Offensive security · New York, NY · 40.7128° N, 74.0060° W
Find the way in first.
Axesec is an offensive security firm in New York. We run red team operations, penetration tests and AI security assessments that show how your organization would actually be attacked, and what to fix first.
Services
Six core services and a set of specialized assessments. All work is manual and led by senior engineers. Every engagement includes a retest.
Red team operations
Objective-based adversary simulation against a live, unwarned defense. External, assumed-breach or full-scope, mapped to MITRE ATT&CK.
Attack narrative, detection gapsPenetration testing
Manual testing of web applications, APIs, mobile apps and networks. Source-assisted where possible, with a focus on business logic and authorization flaws.
Reproducible findings, retestAI and LLM security
Adversarial testing of LLM applications and agents: prompt injection, tool abuse, data exfiltration and tenant isolation.
Abuse cases, guardrail reviewCloud and identity
Configuration review and attack-path analysis across AWS, Azure, GCP, Kubernetes, Active Directory and Entra ID.
Attack paths, prioritized fixesPurple team
Technique-by-technique exercises with your SOC to measure and improve detection coverage against ATT&CK.
Coverage map, tuned detectionsAdvisory
Threat modeling, architecture review and security leadership for teams without a full-time CISO.
Written recommendationsSpecialized assessments
Secure code review, mobile, social engineering, Active Directory, CI/CD and supply chain, Kubernetes, vulnerability research, compliance-driven testing.
Scoped to the target
Why Axesec
Senior engineers on every engagement.
Our team is made up of senior engineers: red team operators, application security engineers, and software and LLM engineers who build the kinds of systems we test. We hold OSCP, OSWE, OSCE and CEH certifications and have published CVEs.
Senior-led, manual testing
Every engagement is scoped, led and carried out by senior engineers. Scanners support the work. They are never the deliverable.
Findings you can reproduce
Each finding includes evidence, impact, CVSS severity, exact reproduction steps and remediation guidance written for your stack.
Retesting included
We verify your fixes and reissue the report, so the engagement ends with closed findings and an attestation letter you can share.
Confidential by default
We work under NDA and do not publish client names, logos or case studies.
Contact
Talk to an engineer.
Run scope below to start a request, or use the contact form. An engineer will reply, usually within one business day.
cat contact.txt
email hello@axesec.com
security security@axesec.com
pgp key available on request
location New York, NY