Web Pentest
XSS, injections, IDOR, CSRF, authentication flaws - exploitable vulnerabilities identified and proven.
View detailsOffensive Security & Cloud
Web application testing, AWS IAM audits and continuous programmes - with actionable deliverables for both your technical teams and management. Remote or on-site across France.
years of offensive security experience
audits and penetration tests completed
response time on every enquiry
Services
A pragmatic approach: identify what is exploitable, prioritise fixes, measure progress.
XSS, injections, IDOR, CSRF, authentication flaws - exploitable vulnerabilities identified and proven.
View details
Permission review, privileged accounts and policies on AWS to reduce over-permissioning.
View details
Scheduled campaigns aligned with your release cadence to track risk over time.
View detailsProcess
From the first contact to retesting your fixes, here are the usual steps.
Technical exchange to define scope, legal constraints, testing window and expected deliverables. Quote within 48 hours.
Tests conducted according to the agreed methodology (black, grey or white box). Every vulnerability is exploited and documented with evidence - no assumptions.
Report delivered, debriefing workshop with your teams, then targeted retest on critical findings after remediation.
Approach
About
Independent offensive security consultant with over ten years in information systems security, primarily focused on penetration testing and technical audits (web applications, APIs, cloud environments). I have completed over 100 engagements for organisations ranging from scale-ups to large enterprises.
Based in Toulouse, France - I work remotely or on-site for clients throughout France.
FAQ
A cloud security audit checks conformance to best practices.
An AWS pentest simulates a real attack to identify exploitable weaknesses - in particular IAM misconfigurations, excessive permissions and cross-service abuse chains that could impact a production cloud environment.
Describe your context - I'll propose a realistic scope and timeline.
Request an audit