Map
A staging subdomain spotted in a certificate, missing from the inventory.
- DNS
- OSINT
- WHOIS
Continuous offensive auditing of your external surface.
Scroll, or use the arrow keys
Two distinct clients, the same stakes
Supports its clients through their IT transformation.
Continuous monitoring of client infrastructure, white-label scans.
Remote code execution on a WordPress instance (wp2shell)
↳Compromise of a hosted client environment
Exposed database credentials
↳Alteration or destruction of business data
Advisory in health, protection, retirement and employee savings.
Mapping of outsourced services, external and internal perimeter scans.
Administration console reachable without authentication
↳Anonymous takeover of the business application, from development to production
XSS on the policyholder portal
↳Silent exfiltration of login credentials
From one forgotten WordPress to full compromise.
Passive enumeration from the domain name alone, with no authentication and no agent
Fingerprinting of the technologies and versions running on each asset
CVE-2026-63030, unauthenticated file upload, exploitation replayed
wp-config.php read, connection credentials stored in cleartext
Lessons from wp2shell, a critical vulnerability affecting WordPress
wp2shell disclosed and patches published
Detection module developed and rolled out automatically
First vulnerable instances detected
Working exploit code goes public
Exploit replayed and wired into the scan
Findings confirmed and alerts sent
The report already describes a system that changed.
from scoping to debrief
per audit
and eleven months without visibility
of initial access starts with an exploited vulnerability
Verizon DBIR 2026, over 22,000 breaches analyzed. The leading initial access vector, ahead of stolen credentials, against 20% a year earlier.
to remediate an actively exploited vulnerability
Verizon DBIR 2026, median time to fix a flaw listed in CISA’s KEV catalog. It was 32 days a year earlier.
average cost of a data breach
IBM Cost of a Data Breach 2026, 602 organizations, March 2025 to February 2026. Global average, up 12% in one year.
A work email, and nothing to install.
A staging subdomain spotted in a certificate, missing from the inventory.
A Swagger left public, describing the API and its internal routes.
A SQL injection confirmed by the data it returns.
A critical finding pushed to Slack the night it appears.
A staging subdomain spotted in a certificate, missing from the inventory.
A Swagger left public, describing the API and its internal routes.
A SQL injection confirmed by the data it returns.
A critical finding pushed to Slack the night it appears.
A staging subdomain spotted in a certificate, missing from the inventory.
A Swagger left public, describing the API and its internal routes.
A SQL injection confirmed by the data it returns.
A critical finding pushed to Slack the night it appears.
The PoC used, the extracted data, the command to replay the test.


more subdomains discovered
On tesla.com, subdomains with an active DNS A record.
more exploitable vulnerabilities
Anonymous scan in default configuration against the hackazon platform.
Bug bounty on YesWeHackSee the counter

€20kper audit
The usual format, to be repeated from one year to the next.
From €5,000excl. VAT per year
The perimeter rebuilds itself, and the scanning never stops.
Pricing scales with the size of the perimeter to audit.
A demo, no commitment.
Passive preview, no sign-up. It reads public sources about the domain you enter.
