About us

Think Like an Attacker.
Defend Like a Pro.

As a specialized offensive security firm, we help organizations uncover vulnerabilities before attackers exploit them.

8+Years operator experience
14ATT&CK tactics
FullKill chain coverage
100%Custom-scoped

Who we are

Built around you.

Every engagement is designed around your unique environment, risks, and objectives. We blend technical expertise with creativity to identify critical vulnerabilities, demonstrate realistic attack paths, and provide guidance to close the gaps.

Our approach is rooted in real-world threat emulation and continuous research into the latest attacker tradecraft. With deep experience in penetration testing, adversarial simulation, and red teaming, we help organizations gain confidence in their security posture and resilience.

Who runs your engagement

Operators, not account managers.

The operator who scopes your engagement is the one who runs it and writes the report. There is no handoff to a junior tester once the contract is signed.

Our operators have worked offensive security since 2018, with depth in Azure and Entra ID attack paths, adversary simulation mapped to the MITRE ATT&CK framework, and custom C2 and offensive tool development. Our tooling is published openly at github.com/init1Security, and our tradecraft reference Red Team Notes 2.0 is an open ATT&CK-mapped resource, free for anyone to use.

Certifications held across the team:

  • OSCP
  • OSWP
  • CRTO
  • CARTP
  • ROPS-RT1

Speaking

Always learning, always sharing.

We research offensive tradecraft continuously and share what we learn back with the security community, at conferences across the United States and Mexico.

  • LayerOne, Los Angeles
  • BugCON, Mexico City
  • BSides Mexico
  • BSidesSLC, Utah

How we work

Four stages, every engagement

01

Scope

Every engagement is designed around your environment, risks, and objectives. We do not run a checklist against you.

02

Emulate

We operate with the mindset of a determined adversary, using the tradecraft real operators use against organisations like yours.

03

Prove

Findings come with a demonstrated attack path, not a severity rating and a hope that you believe us.

04

Close

You get the guidance needed to shut the path down, and a retest to confirm it stayed shut.

Contact

Let's test your defenses.

Tell us what you want tested and we will scope an engagement around your environment, risks, and objectives. No two engagements are the same.