Security audits for small businesses and local shops

I test your network, your systems and your access controls using the same techniques someone would use to break in, and hand you a clear report covering what is broken, how much it matters, and the order to fix it in.

1. Initial access12. User credentials23. Lateral movement34. Service account45. Full control5

Step 1 of 5

Initial access

Someone joins the guest WiFi, or opens an email with a prepared attachment.

Services

How I can help

Three ways to work together, depending on what you need and where you are starting from.

See the services in detail
How I work

Two fronts, not one

An audit that only attacks finds whatever happens to be easy to find. One that only reviews configuration cannot tell you whether a weakness is genuinely exploitable. I do both and cross the results, so every finding comes with proof that it is real and with the underlying cause behind it.

From outside, as an attacker would

I test from specific, realistic positions: someone on the guest WiFi, a compromised office machine, or someone on the internet who can only see what you expose. With no prior knowledge of the infrastructure, so I see what a stranger sees.

From inside, reviewing the configuration

With access to the systems I review permissions, backups, passwords, patching and network segmentation. Many of the problems that cause the most damage never show up under attack, they show up when you read the configuration carefully.

Portfolio

Work you can check yourself

You do not have to take my word for any of this. I publish full technical writeups, step by step, of complete intrusions in authorised lab environments.

Security audit for a real company

A direct engagement for a company, with an executive report and a technical report delivered. The content is confidential, but you can see the exact format of the deliverable in the sample reports.

See the full portfolio

See all writeups

About

Álvaro Irún

I am self taught. I single handedly run the technical operations of a virtual reality entertainment venue, covering networks, point of sale and systems, and I am building Domain Security alongside it. I publish writeups of Hack The Box machines, mostly Active Directory, and I am currently studying for the CompTIA Security+ certification.

Read the longer version

Shall we talk?

Tell me what you have running and what worries you. I will look at whether an audit makes sense in your case and, if I think you do not need one, I will say so.