0%
Free scan Services Kirux Pricing Research Assessment →
PENETRATION TESTING & CLOUD SECURITY · MEXICO

Before they do. We find the gaps.

Multi-source reconnaissance, evidence-based verification and executive reporting. We prioritize verifiable evidence and distinguish observations from confirmed findings.

MITRE ATT&CKOWASPNIST CSFISO 27001
KiruxFindingsEvidenceReports preview · sample data
MITRE ATT&CKOWASP TOP 10 MULTI-SOURCE RECONADVERSARIAL VERIFICATION AWS SECURITYCLOUD AUDITING TERRAFORM / IaCRED TEAM REPRODUCIBLE EVIDENCENIST CSF ZERO TRUSTISO 27001 MITRE ATT&CKOWASP TOP 10 MULTI-SOURCE RECONADVERSARIAL VERIFICATION AWS SECURITYCLOUD AUDITING TERRAFORM / IaCRED TEAM REPRODUCIBLE EVIDENCENIST CSF ZERO TRUSTISO 27001
—
Years of experience
in cybersecurity
—
Vulnerability classes
covered
—
Findings with
reproducible evidence
AWS
Certified Security
— Specialty
Industries we serve
Fintech Manufacturing Healthcare Retail Logistics Construction Startups

Your attack surface changes.
Your security should too.

New services, identities and configurations bring different questions. Knowing what is exposed and what evidence confirms it helps you decide where to act first.

An annual pentest is no longer enough, and neither is an automated scanner. You need verified findings backed by real evidence, beyond a generic list of CVEs.

EXAMPLE Typical attack pattern — illustration
🇷🇺 RU→fintech-monterrey.comCRITICAL2 min ago
🇨🇳 CN→erp.constructora-mx.ioHIGH7 min ago
🇺🇸 US→portal.clinica-cdmx.mxCRITICAL12 min ago
🇧🇷 BR→api.retail-chain.com.mxHIGH19 min ago
🇷🇴 RO→mail.logistica-gdl.mxHIGH25 min ago

Six capabilities.
One report.

Findings with context, evidence and a validation level defined by the agreed scope.

01

Multi-source reconnaissance

Public certificate records, exposed infrastructure search engines, breach datasets and active enumeration, combined. A single source can miss subdomains, assets using third-party certificates and leaked credentials — we connect the sources.

MonTueWedThuFriSatSun
Certificate Transparency Infrastructure + breaches Active enumeration
02

Evidence-based verification

Cited evidence and an explicit validation level. The Full Assessment adds manual finding review.

03

AWS Cloud Audit

IAM, access policies, network architecture and best practices. The attack surface that is too often overlooked.

04

TLS / Certificate

Direct handshake: protocol, issuer, expiration and SAN. No reliance on third-party tools.

05

Terraform / IaC Review

Infrastructure-as-code reviews: network segmentation, unnecessary exposure and best practices before deployment.

06

Executive Reports

AI-generated HTML and PDF reports. Ready for the board, without needing someone to translate the technical details.

Your security operations.
One unified platform.

Kirux is NullGhost’s platform for connecting security testing, operations and cloud posture to the findings you need to address.

Request a Kirux demo

Scope, integrations and AI processing mode defined with you.

One connected workflow
CloudIdentitiesEndpointsCode
KIRUXAnalysis and correlation
Findings in contextExecutive reports
From signal to evidence.
01 / OFFENSIVE SECURITY

Pentesting with defined scope

Web and network testing, evidence and verification. Authorization controls bound the targets; deterministic phases complement the agent’s analysis.

02 / OPERATIONS

Connected signals

AI-assisted triage, AWS GuardDuty and Microsoft 365 context, and finding tracking to help prioritize response.

03 / CLOUD + FINOPS

Risk and resource usage

AWS security posture and optimization opportunities, with a category for AI resources such as SageMaker and accelerated compute.

04 / AI CONTROL

Choose where processing happens

Choose a local model with Ollama or an external provider. We agree on the operating mode, data involved and integrations before work begins.

Evidence,
beyond an alert.

Here is what your report looks like. Every finding includes its severity, status and supporting evidence.

Kirux — example report
Executive Summary
Recon
Findings
Evidence
Cloud AWS
Remediation
2
Critical
5
High
8
Medium
100%
With evidence
FindingSeveritySourceEvidenceVerified
Leaked credentials (infostealer)CRITBreachesverified record
Outdated TLS protocolHIGHHandshakeTLS version
Exposed development subdomainMEDLive hostsstatus 200
SPF softfail instead of hardfailMEDDNSdig TXT
Excessive IAM privilegesHIGHAWSIAM policy

What would we find
on your domain?

A free initial external review of your domain. Receive an exposure summary by email to help decide whether you need a deeper assessment.

Your details are used to handle this request. Submitted through Web3Forms. Data and scope →

External review without exploits · may include HTTP/TLS connections · summary in 24–48 hours.

From scope to
verified findings.

No access to your internal systems is needed to get started. Nothing to install on your side.

nullghost-recon / simulation
23:41:02RECON Sources: certificate records, exposed infrastructure and breach datasets.
23:41:05TLS Direct handshake: certificate, protocol and expiration.
23:41:08VERIFY Cited evidence and validation level for each finding.
nullghost@recon:~$
01

Define the scope

Share your domain and confirm the authorized scope. Nothing starts without it.

Explicit authorization first
External, non-destructive recon
Read-only, no changes
02

We run the assessment

Multi-source reconnaissance, with every finding verified through reproducible evidence before it is recorded.

Certificates + exposed infrastructure + breaches
TLS, DNS, headers, AWS cloud
Prove it before reporting it
03

Receive your report

Executive and technical reporting, prioritized by actual severity, with actionable remediation.

Evidence cited for every finding
PDF/HTML report
Debrief call with the Full Assessment

Simple. Predictable.
No surprises.

Fixed project pricing. No long-term contracts or hidden setup fees.

Free: an initial email summary. Exposure Scan: multi-source reconnaissance and an executive PDF report. Full Assessment: manual verification, cloud review and a debrief within the agreed scope.

Exposure Scan
$3,500 MXN

Multi-source external reconnaissance with an executive PDF report. Scope and delivery date agreed before starting.

  • Subdomains (multi-source)
  • TLS / certificate
  • Leaked credentials (breach datasets)
  • Executive PDF report
  • Manual finding verification
  • AWS cloud audit
  • Debrief call
Ongoing Security
From $15,000 MXN/month

Regular reassessment beyond an annual snapshot. Scales with the number of areas you cover.

  • Recurring scans (monthly/quarterly)
  • Alerts when new findings appear
  • Security posture reporting over time
  • AWS cloud audit included
  • Priority retesting
  • Live 24/7 SOC
  • Formal SLA

Frequently asked
questions.

What businesses ask before getting started.

The Exposure Scan is delivered in days, not weeks. The Full Assessment, with manual verification of every finding, takes longer depending on scope — we agree on a specific delivery date before starting.
Not to get started. Initial reconnaissance is external and unauthenticated; it may include direct HTTP/TLS requests. Any authenticated testing or action that changes system state requires your explicit authorization, recorded before we proceed.
Each finding includes evidence and its validation level. The Exposure Scan documents external signals; the Full Assessment adds manual verification within the agreed scope.
We notify you immediately, without waiting for the final report. A critical finding is escalated as soon as it is verified, with evidence and a remediation recommendation.
Before starting, we agree on evidence access, retention and deletion, as well as the AI processing mode and providers involved in the service.
Yes — that is the most common starting point. Many clients use it to see the level of detail before choosing a Full Assessment or Ongoing Security.

Technical context.
Verifiable sources.

Selected references to understand risk. Applicability depends on your technology, version and configuration.

Technical references · editorial selection24 Sep 2026
CVE
Linksys — CVE-2025-8821Command injection affecting Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000. Check the record’s affected products and versions before determining exposure.Official CVE record ↗
GUIDE
Ransomware preparedness and responseA reference for reviewing prevention, preparedness and response. Use it to guide a control review with your team.CISA — #StopRansomware Guide ↗

What we investigate.
What we learn.

Field observations and industry analysis, with explicit sources and limits. Explore each summary and the full paper in its available language.

Industry analysisSep 2026

The governance gap

Identity, authorization and delegation: questions to ask before putting AI agents into operation.

Explore research
Architecture evaluationSep 2026

Before execution

A verification layer between an agent’s decision and its action. We examine the pattern through TypeSafe AI / Jev.

Explore research
Field observationsSep 2026

When the agent decides

Ten lessons on coverage, verification and silent failures from operating an offensive security agent.

Explore research
FinOps and AISep 2026

From waste to value

What changes when AI spend enters the FinOps conversation. A reading of State of FinOps 2026.

Explore research

Let's talk about
your security.

Tell us what you need: assess your exposure, review your cloud or explore Kirux. We will help you define the next step.

Your details are used to handle this request. Submitted through Web3Forms. Data and scope →