Offensive Security
Find vulnerabilities with real world impact
Penetration Testing
Identify vulnerabilities that could allow adversaries access to your systems and data. Vulnerabilities that put your business at significant risk of a compromise are not only damaging for you, they could have an impact on your employees and your customers.
Penetration testing is our bread and butter! Volkis “pentesting” services will find the vulnerabilities that could be used to hack your networks, web applications, mobile applications, wireless networks, core services and cloud environments. A skilled penetration tester will use the same tools, techniques, and instincts that an adversary would to break into your systems.
What vulnerabilities exist in my systems? Do I need to worry about it? What could attackers do to me if exploited? What can I do to prevent this? All these questions can be answered with a penetration test.
Web Application / API
Make sure your bespoke web applications or APIs are resilient against attackers.
Internal
Find vulnerabilities from the perspective of an attacker inside your network.
External
Test your internet-facing servers and services against external threats.
Mobile
Find those hidden vulnerabilities lurking inside your custom made mobile apps.
Microsoft 365
Take a different approach to cloud security and have us investigate your Microsoft 365 tenant for real-world vulnerabilities with demonstrated exploits.
Continuous penetration testing
Year-round coverage of your attack surface ensures pentests are not just a "point-in-time" exercise. Pentest your newly developed applications as soon as they are ready.
Detection alert testing
Volkis will deliberately set off alerts in a methodical way so you can see those alerts in action, allowing you to gain familiarity with the alerts and ensure they are working properly.
And more!
We employ various security experts with domain knowledge in less commonly penetration tested areas such as Wireless, Citrix, SCADA, or Desktop Applications. If you're unsure, reach out!
Anonymised report
One of our clients allowed us to anonymise their real-world penetration testing report. You can see the report in our handbook with the link below.
Additional Handbook Links
Further reading from the Volkis Handbook on how we approach penetration testing.
Red Team Adversary Simulation
The Volkis Red Team will target your organisation over an extended period using skilled attackers, infrastructure specifically tailored to the engagement, and social engineering attacks to compromise sensitive information and core business services. You can test your organisation against a dedicated adversary, ensuring your security, detection, and incident response are up to scratch.
As close to a real-world hack as you can get, the engagement will be performed over a window period, usually 3-4 months. Our attackers will use drip scanning, passive investigation, and evasion techniques to get by your detection and response systems, breaking into your environment without being seen. The targets will be information and systems that are relevant to your organisation and likely targets for attackers. Instead of targets such as “compromise an administration account”, we look for key business services such as your CRM, financial systems, critical applications, and your web infrastructure to identify real, meaningful impact to your organisation.
Our testing methodology
Every Red Team engagement follows a documented methodology, published in full in the Volkis Handbook.
Anonymised report
Our anonymised red team report is a bit of an amalgamation of real world red teams we've performed - given red team reports are so specific to the organisation it's impossible to fully anonymise a single report. The link to the anonymised red team report is below.
Physical Intrusion
Sometimes the easiest way to get access to your sensitive data is to simply walk in and take it. Volkis’ physical intrusion services will test your organisation to see if that is possible.
Physical intrusion testing will test the resilience of your access control and physical protection systems to see if they can be bypassed or broken. Can your passes be duplicated by someone standing next to them in the elevator? Can someone simply walk through a back door or open a window?
Volkis will employ a variety of different attack types throughout the engagement to gain access. This can include:
- Social engineering
- Lock picking
- Door bypasses
- Badge cloning
If access is gained, the consultant will collect evidence to see what the impact from that physical access is. Depending on the rules of engagement, the consultant may take pictures of desks, access sensitive areas, or connect to the network using a laptop or a concealed network tap.
At the end of the engagement, the consultant will outline any weaknesses and provide actionable recommendations for improving the security of the physical premises. This could include improving access control, improving procedures and processes for handling entrants, or user education.
AI Assessment
As organisations race to adopt Artificial Intelligence (AI), they may be unknowingly introducing new attack surfaces that traditional penetration testing was never designed to assess. Prompt injection, insecure tool integrations, excessive permissions, model manipulation and data leakage can all allow an attacker to manipulate an AI system into performing actions outside its intended design, without ever exploiting a traditional software vulnerability.
Volkis’s AI Assessment (also known as AI Red Teaming) combines application security with specialist AI security testing to identify how attackers could manipulate your AI systems to produce unauthorised actions, expose sensitive information, bypass business controls or perform actions on behalf of your users.
Whether you’ve built your own AI application, integrated with leading foundation models, or deployed autonomous AI agents, we’ll assess the security of the complete solution — not just the underlying infrastructure.
Prompt Injection
Assess whether attackers can manipulate prompts to bypass safety controls, leak information or change the AI's behaviour.
AI Agents
Assess agents that interact with APIs, databases, email systems, ticketing platforms and other business services.
Retrieval Augmented Generation (RAG)
Evaluate knowledge bases for retrieval poisoning, unauthorised information disclosure and document manipulation.
Tool & API Security
Ensure AI integrations cannot be abused to perform privileged actions or access unauthorised systems.
AI Governance
Assess guardrails, permissions, logging, monitoring and human approval processes to ensure AI is operating safely within your organisation.
Get more from your testing
“Not just another penetration test.” We want to make sure you get the most from your testing by being flexible and working the way you work, not forcing you to work our way.
Executive board briefing
We can create a custom, non-technical presentation to show the results of the penetration test to your execs in an easily understood way.
Code assisted testing
Find more vulnerabilities by providing us a copy of the source code. We use that code along-side our regular methodology to get you a better result.
Technical workshop
Skill-up your developers or system admins by going through the penetration test findings in technical detail. We'll highlight how to avoid inadvertently creating these vulnerabilities in the future.
Custom reporting
Want us to contextualise risk into your own risk matrix? Prefer a CSV or Markdown format? We can modify our report into something that will work best for you or even report directly into your ticketing system.
Supporting your organisation
Volkis provides active project management and account management support for enterprise organisations. This enables us to deal with complex projects that need multiple consultants and to support large programs of work.
Read our project lifecycle documentation in our handbook:
Managing projects at VolkisOpen but secure
We aim to be transparent while maintaining the security of ourselves and our clients. Infosec doesn't need to be in the shadows and it's important that clients and the community understand how and why we do what we do.
Our Handbook is a place where staff, clients, partners, colleagues and anyone with interest can go and see the inner workings of Volkis. We try to publish everything that isn't confidential.
Check out the HandbookMethodologies
Our methodologies provide an overview of our high level processes, which we modelled on industry standards and our own experiences.
MethodologiesEngagement Guide
The Penetration Testing Engagement Guide is the standard we hold our consultants to for every engagement we do. You can hold us to these standards of excellence.
Engagement GuideSample Report
You can see our Penetration Testing Sample Report to understand what you're going to get out of your penetration test. Our professional report has all the information you need to remediate the vulnerabilities we find and is backed by a debrief and ongoing consulting.
Anonymised Report
Social Engineering
With Volkis social engineering exercises you can test the security awareness of your users, and incorporate the results into an ongoing security awareness programme.
Our social engineering capability includes:
Phishing campaign welcome pack
See what to expect from a Volkis phishing campaign before it begins, in our handbook.