Security Services

Hands-on security testing, assessment, and training — delivered by the researcher behind Hmmnm’s published work. Twenty-seven focused services, one methodology you can read every week on this site: research-first, vendor-neutral, and explained so your team can act on it.

328+published deep-dives & CVE analyses
27services across three practice areas
Weeklythreat-intelligence briefings since 2026
0vendor lock-in — recommendations are neutral
Certified CEH AZ-500 SecurityX BSCP CRTO SC-200 eWPTX v3 all 25 credentials →

Offensive & Security Testing

Find the flaws before attackers do — from applications and networks to AI systems and the people using them.

Find what scanners miss — logic, auth, and trust boundaries.

  • Authentication and session flows
  • Authorization: BOLA, IDOR, privilege escalation
  • Injection: SQLi, XSS, SSTI
  • REST & GraphQL API abuse cases

Internal and external testing — where an attacker can get, and how to cut the paths off.

  • External perimeter and exposed panels
  • Segmentation and lateral movement
  • Active Directory privilege paths
  • VPN, RDP, and legacy service exposure

Android and iOS apps tested the way a real attacker works.

  • Local storage: tokens, PII, keys
  • Deep links and exported components
  • Certificate pinning bypass
  • Backend API authorization flaws

Can a determined attacker reach the crown jewels — and would you notice?

  • Objective-based adversary scenarios
  • Initial access to exfiltration, safely
  • Detection checkpoints throughout
  • Full operator log for replay

Live attacks, live detection tuning — no months-long report cycle.

  • Techniques chosen for your industry
  • Live execution with your SOC
  • Detection rules tuned in-session
  • ATT&CK coverage map, before and after

Controlled campaigns incl. modern MFA-bypass techniques, with a training plan.

  • Credential-harvesting campaigns
  • Device-code and AiTM MFA bypass
  • Payroll diversion and exec impersonation
  • Per-department reporting

Everything you expose to the internet — mapped, ranked, and explained.

  • Forgotten subdomains and projects
  • Exposed panels and interfaces
  • Leaked secrets in public repos
  • Risk-ranked inventory

Your copilots and agents are a new attack surface. We test them like adversaries will.

  • Prompt injection and exfiltration paths
  • Tool, MCP, and skill permissions
  • Memory and RAG abuse
  • OWASP Agentic AI Top 10 mapping

One leaked credential should not empty your tenant. We check whether it could.

  • AWS, Azure, GCP IAM attack paths
  • SSO and IdP configuration
  • Secrets sprawl and CI/CD keys
  • Blast-radius analysis

From XZ to the AUR hijack, the quiet attacks won. We harden the pipeline.

  • Dependency and registry confusion risk
  • Build pipeline trust and signing
  • SBOM gap analysis
  • Vendor and MSP access review

Dedicated testing for REST, GraphQL and gRPC — authorization is where APIs break.

  • BOLA and function-level authorization
  • Mass assignment and data exposure
  • GraphQL depth and batching abuse
  • Rate-limit and enumeration paths

The flaws scanners cannot see live in business logic. A human reads your code.

  • Business-logic and trust-boundary flaws
  • Injection sinks and deserialization
  • Authentication implementation review
  • Crypto misuse and hardcoded secrets

Program setup, triage, and managed hunting — without the noise.

  • Scope and policy design
  • Report triage and validation
  • Researcher communication
  • Managed hunting passes

Detect & Respond

Know what actually threatens your stack, whether you are already compromised, and how fast you recover.

Which of the week’s CVEs matter to your stack — and would you catch the follow-on?

  • Stack-specific CVE impact analysis
  • Detection coverage vs. real TTPs
  • MITRE ATT&CK gap report
  • Leadership briefings

What does the criminal ecosystem already know about your organization?

  • Domains searched across breach corpora
  • Credential and stealer-log exposure
  • Privileged account overlap
  • Prioritized lock-down plan

“Are we already breached?” A focused hunt for the evidence alerts missed.

  • Persistence and tampering hunt
  • Suspicious authentication patterns
  • Memory and log artifact review
  • Clear verdict with evidence

When it is happening right now: contain safely, preserve evidence, recover.

  • Immediate containment guidance
  • Evidence-safe order of operations
  • Intrusion scoping
  • Post-incident hardening plan

Stress-test against a real kill chain — before attackers run it for you.

  • Kill-chain control mapping
  • Team tabletop exercise
  • Backup and recovery validation
  • Prioritized survival roadmap

Advisory, Training & Compliance

Leadership, measurement, and audit readiness — the parts of security that tools cannot buy.

The public learning-path curriculum, tailored to your team and stack.

  • Hands-on pentesting labs
  • AI agent security for engineers
  • Ransomware tabletops
  • Executive risk sessions

Security leadership on a budget that fits — without a full-time hire.

  • Budget-aware security roadmap
  • Vendor-neutral tool advice
  • Board-ready risk reporting
  • On-call for incidents

Where you actually stand, and the shortest path from here to there.

  • Controls scored across core domains
  • Realistic peer benchmarking
  • Quick wins vs. structural fixes
  • Budget-aware roadmap

Measured against the lists and rigs attackers actually use — not policy documents.

  • Offline strength measurement
  • Modern wordlist and rule testing
  • Weak and reused credential lists
  • NIST-aligned policy update

Audit-ready without the panic — ISO 27001, SOC 2, PCI DSS, DPDP.

  • Framework gap assessment
  • Evidence organization
  • Policies people can follow
  • Audit-time liaison

Which of your trust boundaries still assume the network is safe?

  • Identity perimeter and access reach
  • Segmentation and east-west paths
  • Device trust and conditional access
  • Phased implementation roadmap

Your vendors are your attack surface — one MSP update encrypted 1,500 businesses.

  • Vendor inventory with blast radius
  • Access and privilege review
  • Breach-history checks
  • Ongoing monitoring plan

Custom CVE analysis, disclosure support, and investigation — what Hmmnm does every week.

  • Stack-specific CVE impact analysis
  • Responsible disclosure support
  • Vendor security-claim verification
  • Technical due diligence

Practical security sessions for students and teams — current, from a working researcher.

  • Campus career seminars
  • Current-threat briefings
  • AI security awareness
  • Q&A-heavy formats
Industries served SaaS & Technology Banking & Finance Healthcare E-commerce & Retail Education Manufacturing — remote-first, worldwide

Also from Hmmnm: Security Products — customizable compliance documents and checklists, in-house scanning tools, and our internship program.

Explore Products →

How an engagement works

1 Scope

A free call to understand your environment and goals. You receive a written scope, timeline, and fixed quote — testing only begins with your signed authorization.

2 Test

Time-boxed testing with an agreed communication plan. Exploitation stays safe and reversible; you always know what is happening and when.

3 Report

An executive summary your leadership can act on, plus full technical detail: proof-of-concept steps, severity ratings, and remediation guidance your developers can follow.

4 Verify

After your fixes land, a retest confirms the findings are resolved — included in the engagement, not an extra line item.

Authorization first, always. No testing happens without written permission and defined rules of engagement. We do not exfiltrate real data, tests are designed to be non-destructive, and findings are disclosed only to you. The same ethics that govern responsible disclosure on this site govern every engagement.

Common questions

Twenty services from one researcher — how does that work?

Every service draws on the same research foundation — the 328+ analyses published on this site — across adjacent disciplines of offensive security, detection, and advisory. Engagements are accepted selectively, so every deliverable gets senior, hands-on attention rather than being passed down a chain.

How much does a penetration test cost?

It depends on scope: application size, environments, and depth. We wrote a full public breakdown — How much does a penetration test cost? — and every quote we send is fixed-price, decided after the free scoping call.

How long does an engagement take?

A focused web application or API test typically runs one to two weeks end to end, including the report. Larger environments and red-team style work are scoped to a calendar agreed before we start.

Do you retest after we fix things?

Yes. A verification pass over the fixed findings is part of every engagement — that is what “resolved” should actually mean, not just “patched.”

Can you test our AI features, not just web apps?

That is a specialty. Agent architectures, tool permissions, MCP integrations, and exfiltration paths are covered in our published AI security research — and tested with the same rigor in engagements.

What do you need from us before starting?

Points of contact, access or credentials matching the agreed testing depth (black, grey, or white box), and a signed authorization. We handle the rest, including a communication plan for anything urgent found mid-test.

Is training on-site or remote?

Both. Workshops run remotely by default and are tailored to your stack — see the public learning paths for the curriculum style.

Tell us about your environment

A short conversation is enough to scope it. No obligation, no sales funnel — a researcher will reply.

Start the conversation →