The same people who find it, write it up.
LahavSec is a small offensive security practice. Small is the point: the person who scopes your engagement is the person who runs it, and the person who wrote the tooling it runs on.
Deliberately small.
Most penetration testing is sold by one person and delivered by another. A principal walks you through the methodology, a junior with a scanner profile does the work, and your team spends the next month sorting real risk from noise.
LahavSec is led by Yaniv Avisror, who spent nine years running enterprise infrastructure as an IT professional (MCSA, MCSE) before spending five attacking it. He scopes the engagement, runs the testing across web, mobile, cloud and Active Directory, writes the report, and builds the validation tooling the whole practice runs on. On larger engagements and for second-opinion validation he brings in a short standing list of testers we have worked with long enough to vouch for, and you are told who will be on your engagement before it starts.
That constraint costs us volume. It buys you an assessment where every finding was reproduced by hand before it reached the page.
Four commitments.
Not values on a wall. These are the rules the methodology and the tooling are built around, and you can hold us to each of them.
Nothing ships unconfirmed
A potential finding is not a finding. Every issue is validated against a baseline before it enters the report, and anything that fails is demoted or dropped.
Paths, not tickets
One finding is a ticket. A path is a breach. We chain issues into the routes an attacker would walk, because severity in isolation understates what they can reach.
Your data stays yours
Analysis runs inside the perimeter you authorize. Nothing goes to third-party services for triage, and scope is enforced technically, not just agreed on paper.
The report is for your engineers
Evidence, reproduction steps, prioritized remediation, and detection content, as SARIF, JSON and HTML mapped to MITRE ATT&CK. It drops into the tools you run.
Nine years building it.
Five years breaking it.
The most useful part of our background is not the offensive training. It is the years of running the infrastructure first: configuring the domain, owning the escalation ticket, and living with the trade-offs that create the misconfigurations we now go looking for.
Active Directory & infrastructure
- Certified Red Team Expert (CRTE) · Altered Security
- Active Directory Attacks
- Windows Privilege Escalation
- Linux Privilege Escalation
- Infrastructure Pentesting
Application & API
- Practical API Hacking · TCM Security
- Mobile Application Penetration Testing (iOS & Android) · TCM Security
- Pentesting Web Application
Reconnaissance & cloud
- OSINT · TCM Security and ITSafe
- AWS Practitioner
- Cisco CCNA · routing and switching
Defensive side
- SOC Analyst career path · 260 hours
- Blue Team Incident Response
- Malware Research
CRTE is a proctored, hands-on certification. The rest are completed training programs, listed because they show where the hours went, not because a certificate proves anything on its own. What proves it is the work: ask for a sample report and a reference before you sign anything.
Coordinated disclosure
A trust-boundary bypass discovered during independent research and reported through coordinated disclosure.
Ask us
anything first.
Scoping conversations are free and unhurried. Tell us what you are protecting and what you are worried about, and we will tell you honestly whether an assessment is the right next step, and who would run it.