0%
Free scan Services Kirux The report Pricing Threat Intel FAQ Assessment →
NULLGHOST — OFFENSIVE SECURITY

Before they do. We find the gaps.

Multi-source reconnaissance, evidence-based verification and executive reporting. Every finding is tested before it is reported — we go beyond raw scanner output.

MITRE ATT&CK OWASP NIST CSF ISO 27001
nullghost-recon / simulation
23:41:02RECON Sources: certificate records, exposed infrastructure and breach datasets.
23:41:05TLS Direct handshake: certificate, protocol and expiration.
23:41:08VERIFY Every finding includes the command + actual output. No exceptions.
nullghost@recon:~$
MITRE ATT&CKOWASP TOP 10 MULTI-SOURCE RECONADVERSARIAL VERIFICATION AWS SECURITYCLOUD AUDITING TERRAFORM / IaCRED TEAM REPRODUCIBLE EVIDENCENIST CSF ZERO TRUSTISO 27001 MITRE ATT&CKOWASP TOP 10 MULTI-SOURCE RECONADVERSARIAL VERIFICATION AWS SECURITYCLOUD AUDITING TERRAFORM / IaCRED TEAM REPRODUCIBLE EVIDENCENIST CSF ZERO TRUSTISO 27001
Years of experience
in cybersecurity
Vulnerability classes
covered
Findings with
reproducible evidence
AWS
Certified Security
— Specialty
Industries we serve
Fintech Manufacturing Healthcare Retail Logistics Construction Startups

Mexico is the most targeted country in Latin America.

A ransomware attack occurs somewhere in the world every 11 seconds. Mid-sized businesses are prime targets — without a SOC, visibility or defenses.

An annual pentest is no longer enough, and neither is an automated scanner. You need verified findings backed by real evidence, beyond a generic list of CVEs.

EXAMPLE Typical attack pattern — illustration
🇷🇺 RUfintech-monterrey.comCRITICAL2 min ago
🇨🇳 CNerp.constructora-mx.ioHIGH7 min ago
🇺🇸 USportal.clinica-cdmx.mxCRITICAL12 min ago
🇧🇷 BRapi.retail-chain.com.mxHIGH19 min ago
🇷🇴 ROmail.logistica-gdl.mxHIGH25 min ago

Six capabilities.
One report.

Every finding is tested before reporting. Reproducible evidence goes beyond a scanner alert.

01

Multi-source reconnaissance

Public certificate records, exposed infrastructure search engines, breach datasets and active enumeration, combined. A single source can miss subdomains, assets using third-party certificates and leaked credentials — we connect the sources.

MonTueWedThuFriSatSun
Certificate Transparency Infrastructure + breaches Active enumeration
02

Evidence-based verification

Prove it before reporting it. Every finding includes the command and its actual output — never an unconfirmed scanner alert.

03

AWS Cloud Audit

IAM, access policies, network architecture and best practices. The attack surface that is too often overlooked.

04

TLS / Certificate

Direct handshake: protocol, issuer, expiration and SAN. No reliance on third-party tools.

05

Terraform / IaC Review

Infrastructure-as-code reviews: network segmentation, unnecessary exposure and best practices before deployment.

06

Executive Reports

AI-generated HTML and PDF reports. Ready for the board, without needing someone to translate the technical details.

Your security operations.
One unified platform.

AI-powered pentesting, security operations and visibility across your environment. Kirux connects findings with the context you need to decide what to address first.

Request a Kirux demo

We work with you to define the scope and integrations for your organization.

One connected workflow
CloudIdentitiesEndpointsCode
KIRUXAnalysis and correlation
Findings in contextExecutive reports
From signal to evidence.
01 / OFFENSIVE SECURITY

AI-powered pentesting

Reconnaissance, test execution and finding verification in one workflow, within the authorized scope.

  • Test and finding management
  • Evidence and executive reports
02 / OPERATIONS

A connected SOC

Event correlation and AI-assisted triage to give alerts context and support prioritization.

  • Integration with AWS GuardDuty and Microsoft 365
  • Threat intelligence and endpoint telemetry
03 / VISIBILITY

Beyond the perimeter

Cloud posture, identities, devices and code security for a broader view of risk.

  • AWS, Azure, Google Cloud and Oracle
  • Vulnerable dependencies and exposed secrets

Evidence,
beyond an alert.

Here is what your report looks like. Every finding includes its severity, status and supporting evidence.

nullghost.io — report preview
Executive Summary
Recon
Findings
Evidence
Cloud AWS
Remediation
2
Critical
5
High
8
Medium
100%
With evidence
FindingSeveritySourceEvidenceVerified
Leaked credentials (infostealer)CRITBreachesverified record
Outdated TLS protocolHIGHHandshakeTLS version
Exposed development subdomainMEDLive hostsstatus 200
SPF softfail instead of hardfailMEDDNSdig TXT
Excessive IAM privilegesHIGHAWSIAM policy

What would we find
on your domain?

Free passive reconnaissance on your domain — certificates, exposed infrastructure, breaches and TLS. No exploits or intrusion. Results delivered to your inbox.

100% passive (no exploits or unauthorized access) · report in 24–48 hours.

From scope to
verified findings.

No access to your internal systems is needed to get started. Nothing to install on your side.

01

Define the scope

Share your domain and confirm the authorized scope. Nothing starts without it.

Explicit authorization first
Passive, non-destructive recon
Read-only, no changes
02

We run the assessment

Multi-source reconnaissance, with every finding verified through reproducible evidence before it is recorded.

Certificates + exposed infrastructure + breaches
TLS, DNS, headers, AWS cloud
Prove it before reporting it
03

Receive your report

Executive and technical reporting, prioritized by actual severity, with actionable remediation.

Evidence cited for every finding
PDF/HTML report
Debrief call included

Simple. Predictable.
No surprises.

Fixed project pricing. No long-term contracts or hidden setup fees.

Exposure Scan
$3,500 MXN

Multi-source passive reconnaissance on your domain. Delivered in days, not weeks.

  • Subdomains (multi-source)
  • TLS / certificate
  • Leaked credentials (breach datasets)
  • Executive PDF report
  • Manual finding verification
  • AWS cloud audit
  • Debrief call
Ongoing Security
From $15,000 MXN/month

Regular reassessment beyond an annual snapshot. Scales with the number of areas you cover.

  • Recurring scans (monthly/quarterly)
  • Alerts when new findings appear
  • Security posture reporting over time
  • AWS cloud audit included
  • Priority retesting
  • Live 24/7 SOC
  • Formal SLA

Frequently asked
questions.

What businesses ask before getting started.

The Exposure Scan is delivered in days, not weeks. The Full Assessment, with manual verification of every finding, takes longer depending on scope — we agree on a specific delivery date before starting.
Not to get started. Initial reconnaissance is 100% external, passive and read-only. Any authenticated testing or action that changes system state requires your explicit authorization, recorded before we proceed.
A scanner reports what it finds, including false positives. We follow one rule: "prove it before reporting it". Every finding includes the command and actual output that confirms it, beyond a generic alert.
We notify you immediately, without waiting for the final report. A critical finding is escalated as soon as it is verified, with evidence and a remediation recommendation.
Evidence is retained only for the duration of the project, then deleted according to the process agreed with you. It is never shared with third parties.
Yes — that is the most common starting point. Many clients use it to see the level of detail before choosing a Full Assessment or Ongoing Security.

Recent threats
in Mexico and LATAM.

Cases we follow closely. The threat landscape behind every finding.

Threat Intel — documented cases 2026
CRITICAL
NOVA Ransomware compromises Neubox infrastructure — 60+ businesses affectedVector: shared cPanel/WHM server. Data: source code, databases, phpMyAdmin. Sector: hosting/SMB.
21 May 2026
HIGH
Infostealer campaign targets financial businesses in Mexico CityCorporate credentials for sale on underground forums. Sectors: fintech, insurance, digital banking.
19 May 2026
HIGH
Qilin ransomware active — 340+ victims worldwide, including construction in MexicoTTPs: VPN exploits, Living off the Land. Group active in LATAM since Q1 2026.
21 May 2026
INFO
Critical phpMyAdmin vulnerability — unauthenticated RCE (CVE-2025-8821)Thousands of unpatched instances exposed in Mexico. Update to 5.2.2+ immediately.
15 May 2026

Let's talk about
your security.

Tell us what you need: assess your exposure, review your cloud or explore Kirux. We will help you define the next step.