Wedjat Signal: clear

The Eye of Horus · defensive security lab

Green means go.

Wedjat is a fixed-price external security assessment. We map what your company exposes to the internet, prove every finding with a command you can run yourself, and hand you the fix. When we say a door opens, you watch it open.

  • Fixed fee
  • Two-week window
  • Re-run included

How we operate

Powerful, and leashed on purpose.

The runners walk your perimeter the way a patient attacker would. What holds them back is not good manners. It is a scope gate that refuses any out-of-scope target before a packet leaves the box. That is what makes it safe to point at production.

01

Proof, not a risk score

Nothing counts as a finding until we've shown it working. No CVSS guesses, no scanner dump for your team to sort through. Every claim is a single command, and we hand you the command.

Evidence-anchored
02

Boxed and leashed

The engine runs inside a default-deny network jail. It reaches what the scope allows and nothing else. Every action is written to a hash-chained evidence record before it happens. We demonstrate the door opens. We never read one row of your data.

Scope-gated at every hop
03

Quiet by design

One request per probe, sequential, never a flood. Version checks are detection only, no exploit. You find out what someone with time can reach from the outside. You find out from us, on a Tuesday, instead of from them.

No flooding, no DoS
04

Scope-gated by construction

Ownership proven by DNS challenge before any runner points at you. Approved scope, dated window, recorded run. When a path crosses the line you set, we record that it exists and we stop. The constraint is the product.

Approved scope, dated window

The blast radius

One leaked key. Four hops. The crown jewels.

Four small mistakes that add up to one critical breach. Every finding in a Wedjat report has this shape: where it starts, each hop proven before the next, and what it reaches. Here is the shape of one.

WDJ-0042-PATH-01 assumed-breach traversal evidence store Critical
Exposed dev credential found in a public .git/config on dev.example.com
ev_4471
Internal CI host credential reuse authenticates to ci.example.com:8080
ev_4490
Artifact registry CI service token in the environment grants read
ev_4502
Production customer database a registry image embeds a DSN that reaches prod
ev_4517

Blast radius: one leaked dev key reaches your production customer identity store in four hops. Every edge above is a command we ran and you can re-run, not a claim we're asking you to trust.

We never take what is behind the door. To prove database access we write our own marker, read it back, then drop it. We never read one row of your data.

When the light is green, you are clear to go.

No risk scores, no maybes. We find the path an attacker would take, prove it, and hand you the exact command to close it. Then we run it again. Green is not an opinion. It is a door we tried to open and could not.

WDJ-SERVICE-01 external attack-surface assessment Fixed price

The product

External bill of health

A proof-based assessment of everything your company exposes to the internet. Every finding carries the evidence that produced it and the exact fix. Then we run it again.

$12,000 Standard fixed fee
$7,500 Founding-client rate

While the reference list is being built. Same scope, same report, same re-run.

  • Deposit50% to open the engagement. Balance net-15 on delivery.
  • WindowTypically two weeks, from ownership proof to report.
  • Re-runIncluded. After your fixes we run it again to confirm the door is closed.
  • BillingInvoiced directly. Scope signed and dated before anything runs.

What's included

  1. 01
    Ownership proof first.A DNS TXT challenge proves you control the domain before any runner is pointed at it.
  2. 02
    Passive OSINT.DNS enumeration, TLS certificate host discovery, subdomain takeover checks, search dorks, and breach exposure via k-anonymity. Zero packets reach your target.
  3. 03
    Perimeter walk.TCP connect, HTTP surface, service banners, and sensitive-path checks on every in-scope host. One request per probe, sequential, no flooding.
  4. 04
    KEV and NVD correlation.Observed products and versions matched against CISA KEV and NVD. Detection only, no exploit. KEV hits raise severity.
  5. 05
    The report.Per finding: severity, redacted proof, a blast-radius statement, and the exact fix command.
  6. Re-run after fixes.Same scope, same runners. Green is a door we tried again and could not open.

Two-account authorization testing (BOLA / IDOR, read-only) and offline review of a provided mobile APK can be named in scope when you provision test identities.

Also available, scoped per engagement

Physical and camera coverage Wi-Fi proximity testing BLE and connected-device review

Hands-on work, on site or against hardware shipped to the lab. Scoped and priced per engagement.

Back to top