We do offensive security, and we are careful about what we claim
CyberShells runs penetration tests, red team assessments, and the reporting that makes them worth paying for. What follows is what we can actually back. There is no client logo wall on this page because we have not been given permission to publish one, and no headcount because that is not a number we will inflate.
What we do
We test the systems companies actually get breached through: web applications and the APIs behind them, corporate networks, Windows domains, and Azure tenants. Alongside the testing we do the work that usually gets skipped, which is writing it up so that the people who have to act on it can act on it.
That split matters more than it sounds. A report that only a penetration tester can read produces a ticket backlog and no change. A report that only an executive can read produces a slide and no change. Every engagement here produces one document with both audiences in it, because that is what turns a finding into a fix.
Where the approach comes from
Before the offensive work there was detection engineering and threat intelligence: writing the rules in Microsoft Sentinel meant to catch exactly the techniques we now use. That background changes how we test. We know which actions generate a log entry and which generate nothing, so the report tells you not only what we did but what your tooling should have seen and did not. It also means the remediation section speaks to the blue team rather than past them.
The underlying academic background is network engineering and security, which is why infrastructure findings come with an explanation of the protocol rather than a link to someone else's writeup.
Published, so you can check it first
The Arsenal is the methodology, published openly: certificate services attack chains from ESC1 to ESC16, BloodHound queries and owned node workflows, NetExec across every protocol it speaks, privilege escalation on Windows and Linux, and web exploitation references. It is the same material used on engagements. You can read the depth of the work before you spend anything on it, which is not a claim most security firms let you check.
There is also published research on phishing tradecraft and the abuse of trusted infrastructure, which is where the pretext development for social engineering engagements comes from.
How we talk about ourselves
The voice on this site is we, because CyberShells is the business you contract with. That is the only thing it is meant to convey. It does not imply a headcount, an office, a follow-the-sun rota, or a number of years in business, and you will not find any of those claimed anywhere on the site. If a number appears, it is either independently verifiable or it is labelled illustrative in the place it appears.
We also do not run a security operations centre, sell managed detection, or monitor anything on your behalf. We test, we report, we retest. When purple team work touches detection, it is your detection capability we are testing and tuning, and it stays yours.
What we will not do
- Invent a testimonial, a client name, or an engagement statistic. When real ones are cleared for publication they will appear on testimonials and case studies, and until then those pages say so.
- Sell you the larger engagement when the smaller one answers your question. If you ask for a red team assessment and you have never had a penetration test, we will say so.
- Ship a report full of unverified scanner output. Every finding is reproduced by hand before it is written up.
- Test anything outside a signed scope and rules of engagement.
Credentials
Certifications are the part of this page that does not require you to take our word for anything. Every one below is checkable against the issuing body, and the full wallet is public.
Offensive security
- OSCP+ Offensive Security Certified Professional
- eCPPT Certified Professional Penetration Tester
- eWPT Web Application Penetration Tester
Incident response
- eCIR Certified Incident Responder
Microsoft and cloud
- AZ-500 Azure Security Engineer Associate
- SC-200 Security Operations Analyst Associate
- SC-300 Identity and Access Administrator Associate
Talk to the people who do the testing.
Thirty minutes, free. Bring the environment and the deadline, and leave with a scope and an honest answer about what it will cost.