KUROSEK

クロセク

We attack your systems the way a real adversary would, then hand you the map, the proof, and the fix.

kurosek@edge:~$

// 01

What we do

シンニュウテスト

Kurosek is an independent penetration testing practice. Companies bring us in when they need to know, with evidence rather than assurance, whether a system can be broken and what happens after it is.

Every engagement is manual work led by an operator, not a scanner report with a logo on it. Automation is used where it earns its place, for coverage and for grunt work. The findings that matter, chained logic flaws, broken authorization, trust boundaries that were never really there, come from someone sitting with your system until it gives.

You get a reproducible proof of concept for every finding, an impact assessment written in terms your business already uses, and remediation guidance specific enough to act on. Then we retest, so the report ends with what was actually fixed.

Approach
Manual, operator-led testing
Deliverable
Reproducible proof, not a scan dump
Follow-through
Free retest of every fix
// 02

Capabilities

センモンリョウイキ

Six domains, tested end to end. Most engagements cross at least two of them, because attackers do.

Web & API

ウェブ

Applications, APIs and the auth logic holding them together, tested against the OWASP surface and well past it.

  • Broken access control and IDOR
  • Injection, SSRF, deserialization
  • Auth, SSO, OAuth and session flaws
  • Business logic and race conditions

Network & Infrastructure

ネットワーク

External perimeter and internal estate, from first packet to domain compromise and everything worth taking on the way.

  • External and internal penetration tests
  • Active Directory attack paths
  • Lateral movement and privilege escalation
  • Segmentation and egress validation

Mobile

モバイル

Android and iOS applications reversed, instrumented and driven off their intended path.

  • Static and dynamic analysis, decompilation
  • Root, jailbreak and integrity bypass
  • Insecure storage and key handling
  • Backend and IPC attack surface

Cloud & Containers

クラウド

AWS, Azure and GCP estates plus the orchestration layer, reviewed as configuration and attacked as a live target.

  • IAM privilege escalation paths
  • Kubernetes and container escape
  • Metadata service and SSRF chains
  • CI/CD and supply chain exposure

Hardware & Embedded

ハードウェア

Physical devices opened up: firmware pulled, buses probed, and the assumptions in silicon tested.

  • Firmware extraction and reverse engineering
  • UART, JTAG and SPI flash access
  • Secure boot and debug lock review
  • RF and wireless protocol analysis

Red Team & Advisory

レッドチーム

Objective-driven operations against people, process and technology at once, plus design review before anything ships.

  • Goal-based adversary simulation
  • Detection and response validation
  • Threat modelling and architecture review
  • Secure code review
// 03

How an engagement runs

テツヅキ

No surprises, no black box. You know the scope, the rules and the reporting line before anything is touched.

01

Scope

We agree targets, rules of engagement, timing and escalation contacts in writing. Authorization is signed before testing begins, always.

02

Test

Hands-on assessment against the agreed scope. Critical findings are reported the moment they are confirmed, not held for the report.

03

Report

Every finding with reproduction steps, evidence, real-world impact and remediation guidance. An executive summary that a board can read.

04

Retest

Once you have fixed things, we verify the fixes and issue an updated report showing what closed. Included, not billed as a second engagement.

// 04

Tools we publish

ツール

Some of what we build during engagements is useful to everyone. Those pieces get cleaned up and published.

Our public repositories live on our own Git server, not a third party. Scanners, exploit proofs of concept, analysis helpers and the small utilities that come out of real assessments, released as we are able to share them.

Anyone can browse and clone. Read the code before you run it, the same as you should with anything else that touches your systems.

Browse the repositories
Host
git.kurosek.com
Clone
https and ssh on port 2222
Accounts
Kurosek staff only
If we contacted you first

Unsolicited vulnerability reports

Sometimes we find a vulnerability in a product without anyone hiring us to look. Security research does not stop at the edge of a paid scope, and when we find something that puts a company or its users at risk, we tell that company directly. That email is a good-faith disclosure, nothing more.

If you received a message from us out of the blue, this is what it means and what it does not.

No pressure, no deadline games

We are not withholding details, and we are not threatening publication to force a response. You get the full technical write-up up front.

Nothing beyond proof

Research stops at the minimum needed to demonstrate the issue. We do not pivot deeper, exfiltrate data, or touch other customers.

Your data stays yours

Anything incidentally observed is reported to you and then destroyed. Nothing is sold, traded or published.

// 05

Get in touch

レンラク

Scoping questions, engagement enquiries, or a vulnerability you want to report to us. All of it lands in the same inbox.

Tell us what you have built and what would hurt most if it broke. That is usually enough to scope a first engagement. If you are reporting an issue to us and it is sensitive, encrypt it to the key in the secure contact panel.

Secure contact

Email
contact@kurosek.com
PGP keys
/pgp.txt
Fingerprint
6436 92BB 8A83 A1F0 3951 87D7 8F80 58DB C0AB C330
Policy
/.well-known/security.txt