Lux-Nous Consult logo
What we do

Hands-on offensive security, not scanner-as-a-service.

Six services, all senior-led, all delivered through a secure portal with audit-grade reporting. Pick one or combine them into a multi-surface engagement.

01

Web Application Pentesting

OWASP WSTG-aligned, authenticated and unauthenticated testing of modern web apps, APIs, and SPAs. Auth, authz, business logic.

02

Network & Active Directory

Internal and external testing. Kerberos abuse, lateral movement, privilege escalation, domain dominance scenarios.

03

Red Team Operations

Objective-based adversary simulation. Phishing, C2, persistence, exfiltration — measured against your detection & response.

04

Mobile Application Testing

iOS and Android. Static and dynamic analysis, transport security, jailbreak detection, secure storage, API abuse.

05

Cloud Configuration Review

AWS, Azure, GCP. IAM, network exposure, data store posture, secrets handling, CIS benchmarks where they make sense.

06

Compliance-Aligned Testing

Pentests that map cleanly to PCI DSS, SOC 2, ISO 27001, HIPAA. One engagement, multiple audit checkboxes.

How an engagement runs

Same shape every time, so there are no surprises. Senior consultant scopes, executes, reports, and retests — start to finish.

  • 1
    Scope & threat-model30-min call. Define targets, rules of engagement, success criteria. NDA signed first.
  • 2
    Recon & enumerationAttack surface mapping with the same tooling and discipline adversaries use.
  • 3
    Manual exploitationReal attack chains, business-logic abuse, lateral movement — not just CVE matching.
  • 4
    Report & retestAudit-grade deliverable through the secure portal, plus a free retest of fixed findings.

Ready to see what an adversary would actually find?

Book a scoping call →