases that fail loudly if the behaviour returns.
Verify
Week 5[ artifact ] Re-run report · eval suite handed over
Re-run the corpus against the patched system. Any regression re-opens the finding rather than closing the engagement.
One operator. No bench, no handoff.
The person who scopes your engagement is the person who runs it and writes the report. No account manager in between, no junior on the keyboard, no findings you cannot get an answer about.
- 100+ engagements delivered
- MITRE ATT&CK · PTES · TIBER-EU · TLPT · DORA
- Coordinated disclosure, every time
// Operator certifications
20+ certifications held
A selection of 11, across offensive, defensive and cloud disciplines.
Select a badge to inspect it
Pablo RuizFounder and Lead operatorOffensive security since 2018 — Madrid, Oslo, Amsterdam. Runs the intrusion, then writes the report you can act on.

Offensive security since 2018, across Spain, Norway, and the Netherlands.
The certification path is deliberate rather than decorative: OSCP first, then the full OSCE³ chain — OSEP for evasion, OSWE for the web layer, OSED for exploit development — with GPEN and GCIH covering the defensive side, CRTO for red-team operations, and AWS Security Specialty for the cloud work.
Read for his degree at Universidad de León part-time while working full-time, finishing with first-class honours.
OffSec lists him as an ambassador for its Netherlands chapter, where four of those credentials are published by the body that issued them. Certifications are a floor, not a finding — they say the method is sound, not that the work was.
Every engagement is run end to end by the person who scoped it. Nothing is subcontracted and no finding is handed to someone else to write up, so the operator who got in is the one who explains how, and the one your engineers sit with when it is time to close the path.
What is not covered by an NDA is published. The Labs carry the field notes, the teardowns and the live sessions — the same tradecraft, worked in the open rather than described after the fact.
The practice operates from the Netherlands and works remotely, worldwide.
Spanish · English · Norwegian
20+ held, across offensive, defensive and cloud disciplines
Sectors where the blast radius is real
- Railway
- Public sector
- Financial
- Entertainment
- Critical infrastructure
Schedule a scoping call.
Describe what you need proven. We come back with a threat model, a proposed scope, and a price — inside 48 hours.
- Aligned to TIBER-EU · TLPT · DORA
- Mutual NDA before scoping
- 48h response





