All our expertise
GDR Security

Pentest & offensive security

Penetration test delivered in 24 h, black box from the outside, or white box with your source code. A full report of leaks, intrusions and exploitable flaws.

Offensive security

Penetration testing, delivered in 24 h.

We attack your project before anyone else does.

GDR builds its own offensive testing tools: fast, reliable engines designed to go deep. We map your exposed surface, stress your defences and hand you a full report, data leaks, detected intrusions, exploitable flaws, within twenty-four hours.

Request a pentest
Report delivered24 h
gdr-security · scan report
gdr-sec scan --target your-project.com --mode hardened

[✓] surface mapped · 46 endpoints · 12 subdomains
[✓] leak scan · repos, dumps, pastes, keys
[✓] auth / session / injection
[✓] DDoS resilience · L3 L4 L7 · bots · WAF

findings: critical 1 · high 3 · medium 7
report: delivered in 24h · pdf + remediation plan
Two levels of audit
LIGHT

Light pentest, black box

From the outside, with no access at all. We see exactly what an attacker sees: exposed services, forgotten subdomains, headers and certificates, leaked credentials, application entry points.

  • Reconnaissance and external attack-surface mapping
  • Leak hunting: public repositories, dumps, pastes, API keys
  • Injection, authentication and session-handling tests
  • Full report with prioritised fixes
HARDENED

Hardened pentest, white box

With your project's source code and access. The audit reaches into business logic, dependencies and server configuration, where external testing stops.

  • Security-focused code review, line by line on sensitive paths
  • Complete exploitation chains and privilege escalation
  • Dependencies, secrets and CI/CD configuration
  • Application, server and network hardening
What the audit covers

Full report

For every flaw: the proof, the exploitation path, the business impact, the severity and the exact fix. Readable by your developers and your board alike.

Proprietary tooling

Our testing engines are built in-house. Faster, deeper, and none of your project's data ever passes through a third-party service.

Strictest standards

Methodology aligned with the industry's reference frameworks, OWASP Top 10, OWASP ASVS, PTES, MITRE ATT&CK, and with our own ISO 27001 requirements.

Leak detection

Credentials, tokens, API keys and exposed databases: we look for what has already left your system, on the open web and in dump distribution channels.

Intrusion traces

We look for signs of an existing compromise: webshells, ghost accounts, scheduled tasks and persistence mechanisms.

Re-test after fixes

Once your fixes are in, we replay the attack to confirm the flaw is genuinely closed, not merely hidden.

Network protection & anti-DDoS

An attack never plays out on a single layer. We test and harden your protections level by level, from raw volumetric floods to the finest application request.

L3 / L4

Volumetric & protocol

SYN floods, UDP/ICMP floods, DNS and NTP amplification: absorption capacity, upstream filtering and traffic failover under load.

L7

Application

HTTP flood, slowloris, expensive queries, search and API abuse: the attacks that slip under volumetric thresholds and saturate your servers at low bandwidth.

BOT

Bots & automated abuse

Credential stuffing, abusive scraping, form fraud: behavioural detection, progressive challenges and rate limiting.

WAF

Filtering & rules

Fine-tuned WAF rules, rate limiting, geo-filtering and allow/deny lists, every rule validated by replaying a real attack.

Every engagement runs within a scope agreed in advance and under written authorisation from the system owner.

Our commitments

Reply within one business day

Every request gets a substantive answer within one working day, from first contact to support.

Fixed quote, written scope

Price and timeline set before the first line of code. What is sold is what ships, with no surprises along the way.

Everything stays in-house

Design, code, hosting and monitoring by the same team, with no subcontracting.

Guaranteed reversibility

Your code and data belong to you: full export and documentation handed over on request.

A project like this?

Tell us what you need, reply within one business day.