Services

Services

Seven ways we put your defenses under real pressure, scoped to your environment and aligned to how modern threat actors actually operate.

01 / Pentest

Penetration Testing

We perform comprehensive penetration tests targeting web applications, internal and external networks, cloud infrastructures, and mobile platforms. Our goal is to identify vulnerabilities before attackers do.

  • Web applications
  • Internal networks
  • External networks
  • Cloud
  • Mobile
02 / Simulation

Adversary Simulation

With threats evolving daily across industries such as finance and healthcare, we simulate real world attack scenarios to test your SOC's detection and response capabilities. Our simulations are designed to assess how well your team handles sophisticated, multi-stage intrusions.

  • SOC detection
  • Incident response
  • Multi-stage intrusion
03 / Emulation

Adversary Emulation

Advanced Persistent Threats are becoming increasingly sophisticated, leveraging AI tools, automation, and constantly shifting tactics, techniques, and procedures. We emulate real-world APTs with custom scenarios that match your threat profile, helping your team build effective detection and defense strategies.

  • APT emulation
  • Threat profiling
  • Custom TTPs
04 / Red Team

Red Team

Full-scope operations aligned to the MITRE ATT&CK Framework, reflecting modern threat actor behavior while evaluating your organization's detection, response, and containment capabilities.

  • Initial Access
  • Persistence
  • Defense Evasion
  • Lateral Movement
  • Objective-Based Intrusion
05 / Wireless

Wi-Fi Security Assessments

Wireless networks are often the weakest link. We assess vulnerabilities across WEP, WPA, WPA2, WPA3, and WPA-Enterprise, and demonstrate how adversaries reach internal systems through wireless infrastructure.

  • Password cracking
  • Rogue access points
  • Man-in-the-middle
06 / Cloud

Azure and Entra ID Assessments

Identity is the new perimeter. We assess Azure and Entra ID tenants the way an attacker approaches them: token theft and replay, consent and application abuse, conditional access gaps, privileged role paths, and hybrid trust between on-prem Active Directory and the cloud.

  • Entra ID
  • Token abuse
  • Conditional Access
  • Consent phishing
  • Hybrid AD trust
07 / Human

Social Engineering

Technology is not the only target. People are the first line of defense. We harden the human element of your organization against manipulation and deception.

  • Phishing campaigns
  • Impersonation
  • Awareness training

Tooling

ANIMO

Azure Network Intel & Mission Ops

Our own Azure and Microsoft 365 assessment platform, built in-house and used on engagements. It gives an operator one interface to manage multiple Azure sessions, work with tokens, enumerate cloud resources, and run post-exploitation against a tenant.

  • Capture, exchange, mint and analyse OAuth tokens, including access, refresh, PRT and SAS
  • WhoAmI discovery with derived capability verdicts and fine-grained ARM action enumeration
  • Reach Outlook, Calendar, Teams, OneDrive, SharePoint, Storage and Key Vault through Graph and ARM
  • Remote execution over Azure VM runCommand, uploaded webshells and SSTI payloads
  • Entra device registration for certificate-based persistence, TAP issuance and auth-method backdoors
  • Password, SPN and refresh-token sprays, with engagement report generation
  • C++17
  • Qt 6
  • Graph API
  • ARM API
  • PowerShell 7
  • Azure CLI
View on GitHub
ANIMO dashboard

Command and Control

Like a real intrusion

Full-scope operations from initial access through to objective, executed with our own tooling and command and control infrastructure. We build the infrastructure, we operate the implants, and we document every step so your team can rebuild the timeline afterwards.

C2 screenshots go here.
Drop images in assets/services/ and re-run the build.
See that folder's README for naming and redaction notes.

MITRE ATT&CK Enterprise

Aligned to the framework

Engagements map to ATT&CK tactics so findings land in the same language your blue team already uses.

10 of 14 tactics shown. Every technique links to MITRE ATT&CK.

Contact

Let's test your defenses.

Tell us what you want tested and we will scope an engagement around your environment, risks, and objectives. No two engagements are the same.

Email dgarcia@init1security.com

This form is not connected yet. Until it is, email dgarcia@init1security.com directly.