Sample reports
Redacted reports from real OSec engagements. Read or download each one in full.

Network Penetration Test
OSec breached the external perimeter, reached internal systems and private AWS infrastructure, and pulled administrative and IAM credentials from an uninitialised InfluxDB instance — a single critical chain, plus twelve more findings.
Read the report →
Web & Mobile Application Assessment
By manipulating identifiers in API requests, OSec read other users’ account data and balances; the MFA flow allowed full API access before the second factor was ever completed. One high-risk finding, five medium.
Read the report →
Purple Team & Ransomware Tabletop
OSec ran a ransomware scenario end to end, mapped each step to MITRE ATT&CK, and recorded what the client’s tooling caught and missed. The verdict: detections existed, but their coverage and timeliness could be materially improved.
Read the report →