Proof, not a risk score
Nothing counts as a finding until we've shown it working. No CVSS guesses, no scanner dump for your team to sort through. Every claim is a single command, and we hand you the command.
Evidence-anchoredThe Eye of Horus · defensive security lab
Wedjat is a fixed-price external security assessment. We map what your company exposes to the internet, prove every finding with a command you can run yourself, and hand you the fix. When we say a door opens, you watch it open.
How we operate
The runners walk your perimeter the way a patient attacker would. What holds them back is not good manners. It is a scope gate that refuses any out-of-scope target before a packet leaves the box. That is what makes it safe to point at production.
Nothing counts as a finding until we've shown it working. No CVSS guesses, no scanner dump for your team to sort through. Every claim is a single command, and we hand you the command.
Evidence-anchoredThe engine runs inside a default-deny network jail. It reaches what the scope allows and nothing else. Every action is written to a hash-chained evidence record before it happens. We demonstrate the door opens. We never read one row of your data.
Scope-gated at every hopOne request per probe, sequential, never a flood. Version checks are detection only, no exploit. You find out what someone with time can reach from the outside. You find out from us, on a Tuesday, instead of from them.
No flooding, no DoSOwnership proven by DNS challenge before any runner points at you. Approved scope, dated window, recorded run. When a path crosses the line you set, we record that it exists and we stop. The constraint is the product.
Approved scope, dated windowThe blast radius
Four small mistakes that add up to one critical breach. Every finding in a Wedjat report has this shape: where it starts, each hop proven before the next, and what it reaches. Here is the shape of one.
Blast radius: one leaked dev key reaches your production customer identity store in four hops. Every edge above is a command we ran and you can re-run, not a claim we're asking you to trust.
We never take what is behind the door. To prove database access we write our own marker, read it back, then drop it. We never read one row of your data.
No risk scores, no maybes. We find the path an attacker would take, prove it, and hand you the exact command to close it. Then we run it again. Green is not an opinion. It is a door we tried to open and could not.
The product
A proof-based assessment of everything your company exposes to the internet. Every finding carries the evidence that produced it and the exact fix. Then we run it again.
While the reference list is being built. Same scope, same report, same re-run.
What's included
Two-account authorization testing (BOLA / IDOR, read-only) and offline review of a provided mobile APK can be named in scope when you provision test identities.
Also available, scoped per engagement
Physical and camera coverage Wi-Fi proximity testing BLE and connected-device reviewHands-on work, on site or against hardware shipped to the lab. Scoped and priced per engagement.