Pentesting with defined scope
Web and network testing, evidence and verification. Authorization controls bound the targets; deterministic phases complement the agent’s analysis.
Multi-source reconnaissance, evidence-based verification and executive reporting. We prioritize verifiable evidence and distinguish observations from confirmed findings.
New services, identities and configurations bring different questions. Knowing what is exposed and what evidence confirms it helps you decide where to act first.
An annual pentest is no longer enough, and neither is an automated scanner. You need verified findings backed by real evidence, beyond a generic list of CVEs.
Findings with context, evidence and a validation level defined by the agreed scope.
Public certificate records, exposed infrastructure search engines, breach datasets and active enumeration, combined. A single source can miss subdomains, assets using third-party certificates and leaked credentials — we connect the sources.
Cited evidence and an explicit validation level. The Full Assessment adds manual finding review.
IAM, access policies, network architecture and best practices. The attack surface that is too often overlooked.
Direct handshake: protocol, issuer, expiration and SAN. No reliance on third-party tools.
Infrastructure-as-code reviews: network segmentation, unnecessary exposure and best practices before deployment.
AI-generated HTML and PDF reports. Ready for the board, without needing someone to translate the technical details.
Kirux is NullGhost’s platform for connecting security testing, operations and cloud posture to the findings you need to address.
Request a Kirux demoScope, integrations and AI processing mode defined with you.
Web and network testing, evidence and verification. Authorization controls bound the targets; deterministic phases complement the agent’s analysis.
AI-assisted triage, AWS GuardDuty and Microsoft 365 context, and finding tracking to help prioritize response.
AWS security posture and optimization opportunities, with a category for AI resources such as SageMaker and accelerated compute.
Choose a local model with Ollama or an external provider. We agree on the operating mode, data involved and integrations before work begins.
Here is what your report looks like. Every finding includes its severity, status and supporting evidence.
A free initial external review of your domain. Receive an exposure summary by email to help decide whether you need a deeper assessment.
Your details are used to handle this request. Submitted through Web3Forms. Data and scope →
External review without exploits · may include HTTP/TLS connections · summary in 24–48 hours.
No access to your internal systems is needed to get started. Nothing to install on your side.
Share your domain and confirm the authorized scope. Nothing starts without it.
Multi-source reconnaissance, with every finding verified through reproducible evidence before it is recorded.
Executive and technical reporting, prioritized by actual severity, with actionable remediation.
Fixed project pricing. No long-term contracts or hidden setup fees.
Free: an initial email summary. Exposure Scan: multi-source reconnaissance and an executive PDF report. Full Assessment: manual verification, cloud review and a debrief within the agreed scope.
Multi-source external reconnaissance with an executive PDF report. Scope and delivery date agreed before starting.
Red teaming with adversarial verification. Every finding is tested before it makes the list.
Regular reassessment beyond an annual snapshot. Scales with the number of areas you cover.
What businesses ask before getting started.
Selected references to understand risk. Applicability depends on your technology, version and configuration.
Field observations and industry analysis, with explicit sources and limits. Explore each summary and the full paper in its available language.
Identity, authorization and delegation: questions to ask before putting AI agents into operation.
Explore researchA verification layer between an agent’s decision and its action. We examine the pattern through TypeSafe AI / Jev.
Explore researchTen lessons on coverage, verification and silent failures from operating an offensive security agent.
Explore researchWhat changes when AI spend enters the FinOps conversation. A reading of State of FinOps 2026.
Explore researchTell us what you need: assess your exposure, review your cloud or explore Kirux. We will help you define the next step.
Your details are used to handle this request. Submitted through Web3Forms. Data and scope →