Offensive Security

Find vulnerabilities with real world impact

Penetration Testing

Identify vulnerabilities that could allow adversaries access to your systems and data. Vulnerabilities that put your business at significant risk of a compromise are not only damaging for you, they could have an impact on your employees and your customers.

Penetration testing is our bread and butter! Volkis “pentesting” services will find the vulnerabilities that could be used to hack your networks, web applications, mobile applications, wireless networks, core services and cloud environments. A skilled penetration tester will use the same tools, techniques, and instincts that an adversary would to break into your systems.

What vulnerabilities exist in my systems? Do I need to worry about it? What could attackers do to me if exploited? What can I do to prevent this? All these questions can be answered with a penetration test.

Web Application / API
Web Application / API

Make sure your bespoke web applications or APIs are resilient against attackers.

Internal
Internal

Find vulnerabilities from the perspective of an attacker inside your network.

External
External

Test your internet-facing servers and services against external threats.

Mobile
Mobile

Find those hidden vulnerabilities lurking inside your custom made mobile apps.

Microsoft 365
Microsoft 365

Take a different approach to cloud security and have us investigate your Microsoft 365 tenant for real-world vulnerabilities with demonstrated exploits.

Continuous penetration testing
Continuous penetration testing

Year-round coverage of your attack surface ensures pentests are not just a "point-in-time" exercise. Pentest your newly developed applications as soon as they are ready.

Detection alert testing
Detection alert testing

Volkis will deliberately set off alerts in a methodical way so you can see those alerts in action, allowing you to gain familiarity with the alerts and ensure they are working properly.

And more!
And more!

We employ various security experts with domain knowledge in less commonly penetration tested areas such as Wireless, Citrix, SCADA, or Desktop Applications. If you're unsure, reach out!

Our testing methodologies

Every engagement follows a documented methodology, modelled on industry standards such as OWASP and published in full in the Volkis Handbook.

Anonymised report

One of our clients allowed us to anonymise their real-world penetration testing report. You can see the report in our handbook with the link below.

Additional Handbook Links

Further reading from the Volkis Handbook on how we approach penetration testing.

Red Team Adversary Simulation

The Volkis Red Team will target your organisation over an extended period using skilled attackers, infrastructure specifically tailored to the engagement, and social engineering attacks to compromise sensitive information and core business services. You can test your organisation against a dedicated adversary, ensuring your security, detection, and incident response are up to scratch.

As close to a real-world hack as you can get, the engagement will be performed over a window period, usually 3-4 months. Our attackers will use drip scanning, passive investigation, and evasion techniques to get by your detection and response systems, breaking into your environment without being seen. The targets will be information and systems that are relevant to your organisation and likely targets for attackers. Instead of targets such as “compromise an administration account”, we look for key business services such as your CRM, financial systems, critical applications, and your web infrastructure to identify real, meaningful impact to your organisation.

Our testing methodology

Every Red Team engagement follows a documented methodology, published in full in the Volkis Handbook.

Anonymised report

Our anonymised red team report is a bit of an amalgamation of real world red teams we've performed - given red team reports are so specific to the organisation it's impossible to fully anonymise a single report. The link to the anonymised red team report is below.

Social Engineering

With Volkis social engineering exercises you can test the security awareness of your users, and incorporate the results into an ongoing security awareness programme.

Our social engineering capability includes:

  • Phishing attacks: We can send malicious emails to your users that will attempt to trick them into downloading software, providing credentials, or visiting a particular web site. Phishing attacks can be sent to a large number of users in a cost effective manner.
  • Vishing attacks (phone calls): We can test your employees or service desk to identify if they are likely to give out privileged information or credentials over the phone, or if they would be willing to undertake potentially damaging actions from an unknown source.
  • SMishing attacks (SMS): We can test your users’ abilities to detect a malicious text by sending SMS messages to their company phones. This text may instruct them to either download a malicious app or provide credentials.
  • Malicious USBs: We can provide malicious USBs that, when inserted into a user’s laptop or PC and executed, will call back to Volkis. This will test the likelihood of your users being tricked by a malicious attacker with physical access to your premises, or by someone who could send a USB stick through post.

Phishing campaign welcome pack

See what to expect from a Volkis phishing campaign before it begins, in our handbook.

Physical Intrusion

Sometimes the easiest way to get access to your sensitive data is to simply walk in and take it. Volkis’ physical intrusion services will test your organisation to see if that is possible.

Physical intrusion testing will test the resilience of your access control and physical protection systems to see if they can be bypassed or broken. Can your passes be duplicated by someone standing next to them in the elevator? Can someone simply walk through a back door or open a window?

Volkis will employ a variety of different attack types throughout the engagement to gain access. This can include:

  • Social engineering
  • Lock picking
  • Door bypasses
  • Badge cloning

If access is gained, the consultant will collect evidence to see what the impact from that physical access is. Depending on the rules of engagement, the consultant may take pictures of desks, access sensitive areas, or connect to the network using a laptop or a concealed network tap.

At the end of the engagement, the consultant will outline any weaknesses and provide actionable recommendations for improving the security of the physical premises. This could include improving access control, improving procedures and processes for handling entrants, or user education.

AI Assessment

As organisations race to adopt Artificial Intelligence (AI), they may be unknowingly introducing new attack surfaces that traditional penetration testing was never designed to assess. Prompt injection, insecure tool integrations, excessive permissions, model manipulation and data leakage can all allow an attacker to manipulate an AI system into performing actions outside its intended design, without ever exploiting a traditional software vulnerability.

Volkis’s AI Assessment (also known as AI Red Teaming) combines application security with specialist AI security testing to identify how attackers could manipulate your AI systems to produce unauthorised actions, expose sensitive information, bypass business controls or perform actions on behalf of your users.

Whether you’ve built your own AI application, integrated with leading foundation models, or deployed autonomous AI agents, we’ll assess the security of the complete solution — not just the underlying infrastructure.

Prompt Injection
Prompt Injection

Assess whether attackers can manipulate prompts to bypass safety controls, leak information or change the AI's behaviour.

AI Agents
AI Agents

Assess agents that interact with APIs, databases, email systems, ticketing platforms and other business services.

Retrieval Augmented Generation (RAG)
Retrieval Augmented Generation (RAG)

Evaluate knowledge bases for retrieval poisoning, unauthorised information disclosure and document manipulation.

Tool & API Security
Tool & API Security

Ensure AI integrations cannot be abused to perform privileged actions or access unauthorised systems.

AI Governance
AI Governance

Assess guardrails, permissions, logging, monitoring and human approval processes to ensure AI is operating safely within your organisation.

Get more from your testing

“Not just another penetration test.” We want to make sure you get the most from your testing by being flexible and working the way you work, not forcing you to work our way.

Executive board briefing
Executive board briefing

We can create a custom, non-technical presentation to show the results of the penetration test to your execs in an easily understood way.

Code assisted testing
Code assisted testing

Find more vulnerabilities by providing us a copy of the source code. We use that code along-side our regular methodology to get you a better result.

Technical workshop
Technical workshop

Skill-up your developers or system admins by going through the penetration test findings in technical detail. We'll highlight how to avoid inadvertently creating these vulnerabilities in the future.

Custom reporting
Custom reporting

Want us to contextualise risk into your own risk matrix? Prefer a CSV or Markdown format? We can modify our report into something that will work best for you or even report directly into your ticketing system.

Supporting your organisation

Volkis provides active project management and account management support for enterprise organisations. This enables us to deal with complex projects that need multiple consultants and to support large programs of work.

Read our project lifecycle documentation in our handbook:

Managing projects at Volkis  

Open but secure

We aim to be transparent while maintaining the security of ourselves and our clients. Infosec doesn't need to be in the shadows and it's important that clients and the community understand how and why we do what we do.

Our Handbook is a place where staff, clients, partners, colleagues and anyone with interest can go and see the inner workings of Volkis. We try to publish everything that isn't confidential.

Check out the Handbook  

Methodologies

Our methodologies provide an overview of our high level processes, which we modelled on industry standards and our own experiences.

Methodologies  

Engagement Guide

The Penetration Testing Engagement Guide is the standard we hold our consultants to for every engagement we do. You can hold us to these standards of excellence.

Engagement Guide  

Sample Report

You can see our Penetration Testing Sample Report to understand what you're going to get out of your penetration test. Our professional report has all the information you need to remediate the vulnerabilities we find and is backed by a debrief and ongoing consulting.

Anonymised Report  

Learn the 6 things to look for in a penetration test company

Learn more