Pentest & offensive security
Penetration test delivered in 24 h, black box from the outside, or white box with your source code. A full report of leaks, intrusions and exploitable flaws.
Penetration testing, delivered in 24 h.
We attack your project before anyone else does.
GDR builds its own offensive testing tools: fast, reliable engines designed to go deep. We map your exposed surface, stress your defences and hand you a full report, data leaks, detected intrusions, exploitable flaws, within twenty-four hours.
gdr-sec scan --target your-project.com --mode hardened [✓] surface mapped · 46 endpoints · 12 subdomains [✓] leak scan · repos, dumps, pastes, keys [✓] auth / session / injection [✓] DDoS resilience · L3 L4 L7 · bots · WAF findings: critical 1 · high 3 · medium 7 report: delivered in 24h · pdf + remediation plan
Light pentest, black box
From the outside, with no access at all. We see exactly what an attacker sees: exposed services, forgotten subdomains, headers and certificates, leaked credentials, application entry points.
- Reconnaissance and external attack-surface mapping
- Leak hunting: public repositories, dumps, pastes, API keys
- Injection, authentication and session-handling tests
- Full report with prioritised fixes
Hardened pentest, white box
With your project's source code and access. The audit reaches into business logic, dependencies and server configuration, where external testing stops.
- Security-focused code review, line by line on sensitive paths
- Complete exploitation chains and privilege escalation
- Dependencies, secrets and CI/CD configuration
- Application, server and network hardening
Full report
For every flaw: the proof, the exploitation path, the business impact, the severity and the exact fix. Readable by your developers and your board alike.
Proprietary tooling
Our testing engines are built in-house. Faster, deeper, and none of your project's data ever passes through a third-party service.
Strictest standards
Methodology aligned with the industry's reference frameworks, OWASP Top 10, OWASP ASVS, PTES, MITRE ATT&CK, and with our own ISO 27001 requirements.
Leak detection
Credentials, tokens, API keys and exposed databases: we look for what has already left your system, on the open web and in dump distribution channels.
Intrusion traces
We look for signs of an existing compromise: webshells, ghost accounts, scheduled tasks and persistence mechanisms.
Re-test after fixes
Once your fixes are in, we replay the attack to confirm the flaw is genuinely closed, not merely hidden.
An attack never plays out on a single layer. We test and harden your protections level by level, from raw volumetric floods to the finest application request.
Volumetric & protocol
SYN floods, UDP/ICMP floods, DNS and NTP amplification: absorption capacity, upstream filtering and traffic failover under load.
Application
HTTP flood, slowloris, expensive queries, search and API abuse: the attacks that slip under volumetric thresholds and saturate your servers at low bandwidth.
Bots & automated abuse
Credential stuffing, abusive scraping, form fraud: behavioural detection, progressive challenges and rate limiting.
Filtering & rules
Fine-tuned WAF rules, rate limiting, geo-filtering and allow/deny lists, every rule validated by replaying a real attack.
Every engagement runs within a scope agreed in advance and under written authorisation from the system owner.
Reply within one business day
Every request gets a substantive answer within one working day, from first contact to support.
Fixed quote, written scope
Price and timeline set before the first line of code. What is sold is what ships, with no surprises along the way.
Everything stays in-house
Design, code, hosting and monitoring by the same team, with no subcontracting.
Guaranteed reversibility
Your code and data belong to you: full export and documentation handed over on request.
