Skip to content
TheoSec

Offensive security

There's always a way in.

Rarely a missing patch. Usually a workflow nobody thought to question, an approval that trusts the wrong field, a boundary that holds everywhere except here.

The difference

A scanner has never asked a question.

Which workflow stops the company if it breaks?
Nothing in the code says which one matters.
How is authorisation supposed to behave?
A tool can only see how it does behave.
Where does a new system still trust an old one?
Trust is a decision somebody made, not a header.

How an engagement runs

Machines for breadth. People for depth.

  1. 01Outsider reconMap what an unauthenticated attacker sees before they have any help from you.
  2. 02Context alignmentStop enumerating technology and start modelling business risk.
  3. 03Deep-context exploitationWeaponise that context against the gap between design and reality.

Phase two is the one most firms skip. It is a working session with your engineers, and it is why phase three finds anything a scanner could not.

OWASP · PTES · NIST SP 800-115 · MITRE ATT&CK · CVSS

Capabilities

Five ways to find out where you stand.

00By invitation · 90 minutes · No cost

Executive Adversary Briefing

A private session with your leadership on how someone would actually come after you: who targets your sector, what your public footprint already gives away, and the three routes in we would try first. We give away the thinking, not a scan.

  • Threat actors credibly targeting your sector
  • What your public footprint already discloses
  • The three routes in we would try first
  • Straight answers, in the room, no report to chase
Explore Executive Adversary Briefing
01Six-month engagement · Continuous

Managed Red Team

A standing adversary for your organisation. Continuous offensive testing across your technology and your people, with executive reporting every month.

  • Baseline assessment in month one
  • Weekly external testing & OSINT monitoring
  • Three social engineering campaigns monthly
  • Executive reporting with trend analysis
Explore Managed Red Team
02Objective-based · Full-scope

Red Team Assessment

Not a list of vulnerabilities — a single question, answered honestly. Can a capable adversary reach the thing you cannot afford to lose? Technology, people and process are all in scope, because they are all in scope for the people who mean it.

  • A defined objective, not a coverage checklist
  • Technology, people and physical in one engagement
  • Detection and response measured as you go
  • Full attack narrative, start to objective
Explore Red Team Assessment
03Point-in-time · Scoped to you

Penetration Testing

Real-world attack simulation across applications, networks, cloud and devices — executed by hand, reported in plain language, prioritised by genuine business risk.

  • Web applications & APIs
  • External & internal networks
  • Cloud infrastructure (AWS, Azure, GCP)
  • Mobile & IoT devices
Explore Penetration Testing
04Ongoing · Human-crafted

Phishing & Social Engineering

Multi-channel campaigns written by an operator using your real business context, plus the live training that turns a failed test into a lasting habit. Never a template library.

  • Email, SMS, voice and social channels
  • Pretexts built from your real business context
  • Teachable-moment training at the point of failure
  • Live awareness sessions for staff and executives
Explore Phishing & Social Engineering
Daniel Scragg, Founder and Principal Consultant at Theosec

The practitioner

Daniel Scragg

Founder & Principal Consultant

A principal leads every engagement, reviews every finding, and is the person you speak to from first call to retest. A larger firm will sell you more people. It will not sell you more attention.

OSCPOSEPOSWECRTOeWPTXCREST CRT

Every one earned by compromising live systems under examination conditions.

Next step

Find out what an attacker already knows.

Every engagement starts with a conversation and a mutual NDA — not a sales pipeline. Tell me what you are worried about and I will tell you honestly whether I can help.

daniel@theosec.com · +27 63 484 1051