Skip to main content

Offensive security consultancy

We attack your systems first, on your terms.

Nullpath Security is an offensive security practice. We run penetration tests, red team engagements, vulnerability assessments and exploit research against the systems your business depends on, then hand your engineers a fix path they can act on before somebody else finds the same route in.

  • Aligned to PTES and the OWASP testing guides
  • Every finding manually verified, with evidence
  • Retest of remediated findings included in the fee

nullpath://engagement/lifecycle

5 phases

  1. 01

    Discovery

    Threat model summary for the target environment

    2 to 3 days
  2. 02

    Scope and rules of engagement

    Signed rules of engagement with authorisation to test

    3 to 5 days
  3. 03

    Testing

    Progress notes at agreed checkpoints throughout the engagement

    1 to 6 weeks
  4. 04

    Reporting

    Technical findings with evidence, reproduction steps and CVSS v3.1 ratings

    3 to 5 days
  5. 05

    Remediation guidance

    Live walkthrough and follow-up support for the engineering team

    Up to 90 days

Methodology anchored in

  • PTES

    Penetration Testing Execution Standard

  • WSTG

    OWASP Web Security Testing Guide

  • ASVS

    OWASP Application Security Verification Standard

  • ATT&CK

    MITRE adversary tactics and techniques

  • 800-115

    NIST technical guide to security testing

  • CIS

    CIS platform hardening benchmarks

02How we operate

Trust is built on how the work runs, not on a wall of logos.

Offensive work puts a supplier inside your systems with permission to break things. These are the commitments we make before that starts, and they sit in the contract rather than on a slide.

  • Written authorisation first

    No traffic leaves our infrastructure until rules of engagement are signed, scope is documented and emergency stop contacts are agreed.

  • Critical findings reported immediately

    Anything critical is escalated out of band the moment it is confirmed, with enough detail to act on before the engagement finishes.

  • Retest is part of the fee

    Remediated findings are retested and the report reissued within 90 days, so the version you hand to a customer or auditor reflects the fixed state.

  • Your data, handled carefully

    Engagement data is encrypted at rest, kept only for the agreed retention period, and destroyed on request with written confirmation.

Certifications held across the practice

Consultants are certified in the discipline they are staffed on.

  • OSCP, Offensive Security Certified Professional
  • OSEP, Offensive Security Experienced Penetration Tester
  • OSWE, Offensive Security Web Expert
  • OSED, Offensive Security Exploit Developer
  • CRTO, Certified Red Team Operator
  • CRT, CREST Registered Penetration Tester
  • GXPN, GIAC Exploit Researcher and Advanced Penetration Tester
  • GWAPT, GIAC Web Application Penetration Tester

03Client accounts

What the engineering teams said afterwards.

All client accounts
They chained three findings we had each rated low into a full account takeover, then showed us the exact request that did it. Our previous supplier had reported two of those same issues and closed them as informational. The report went straight into our sprint board without translation.

VP Engineering

Series B payments platform

Web application and API penetration test

The value was not the initial access, it was the timeline. Seeing exactly which of our alerts fired, which ones nobody looked at for eleven hours, and which stages produced no telemetry at all changed how we spend our detection budget.

Head of Information Security

UK insurance group

Red team engagement and purple team replay

Client names are withheld under non-disclosure agreement. Named references are available on request once an engagement reaches scoping.

04Research notes

Notes from the engagements we are allowed to talk about.

Read the blog
  • Attack Surface

    Your attack surface drifts faster than your test cycle

    An annual penetration test measures the estate as it stood on one morning in March. Cloud accounts, DNS records and third party integrations change every week, so the gap between that report and reality starts widening the day it is delivered. Continuous discovery is what keeps the gap small.

    7 minute read

  • Engagement Design

    Red team or penetration test: choosing the right engagement

    A penetration test asks how much of a system is broken. A red team engagement asks whether anyone would notice a competent operator coming for a specific objective. Choosing the wrong one wastes the budget and produces a report nobody can act on.

    8 minute read

  • Internal Testing

    Five Active Directory misconfigurations that hand over domain admin

    Most internal assessments reach domain admin through configuration rather than a missing patch. Kerberoastable service accounts, permissive certificate templates, wide delegation, available NTLM relay and forgotten access control entries account for most of the paths we walk. All five are fixable in house.

    8 minute read

Start here

Find out what an attacker would reach first.

Send us the shape of your environment and a rough deadline. A consultant replies within one business day with a scope, a window and a fixed price. No sales sequence, no discovery deck.