Axesec

Services

Offensive security services.

Six core services, followed by specialized assessments. Scope, depth and duration are set per engagement. All work is manual and senior-led, and every engagement includes a retest.

Adversary simulation

Red team operations

Objective-based adversary simulation. You set the objective, such as access to a payment system, source code or executive mail. We pursue it using the tactics of real threat actors while your defenders operate as normal. The result measures prevention, detection and response together.

Scope
  • External, assumed-breach or full-scope
  • Phishing and social engineering
  • Initial access, lateral movement, privilege escalation
  • Active Directory, Entra ID and cloud pivoting
  • Custom tooling and command-and-control
Common drivers
  • A mature program that has outgrown penetration tests
  • Validating SOC, MDR or EDR investment
  • Board or regulator request for threat-led testing
Deliverables
  • Attack narrative with full timeline
  • Techniques mapped to MITRE ATT&CK
  • Detection and response gap analysis
  • Technical and executive debriefs

Application, network, device

Penetration testing

Manual penetration testing of a defined target. We test black-box, gray-box or white-box, and prefer source-assisted testing because it finds more in less time. Coverage follows OWASP ASVS and the OWASP testing guides. The findings that matter come from an engineer working through your business logic.

Scope
  • Web applications and APIs (REST, GraphQL, gRPC)
  • Mobile applications, iOS and Android
  • External and internal networks
  • Thick clients and desktop applications
  • Authentication, authorization and multi-tenancy
Common drivers
  • Product launch or major release
  • Customer security questionnaires and enterprise deals
  • SOC 2, ISO 27001, PCI DSS, HIPAA
  • NYDFS 23 NYCRR Part 500 annual testing
Deliverables
  • Findings with evidence, CVSS and reproduction steps
  • Remediation guidance for your stack
  • Retest of every finding
  • Attestation letter for customers and auditors

Models, agents, pipelines

AI and LLM security

Security assessment of LLM applications, agents and the systems around them. Our LLM and agentic engineers build these systems, which is why they know where they break. Testing is aligned to the OWASP Top 10 for LLM Applications and MITRE ATLAS, and covers the conventional application layer underneath.

Scope
  • Direct and indirect prompt injection
  • Tool, function-calling and agent abuse
  • RAG poisoning and data exfiltration
  • Tenant isolation and authorization
  • Guardrails, sandboxing and output handling
  • MCP servers and third-party integrations
Common drivers
  • Shipping an assistant or agent to customers
  • Agents with access to tools, code or internal data
  • Enterprise buyers asking for AI security evidence
Deliverables
  • Abuse cases demonstrated end to end
  • Architecture and guardrail review
  • Regression test cases for your evaluation suite

AWS, Azure, GCP, IdP

Cloud and identity

Configuration review and attack-path analysis for cloud and identity environments. We start from a realistic foothold, such as a compromised developer workstation or a leaked access key, and demonstrate which paths lead to production data and administrative control.

Scope
  • AWS, Azure and GCP
  • IAM policies, roles and trust relationships
  • Kubernetes and container platforms
  • Active Directory, Entra ID, Okta
  • CI/CD pipelines and secrets management
Common drivers
  • Rapid growth or a recent migration
  • Multi-cloud or complex identity federation
  • Preparation for a red team
  • Post-incident hardening
Deliverables
  • Attack-path map from foothold to critical assets
  • Misconfigurations ranked by attack paths closed
  • Infrastructure-as-code fixes where practical

With your defenders

Purple team

Collaborative exercises with your SOC or detection engineering team. We execute attacker techniques one at a time while your team checks telemetry, alerts and response. Gaps are fixed and the technique is rerun in the same session.

Scope
  • Technique coverage against MITRE ATT&CK
  • EDR, SIEM and cloud detection validation
  • Threat-actor emulation plans
  • Incident response tabletop exercises
Common drivers
  • New SOC, MDR provider or SIEM
  • Measuring detection coverage for leadership
  • Following up on red team findings
Deliverables
  • ATT&CK coverage map, before and after
  • New and tuned detection rules
  • Tabletop after-action report

Retained or per project

Advisory

Senior security engineering support for decisions that are expensive to reverse. For companies without a security leader, we can act as a fractional CISO while you hire.

Scope
  • Threat modeling and architecture review
  • Secure SDLC and application security programs
  • Vendor and product security evaluation
  • Fractional CISO and board reporting
Common drivers
  • New product or platform design
  • Building a security function from zero
  • Investor, acquirer or customer diligence
Deliverables
  • Written recommendations and roadmaps
  • Design review findings
  • A named advisor who knows your systems

Specialized

Specialized assessments

Focused work for specific targets and situations. Each can run alone or as part of a larger engagement.

Secure code review
Manual source review for vulnerabilities and design flaws, by engineers who write production software.
Social engineering
Phishing, vishing and pretext campaigns that measure how people and process hold up.
Active Directory and Entra ID
Identity attack paths, Kerberos and certificate services abuse, tiering and hardening review.
CI/CD and supply chain
Build pipelines, runners, artifact integrity, dependency risk and secrets exposure.
Kubernetes and containers
Cluster configuration, workload isolation, escape paths and admission control.
Mobile applications
iOS and Android clients, local storage, transport security and the backend APIs they call.
Vulnerability research and exploit development
Targeted research against a product or dependency you rely on, with coordinated disclosure.
Compliance-driven testing
Testing scoped to SOC 2, PCI DSS, ISO 27001, HIPAA and NYDFS Part 500 requirements, without reducing the work to a checkbox exercise.

Contact

Not sure what you need? Start with a scoping call.

Run scope below to start a request, or use the contact form. An engineer will reply, usually within one business day.

cat contact.txt

email hello@axesec.com

security security@axesec.com

pgp key available on request

location New York, NY