aptpen.com OPS · ONLINE
scope_engagement →
◢ THE BENCH BEHIND EVERY CAMPAIGN

Operators only.

// Every name on our bench has spent a decade in offensive cyber, inside a nation, a sanctioned red team, or a vendor research group whose findings ended up in the news. The firm exists because the operators wanted a place to keep doing the work, with paperwork, on a clearance, and with the discipline that a real adversary campaign requires.

§01 BY THE NUMBERS

The shape of the bench.

01 / 06
100%
U.S.-based operators
Onshore staff. Onshore contractors. Onshore vetting.
02 / 06
Hire
Your adversary, on retainer
Nation-grade tradecraft pointed at your estate. Cleared operators and CJIS-eligible staff available on request.
03 / 06
14
ATT&CK tactics covered
Reconnaissance through Impact. Every engagement.
04 / 06
40+
Industry certifications
OSCP · OSEP · OSCE³ · CRTO · GXPN · OSWE.
05 / 06
< 8h
Average DA time-to-compromise
From assume-breach start, in tested environments.
06 / 06
0
Findings without a fix
Every issue ships with a D3FEND-mapped recommendation.
§02 THE FIRM, AS BUILT

Six tenets.

01
TENET 01

The work is the product.

The work itself is what we sell. The report, the methodology slide, and any post-engagement followup exist to evidence that the work happened, in a form a customer can act on.

02
TENET 02

Operators carry the last word.

Every senior operator has veto authority on scope, on pairing, and on go-or-no-go calls during a campaign. The operator answers ahead of sales and ahead of account management on every question a campaign raises.

03
TENET 03

Hiring is slow on purpose.

Reference depth before resume length. A working tradecraft sample before any interview that touches strategy. The bench grows by one or two people a year, on purpose, so the median operator stays senior.

04
TENET 04

Patience is the multiplier.

A campaign run on threat-actor time surfaces findings a fiscal-quarter sprint will miss. Pricing covers the campaign as a whole, so an operator who waits three weeks before the next move is doing the job correctly.

05
TENET 05

Quiet is the default posture.

Loud is a decision an operator makes against data when the data calls for it, and every operator on the bench knows the moment that decision arrives.

06
TENET 06

The customer is the blue team.

The blue team is who we work for on every engagement, ahead of procurement and ahead of the audit committee, even when someone else signs the check. Every deliverable lands in their hands first.

§03 RESEARCH · DISCLOSURES · TOOLING

The bench publishes.

// Skill at this level is verifiable. Our operators ship CVEs, present at the conferences your team already attends, and maintain tooling that runs in other red teams' kits. The work below is sanitized for the open web. Named talks, CVE numbers, and repository links arrive with the scoping packet under NDA.

01
VULNERABILITY RESEARCH

CVEs in the gear on your perimeter.

Coordinated disclosures across enterprise VPN appliances, identity providers, and management software. Each one becomes an N-day we replay where the engagement scope allows.

Pre-auth RCE Auth bypass Coordinated disclosure
02
TECHNIQUE RESEARCH

Primitives the industry adopts.

AD and ADCS escalation work beyond the published ESC set, Kerberos abuse refinements, and cloud IAM confused-deputy classes. Presented at major industry conferences and folded into the engagement playbook.

ADCS Kerberos Cloud IAM
03
OPEN-SOURCE TOOLING

Code that ships in other kits.

BloodHound collector extensions, a Kerberos abuse module, and an agentic-emulation harness. Maintained in the open once a technique is widely understood, used by red teams beyond our own.

BloodHound ext Kerberos module Agentic harness
WHY IT MATTERS TO YOU
A firm that finds original vulnerabilities finds yours. The same people who write the disclosure are the people on your engagement, and the tooling they build between campaigns is the tooling pointed at your estate during one.
§04 CERTIFICATIONS · COMPLIANCE

Credentials and frameworks.

// The bench carries every certification on the left. We scope engagements against any of the frameworks on the right when the deliverable needs to land inside a compliance program.

OPERATOR CERTIFICATIONS
Industry-standard, current.
OSCP OSEP OSED OSCE³ OSWE CRTO CRTO II GXPN GPEN GWAPT GCPN CISSP CKS GCFA
COMPLIANCE FRAMEWORKS
Scoped on request.
NIST 800-115 PTES OWASP ASVS PCI DSS 4.0 HIPAA SOC 2 CMMC L2 / L3 FedRAMP ISO 27001 NYDFS 500 NERC CIP IEC 62443
TRUSTED BY ↦ FORTUNE 500 BANK GLOBAL HEALTHCARE NET DOD SUBCONTRACTOR AM-LAW 100 CRITICAL INFRA · ENERGY PUBLIC SAFETY · CJIS NATIONAL INSURER SAAS UNICORN

Bring an operator to the problem.

The first conversation is with the operator we would assign to the campaign. Tell us about the environment and we will respond within one business day with a draft ops plan and a price.

open_intake →