Web application pentesting
Auth, access control, business logic, session handling, injection paths, file handling, and exposed admin workflows.
offensive security consulting
Penetration testing for teams that need exploit-driven findings, clear evidence, and remediation advice that engineers can use.
what this is
1H Security tests the controls that protect real applications and infrastructure. The work is scoped around real attack paths, clear evidence, and fixes your engineers can ship.
services
Auth, access control, business logic, session handling, injection paths, file handling, and exposed admin workflows.
Endpoint discovery, object-level authorisation, schema drift, token handling, abuse cases, and integration boundaries.
Internet-facing cloud services, IAM assumptions, storage exposure, deployment defaults, and control-plane reachability.
Asset discovery, exposed services, forgotten hosts, risky management paths, and evidence-backed prioritisation.
Threat-model-led testing for new systems, major releases, and sensitive data flows before they become production incidents.
process
Agree objectives, dates, access, test accounts, reporting channel, and production-safety constraints.
Build a working model of exposed systems, roles, trust boundaries, APIs, data flows, and control assumptions.
Validate exploitability with safe evidence, then chain issues where that changes the practical impact.
Deliver concise findings with reproduction notes, affected assets, impact, and remediation guidance.
deliverables
Reproduction notes, screenshots where useful, affected routes, payload context, and clear exploit conditions.
Risk ranked by reachability, business impact, chaining potential, and what an attacker actually gains.
Fix guidance written for engineering teams, including validation notes for re-testing critical issues.
principles
contact
Send the systems, the outcome you need, and what needs to be true at the end. You will get a practical engagement shape back.
[email protected]