Home  /  About
About LahavSec

The same people who find it, write it up.

LahavSec is a small offensive security practice. Small is the point: the person who scopes your engagement is the person who runs it, and the person who wrote the tooling it runs on.

01
The practice

Deliberately small.

Most penetration testing is sold by one person and delivered by another. A principal walks you through the methodology, a junior with a scanner profile does the work, and your team spends the next month sorting real risk from noise.

LahavSec is led by Yaniv Avisror, who spent nine years running enterprise infrastructure as an IT professional (MCSA, MCSE) before spending five attacking it. He scopes the engagement, runs the testing across web, mobile, cloud and Active Directory, writes the report, and builds the validation tooling the whole practice runs on. On larger engagements and for second-opinion validation he brings in a short standing list of testers we have worked with long enough to vouch for, and you are told who will be on your engagement before it starts.

That constraint costs us volume. It buys you an assessment where every finding was reproduced by hand before it reached the page.

banner headers reflected cross-tenant low med high CRIT
Four findings a scanner would rank low to high. Walked in order, they are a tenant boundary falling over.
02
How we work

Four commitments.

Not values on a wall. These are the rules the methodology and the tooling are built around, and you can hold us to each of them.

01

Nothing ships unconfirmed

A potential finding is not a finding. Every issue is validated against a baseline before it enters the report, and anything that fails is demoted or dropped.

02

Paths, not tickets

One finding is a ticket. A path is a breach. We chain issues into the routes an attacker would walk, because severity in isolation understates what they can reach.

03

Your data stays yours

Analysis runs inside the perimeter you authorize. Nothing goes to third-party services for triage, and scope is enforced technically, not just agreed on paper.

04

The report is for your engineers

Evidence, reproduction steps, prioritized remediation, and detection content, as SARIF, JSON and HTML mapped to MITRE ATT&CK. It drops into the tools you run.

03
Background & credentials

Nine years building it.
Five years breaking it.

The most useful part of our background is not the offensive training. It is the years of running the infrastructure first: configuring the domain, owning the escalation ticket, and living with the trade-offs that create the misconfigurations we now go looking for.

9 years
Enterprise IT and infrastructure. Microsoft Certified Solutions Associate (MCSA) and Microsoft Certified Solutions Expert (MCSE).
5 years
Offensive security: penetration testing, red team operations, and vulnerability research.
CRTE
Certified Red Team Expert, Altered Security, January 2025. A fully hands-on exam: compromise a live multi-domain Active Directory lab and document it.

Active Directory & infrastructure

  • Certified Red Team Expert (CRTE) · Altered Security
  • Active Directory Attacks
  • Windows Privilege Escalation
  • Linux Privilege Escalation
  • Infrastructure Pentesting

Application & API

  • Practical API Hacking · TCM Security
  • Mobile Application Penetration Testing (iOS & Android) · TCM Security
  • Pentesting Web Application

Reconnaissance & cloud

  • OSINT · TCM Security and ITSafe
  • AWS Practitioner
  • Cisco CCNA · routing and switching

Defensive side

  • SOC Analyst career path · 260 hours
  • Blue Team Incident Response
  • Malware Research

CRTE is a proctored, hands-on certification. The rest are completed training programs, listed because they show where the hours went, not because a certificate proves anything on its own. What proves it is the work: ask for a sample report and a reference before you sign anything.

Research

Coordinated disclosure

A trust-boundary bypass discovered during independent research and reported through coordinated disclosure.

Work with us

Ask us
anything first.

Scoping conversations are free and unhurried. Tell us what you are protecting and what you are worried about, and we will tell you honestly whether an assessment is the right next step, and who would run it.

Direct line contact@lahavsec.com
Offensive Security · Defensive Value
Accepting new engagements