AUTHORIZED PENTEST · $100 CHECK

We play the villain.

A $100 attack-surface check: we run the attack on the systems you authorize, then a senior pentester walks you through what we found.

How it works

Four steps, no sales call. You scope it and pick a time in minutes; we take it from there.

Tell us the scope

A few short questions, mostly tapping. You tell us what to test and confirm you control it.

Pick a time

Choose a slot that suits you for the 30-minute readout. We reach out to lock it in.

We confirm authorization

Before anything runs, we verify you control the target and put the scope in writing.

We run it, then your readout

A senior operator runs the check, then walks you through what we found on your call.

What you walk away with

Not a raw scanner dump. A short, ranked report plus a human who explains it, so you know what to fix first and why it matters.

  • Findings ranked by real-world exploitability
  • Reproduction steps your team can run
  • A plain-language readout with a real pentester
  • Free retest of every finding you fix
OT-2026-014 CRITICAL

Domain compromise via unconstrained delegation

ACCESS PATH
phish → workstation → delegation host → coerce DC → domain admin
IMPACT

Full control of the corporate domain from a single phished workstation, in under two days, with no reliable detection in place.

REMEDIATION

Replace unconstrained delegation with constrained or RBCD; add tier-0 accounts to Protected Users and flag them sensitive and cannot be delegated; block coercion paths to domain controllers.

Illustrative of our full-engagement reporting format. The $100 check covers external surface and one web app.

One price to start

Begin with the check. Move up when the scope or the paperwork calls for it.

START HERE $100

Attack-surface check

Your external attack surface and one web app. Hands-on testing, a senior-pentester readout, and a ranked findings report.

Start your check
WHEN YOU NEED DEPTH Custom

Full engagement

Internal networks, cloud, larger scope, and compliance-ready reporting for auditors and insurers. Scoped and quoted with you.

Talk to us

The $100 check is a fast first look, not a full penetration test. If an auditor or insurer set specific requirements, tell us up front and we will say straight whether the check covers it or you need a full engagement.

We only test what you authorize

No authorization, no testing. Before a single request goes out, you confirm you control the target and sign off on scope. Run by a senior offensive-security operator (OSCP, OSEP).

  • Proof of ownershipYou verify control of the target by publishing a token we issue, as a DNS record or a file we can read, before we start.
  • Written authorizationA signed agreement defines the scope, the rules of engagement, and the limits.
  • Nothing out of scopeWe test only the assets you list. Everything else is off limits, by design.

Straight answers

Is this a real pentest or just a scan?

The $100 check is hands-on testing by a senior pentester, focused on your attack surface. It goes deeper than an automated scan and lighter than a full manual engagement. For audit-grade depth, start with a full engagement.

Is it legal?

Yes, when you authorize it. We only test targets you confirm you own or control, under written authorization. That confirmation is part of the intake, and testing does not begin until it is signed.

What do I need before I start?

The domain or web app you want tested, and the ability to prove you control it by publishing a token we issue, either as a DNS record or as a file on the domain.

Will my auditor or insurer accept the report?

It depends on their requirements. Tell us what they ask for up front, and we will tell you honestly whether the $100 check covers it or you need a full engagement.

What if you do not find anything?

You still get the readout and a written result you can show. A clean check is a real outcome, and worth knowing.

Can I get a refund?

If we cannot test your target because of a scope or ownership issue we cannot resolve, you get a full refund before any testing starts.

How it goes

Answer a few short questions, one at a time, mostly by tapping. We scope exactly what to test and confirm you are authorized. Nothing runs until that is settled.

Then you pick a time for the 30-minute readout and we get in touch to confirm. We run the check first, so the earliest slots are about three working days out.

  1. Tell us what to test. No account, no sales call.
  2. Answer the scoping questions (about 2 minutes).
  3. Confirm you control the target and authorize the test.
  4. Pick a time. We confirm, run the check, and get in touch.
Start your check

We only use what you share to scope and deliver the check. Privacy policy.

Find out before someone else does.

Start your check