// offensive security & ai-agent penetration testing

We break what
others trust.

agent::offense is an offensive security team attacking the full modern stack — web, API, cloud, infrastructure and the emerging attack surface of autonomous AI agents. We find the exploit path before a real adversary does.

01 — practices

penetration testing & ai-agent security services

Every service is delivered adversary-first: manual, exploit-driven testing backed by reproducible proof and clear remediation — not a template scanner report.

01

Web Application Penetration Testing

Manual web application penetration testing against the OWASP Top 10 and business-logic flaws. Exploit-driven testing with reproducible PoCs…

  • Broken access control & IDOR
  • SQL, NoSQL & command injection
  • Authentication & session management flaws
./open →
02

API Penetration Testing

REST and GraphQL API penetration testing against the OWASP API Top 10 — BOLA, BFLA, mass assignment, auth…

  • Broken object-level authorization (BOLA)
  • Broken function-level authorization (BFLA)
  • Mass assignment & excessive data exposure
./open →
03

Mobile Application Penetration Testing

iOS and Android mobile application penetration testing — static and dynamic analysis, runtime instrumentation, secret extraction and API…

  • Hardcoded secrets, keys & token extraction
  • Insecure local & keychain storage
  • Certificate-pinning & root/jailbreak bypass
./open →
04

GraphQL Security Testing

Specialist GraphQL security testing — introspection abuse, query depth and batching DoS, authorization gaps per resolver, and injection…

  • Introspection & schema disclosure
  • Per-resolver authorization (IDOR) gaps
  • Alias/batching rate-limit bypass
./open →
05

Secure Code Review

Manual secure code review backed by SAST — data-flow and taint analysis, secrets detection and insecure-pattern audit to…

  • Taint & data-flow analysis
  • Injection and unsafe deserialization
  • Authentication & authorization logic flaws
./open →
06

OWASP Top 10 Penetration Testing

OWASP Top 10 penetration testing — manual, exploit-led assessment against every OWASP risk category.

  • Broken access control (OWASP A01)
  • Cryptographic failures (A02)
  • Injection: SQL, NoSQL, command, LDAP (A03)
./open →
07

E-Commerce Penetration Testing

E-commerce penetration testing — payment, cart and checkout logic tested by hand. PCI DSS & OWASP aligned.

  • Payment and checkout flow abuse
  • Price and quantity manipulation
  • Coupon, discount and loyalty-point abuse
./open →
08

SaaS Penetration Testing

SaaS penetration testing — multi-tenant isolation, RBAC and API security tested by hand.

  • Tenant isolation and cross-tenant access
  • Role-based access control (RBAC) enforcement
  • Cross-tenant IDOR and data leakage
./open →
09

WordPress & CMS Penetration Testing

WordPress & CMS penetration testing — core, plugins, themes and config tested for real exploitability.

  • Core, plugin and theme vulnerabilities (known CVEs)
  • Authentication, brute-force and user enumeration
  • File upload and remote code execution
./open →
10

Single-Page Application (SPA) Penetration Testing

SPA penetration testing — React, Angular and Vue apps tested for client-side and API-side risk.

  • Client-side access control and hidden functionality
  • Token storage and JWT handling
  • DOM-based XSS and client-side injection
./open →
11

PCI DSS Penetration Testing

PCI DSS penetration testing — CDE, segmentation and application testing aligned to PCI DSS 4.0 requirement 11.4.

  • Cardholder data environment (CDE) scoping
  • Network segmentation control testing (11.4.5)
  • External penetration testing of the CDE perimeter
./open →
12

SQL Injection Testing

SQL injection testing — manual detection and safe exploitation of SQLi across every input, as part of a…

  • Error-based and UNION-based SQL injection
  • Blind SQLi (boolean and time-based)
  • Second-order and stored SQL injection
./open →
13

Cross-Site Scripting (XSS) Testing

Cross-site scripting (XSS) testing — reflected, stored and DOM-based XSS found and proven by hand.

  • Reflected XSS across every input and context
  • Stored/persistent XSS in saved content
  • DOM-based XSS in client-side JavaScript
./open →
14

Broken Access Control & IDOR Testing

Broken access control & IDOR testing — the number-one web risk, tested across every role and object.

  • Horizontal access control (cross-user IDOR)
  • Vertical access control (privilege escalation)
  • Object-level authorization on every reference
./open →
15

SSRF Testing

SSRF testing — server-side request forgery hunted across every server-initiated request, including cloud metadata.

  • Basic and blind server-side request forgery
  • Cloud metadata access (169.254.169.254)
  • Internal service and port discovery via SSRF
./open →
16

Thick Client Application Penetration Testing

Thick client & desktop application penetration testing — binaries, local storage, IPC and back-end traffic tested end to…

  • Binary and reverse-engineering analysis
  • Local data storage and configuration security
  • Traffic interception and TLS validation
./open →
17

PCI DSS 4.0 Penetration Testing

PCI DSS 4.0 penetration testing — segmentation, authenticated scanning and application-layer testing aligned to the requirements now fully…

  • Cardholder data environment network penetration testing
  • Application-layer penetration testing (CDE-connected systems)
  • Segmentation testing (Requirement 11.4.5)
./open →
18

Penetration Testing as a Service (PTaaS)

Penetration testing as a service — continuous, manual, exploit-led testing on a subscription model instead of a once-a-year…

  • Initial full-depth manual penetration test
  • Continuous retesting of changed & new features
  • Live findings dashboard & remediation tracking
./open →
19

External Network Penetration Testing

External network penetration testing of your internet-facing perimeter — exposed services, misconfigurations and exploitable hosts, tested from an…

  • Attack-surface & service enumeration
  • Exposed admin panels & default credentials
  • Exploitable service vulnerabilities
./open →
20

Internal Network Penetration Testing

Internal network penetration testing — lateral movement, privilege escalation and segmentation review from an assumed-breach position inside your…

  • Lateral movement & privilege escalation
  • Credential harvesting & reuse attacks
  • Network segmentation validation
./open →
21

Wireless Network Penetration Testing

Wireless penetration testing — WPA2/WPA3 attacks, rogue access points, client isolation and guest/corporate segmentation testing across your Wi-Fi…

  • WPA2/WPA3 authentication attacks
  • Rogue AP & evil-twin susceptibility
  • Client isolation & de-authentication
./open →
22

Firewall & Configuration Review

Firewall and infrastructure configuration review — rule-base audit, segmentation validation and hardening against CIS benchmarks to shrink your…

  • Firewall rule-base & any-any audit
  • Network segmentation & zoning review
  • CIS benchmark configuration gaps
./open →
23

IoT Device Penetration Testing

IoT and embedded device penetration testing — firmware analysis, hardware interfaces, wireless protocols and cloud/app backends across the…

  • Firmware extraction & analysis
  • Hardware interfaces (UART/JTAG/SPI)
  • Wireless protocol attacks (BLE/Zigbee)
./open →
24

OT / ICS / SCADA Penetration Testing

OT, ICS and SCADA penetration testing — safely assess PLCs, HMIs and industrial networks, validate IT/OT segmentation and…

  • IT/OT segmentation & Purdue-zone validation
  • Exposed HMI, SCADA & engineering-station review
  • PLC/RTU configuration & default-credential testing
./open →
25

AWS Penetration Testing

AWS penetration testing — IAM privilege escalation, S3 and storage exposure, SSRF-to-metadata, and misconfiguration review mapped to attacker…

  • IAM privilege escalation paths
  • S3 and storage exposure
  • SSRF-to-instance-metadata (IMDS) abuse
./open →
26

Azure Penetration Testing

Azure penetration testing — Entra ID (Azure AD) attack paths, role and consent abuse, storage exposure and misconfiguration…

  • Entra ID role & consent abuse
  • Managed identity & service principal attacks
  • Subscription privilege escalation
./open →
27

GCP Penetration Testing

Google Cloud Platform penetration testing — service account abuse, IAM privilege escalation, storage exposure and project-level misconfiguration review.

  • Service account impersonation & key abuse
  • IAM privilege escalation paths
  • Cloud Storage bucket exposure
./open →
28

Kubernetes Penetration Testing

Kubernetes penetration testing — container escape, RBAC misconfiguration, exposed control plane, and pod-to-cluster-admin escalation across your clusters.

  • Container escape & privileged pods
  • RBAC & service-account misconfiguration
  • Exposed API server, etcd & kubelet
./open →
29

Cloud Configuration Review

Cloud configuration review across AWS, Azure and GCP — CIS benchmark gaps, IAM hygiene, exposure and logging coverage…

  • CIS benchmark configuration gaps
  • IAM hygiene & over-privileged access
  • Public exposure of storage & services
./open →
30

Container Security Assessment

Container security assessment — Docker image analysis, supply-chain review, runtime hardening and registry exposure across your containerized workloads.

  • Image layer & dependency analysis
  • Secrets in build args & layers
  • Registry exposure & access control
./open →
31

Red Team Operations

Full-scope red team operations — stealthy, objective-driven attack simulation across digital, human and physical vectors to test detection…

  • Objective-based full kill-chain attack
  • Initial access via phishing & exposure
  • Command-and-control & evasion
./open →
32

Social Engineering Assessment

Social engineering assessment — targeted phishing, vishing and pretext attacks that measure your human attack surface and security-awareness…

  • Targeted spear-phishing campaigns
  • Vishing (voice) pretext calls
  • Payload delivery & credential capture
./open →
33

Phishing Simulation

Phishing simulation services — realistic, authorized email campaigns that measure click, credential-entry and reporting rates to strengthen human…

  • Tailored phishing lure design
  • Click and credential-entry tracking
  • Reporting-rate measurement
./open →
34

Physical Penetration Testing

Physical penetration testing — tailgating, badge cloning, lock bypass and on-site access attempts that test whether an intruder…

  • Tailgating & social entry
  • RFID/badge cloning & bypass
  • Lock picking & door bypass
./open →
35

Assumed Breach Assessment

Assumed breach assessment — start from a compromised foothold to measure blast radius, lateral movement and how far…

  • Post-compromise lateral movement
  • Privilege escalation to critical systems
  • Credential harvesting & reuse
./open →
36

Ransomware Readiness Assessment

Ransomware readiness assessment — attack-path simulation, backup and recovery validation, and detection testing against real ransomware TTPs.

  • Initial-access & foothold simulation
  • Privilege escalation & Active Directory attack paths
  • Credential theft & lateral movement
./open →
40

AI Agent Penetration Testing

Penetration testing for autonomous AI agents — tool-use abuse, goal hijacking, privilege escalation and sandbox escape across agentic…

  • Tool-use & function-calling abuse
  • Goal hijacking & instruction override
  • Privilege escalation through agent tools
./open →
41

Prompt Injection Testing

Prompt injection testing — direct and indirect injection across every untrusted input path, including RAG and tool outputs,…

  • Direct prompt injection
  • Indirect injection via RAG & documents
  • Tool-output & web-content injection
./open →
42

LLM Jailbreak & Guardrail Testing

LLM jailbreak and guardrail testing — systematic evaluation of safety controls, policy evasion and harmful-output elicitation with reproducible…

  • Guardrail & content-filter bypass
  • Policy evasion techniques
  • Harmful-output elicitation
./open →
43

RAG Pipeline Security Assessment

RAG security assessment — vector-store poisoning, context leakage, access-control gaps and retrieval-based prompt injection across your RAG pipeline.

  • Vector-store & document poisoning
  • Retrieval-based prompt injection
  • Cross-tenant context leakage
./open →
44

MCP Server & Tool-Chain Security Testing

MCP server security testing — tool schema tampering, confused-deputy paths, credential-scope leakage and abuse of Model Context Protocol…

  • MCP server & tool abuse
  • Tool schema tampering & poisoning
  • Confused-deputy & privilege paths
./open →
45

AI Supply Chain Security Audit

AI supply chain security audit — model provenance, plugin and extension risk, dataset integrity and fine-tune leakage across…

  • Model provenance & integrity
  • Plugin & extension risk review
  • Dataset integrity & poisoning exposure
./open →
46

LLM Application Penetration Testing

LLM application penetration testing — the full stack around your model: prompts, plugins, APIs, output handling and the…

  • Prompt injection & output handling
  • Insecure plugin & tool integration
  • Sensitive information disclosure
./open →
47

Agentic AI Threat Modeling

Agentic AI threat modeling — structured analysis of autonomous agent workflows, trust boundaries and abuse cases to secure…

  • Agent workflow & data-flow mapping
  • Trust boundary identification
  • Abuse-case & threat enumeration
./open →
48

NIS2 & DORA Compliance Readiness

NIS2 and DORA compliance readiness — gap analysis, ICT risk assessment and the pentesting and TLPT these EU…

  • NIS2 risk-management & reporting gap analysis
  • DORA ICT-risk & operational-resilience assessment
  • Threat-led penetration testing (TLPT / TIBER-EU) scoping
./open →
49

SOC 2 Penetration Testing

SOC 2 penetration testing mapped to the Trust Services Criteria — the evidence auditors and enterprise customers expect…

  • Production web application & API penetration testing
  • Cloud infrastructure & configuration review
  • Trust Services Criteria (CC7.1 / CC4.1) evidence mapping
./open →
50

HIPAA Penetration Testing

HIPAA penetration testing and Security Risk Assessment support for covered entities and business associates — manual testing of…

  • PHI-handling application & API penetration testing
  • EHR & patient-portal integration security testing
  • Cloud infrastructure hosting PHI — configuration review
./open →
51

CMMC Penetration Testing

CMMC Level 2 penetration testing mapped to NIST SP 800-171 — the technical evidence defense contractors need to…

  • CUI enclave & connected-system penetration testing
  • NIST 800-171 control gap analysis
  • Vulnerability scanning & assessment (RA.L2-3.11.2 evidence)
./open →
52

NYDFS Cybersecurity Regulation Penetration Testing

NYDFS Cybersecurity Regulation (23 NYCRR 500) penetration testing — annual and biannual testing evidence for New York-regulated financial…

  • Information systems penetration testing (§500.05 annual requirement)
  • Biannual vulnerability assessment
  • Multi-factor authentication implementation testing
./open →
53

GLBA Safeguards Rule Penetration Testing

GLBA Safeguards Rule (16 CFR 314) penetration testing — annual testing and biannual vulnerability assessment evidence for financial…

  • Customer information systems penetration testing (§314.4(d)(2))
  • Biannual vulnerability assessment
  • Access control & authentication testing
./open →
54

DORA TLPT — Threat-Led Penetration Testing

DORA-aligned threat-led penetration testing (TLPT) for EU financial entities — TIBER-EU-aligned scoping for significant entities, and resilience testing…

  • DORA applicability & TLPT-scope determination
  • Threat-intelligence-led attack scenario design (where TLPT applies)
  • Red-team simulation against production-aligned systems
./open →
55

NIS2 Compliance Penetration Testing

NIS2 penetration testing and compliance readiness for EU essential and important entities — Article 21 risk-management gap analysis…

  • Entity classification & Annex I/II scope determination
  • Article 21 risk-management measures gap analysis
  • External & internal network penetration testing
./open →
56

ISO 27001 Penetration Testing (Annex A.8.29)

ISO 27001 penetration testing mapped to Annex A.8.29 — the evidence certification auditors expect for security testing in…

  • External & internal network penetration testing
  • Web application & API penetration testing
  • Cloud configuration & access-control review
./open →
57

HITRUST CSF Penetration Testing

HITRUST CSF penetration testing — the technical evidence healthcare and healthtech organisations need to support r2 certification.

  • In-scope application & API penetration testing
  • Cloud infrastructure & configuration review
  • HITRUST CSF control evidence mapping
./open →
58

Cyber Essentials Plus Penetration Testing

Cyber Essentials Plus penetration testing and technical verification — the hands-on assessment component UK organisations need alongside self-assessment.

  • External vulnerability testing (firewall & boundary controls)
  • Internal vulnerability testing (secure configuration)
  • Access control & privilege verification
./open →
59

Cyber Insurance Penetration Testing

Penetration testing built to satisfy cyber insurance underwriting requirements — the evidence insurers and brokers increasingly demand before…

  • External perimeter & attack surface penetration testing
  • Remote access & VPN security testing
  • Backup isolation & immutability validation
./open →
60

M&A Cybersecurity Due Diligence Penetration Testing

Cybersecurity due diligence penetration testing for M&A and investment transactions — independent technical evidence of the security risk…

  • External perimeter & attack surface penetration testing
  • Core application & API penetration testing
  • Cloud infrastructure & configuration review
./open →
61

FedRAMP Penetration Testing

FedRAMP penetration testing aligned to CSP guidance — the technical evidence cloud service providers need for a 3PAO…

  • External network penetration testing (authorization boundary)
  • Internal network penetration testing
  • Mobile application testing (where in scope)
./open →
62

FFIEC Penetration Testing

FFIEC-aligned penetration testing for banks and financial institutions — technical evidence mapped to FFIEC IT examination handbook expectations.

  • Network penetration testing (examination-aligned scope)
  • Application penetration testing
  • Independent testing separate from internal vulnerability management
./open →
63

NIST-Aligned Penetration Testing

NIST-aligned penetration testing, following SP 800-115 methodology and mapped to the NIST Cybersecurity Framework — a defensible technical…

  • Network penetration testing (SP 800-115 methodology)
  • Application & API penetration testing
  • Cloud configuration review
./open →
64

NERC CIP Penetration Testing

NERC CIP penetration testing for bulk electric system owners and operators — technical evidence mapped to CIP-005 and…

  • Electronic Security Perimeter penetration testing (CIP-005)
  • Vulnerability assessment for baseline configuration changes (CIP-010)
  • Access control & authentication testing
./open →
65

EU Cyber Resilience Act Penetration Testing

Cyber Resilience Act penetration testing and SBOM-ready security testing for products with digital elements sold into the EU…

  • Product software & firmware penetration testing
  • Secure-by-default configuration review
  • Vulnerability handling & disclosure process review
./open →
66

NAIC Insurance Data Security Penetration Testing

Penetration testing aligned to the NAIC Insurance Data Security Model Law — technical evidence for insurers licensed in…

  • Nonpublic information systems penetration testing
  • Access control & authentication testing
  • Encryption implementation review
./open →
67

HECVAT Security Assessment Support

Penetration testing and evidence support for vendors completing the HECVAT security questionnaire required by US colleges and universities.

  • Production application & API penetration testing
  • Cloud infrastructure & configuration review
  • Vulnerability management process review
./open →
68

StateRAMP Penetration Testing

StateRAMP-aligned penetration testing for cloud service providers selling into US state and local government — the technical evidence…

  • Cloud infrastructure & configuration review
  • Application & API penetration testing
  • Access control & authentication testing
./open →
69

MiCA Penetration Testing

MiCA-aligned penetration testing for Crypto-Asset Service Providers operating in the EU — platform, custody and ICT risk testing…

  • CASP trading / exchange platform penetration testing
  • Custody & wallet infrastructure security testing
  • Key management & wallet separation review
./open →
70

PSD2 Security Penetration Testing

PSD2-aligned penetration testing for payment service providers and open banking platforms operating across the EU.

  • Strong customer authentication implementation testing
  • Open banking API penetration testing (AIS / PIS)
  • Payment platform & transaction integrity testing
./open →
02 — methodology

engagement flow

A disciplined, repeatable methodology from first recon to retest.

01

Scope & Recon

Define rules of engagement, map the full attack surface and set objectives.

02

Exploit

Manual, chained exploitation to prove real impact — not theoretical findings.

03

Report

Reproducible PoCs, severity calibration and prioritized, actionable fixes.

04

Retest

Verify remediation and confirm the attack path is genuinely closed.

03 — why it matters

why ai-agent security

Autonomous agents act with real permissions, call real tools and read untrusted data. That is a new, high-value attack surface most testing programs do not cover.

// threat

agents_execute

An LLM agent that can browse, run tools or move funds becomes an insider the moment it ingests attacker-controlled text. We test that boundary end to end.

// threat

trust_is_implicit

RAG stores, MCP servers and plugins are trusted by default. We treat every one of them as hostile input and prove where that assumption breaks.

Book a penetration test

Ready to see your systems the way an attacker does? Scope a pentest of your application, infrastructure or AI agents today.

Get in touch