Blog

Todos nuestros aprendizajes desde the offensive side.

Walkthroughs, CVE disclosures and research written by the specialists who do the work, not by a content team paraphrasing them.

Weekly cyber news

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Sort by
26 articles

Cybersecurity companies in Spain: how to choose one

What to check before signing with an offensive security provider in Spain: scope, methodology, who does the work, the deliverable, the retest and what the applicable rules ask for.

AS

How an external network pentest works

The real sequence of an external network penetration test: scope and rules of engagement, reconnaissance, perimeter analysis, exploitation, reporting and retest, plus what the test will not cover.

MA

How an internal network pentest works

The sequence of a real internal network penetration test: the starting point we agree, what a domain account becomes, what you get at the end, how long it takes and what the exercise deliberately does not cover.

MA

How a mobile application pentest works

The real sequence of an iOS or Android engagement: what gets agreed before day one, what happens on a device we control, what reaches your backend, what you receive, and the six things this test deliberately does not cover.

MA

How a cloud pentest works

The real sequence of a cloud engagement: rules of engagement, external recon, identity mapping, proving the chain, the report and the retest. Including what it deliberately does not cover.

CF

How a web application pentest works

The seven phases of a web application penetration test, what has to be ready before day one, how long it runs, what lands in your inbox at the end, and the things it deliberately does not cover.

CF

How an API pentest works

A plain account of an API penetration test from the rules of engagement to the retest: what happens in each phase, what you get at the end, and the limits of what the test can tell you.

MA

How an AI pentest works

The engagement behind the button, phase by phase: how scope and rules of engagement get set, what reconnaissance covers on an AI system, the four layers of the technical phase, how findings are proved and reported, how long it takes, and what the test deliberately leaves out.

CF

Our pentesting methodology, end to end

The seven phases of an Asperis engagement, from scope and rules of engagement through to the retest, with the standard behind each one, the duration ranges we scope to, and a plain list of what a penetration test does not cover.

CF

How a wireless pentest works

The real sequence of a wireless penetration test, from the rules of engagement to the retest: what happens at each phase, what you need ready, how long it takes, and what this test deliberately does not cover.

MA

How an IoT pentest works

A connected product is hardware, firmware, a radio and a cloud backend at once. Here is the sequence we run across all four, what you receive, how long it takes and where the test stops.

CF

Hacked: incident response for companies operating in Spain

What to do in the first hours after a breach at a company operating in Spain: containment, evidence, the 72 hour deadline for notifying the AEPD, and what NIS2 and DORA require.

AS

Want to stay current on security? Get our weekly news recap in your inbox.

Every Tuesday you will get the latest news from the world of cybersecurity.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Want to publish your article here?

We publish research from people outside the team: findings, walkthroughs and analysis with real data behind it. We review it technically in house, and if it delivers what it promises, it goes out under your name and your link, not ours. We read everything that arrives; we do not publish everything that arrives.

Frequently asked questions.

What people ask us most before the first call.

A boutique cybersecurity firm is a small specialist that works by hand: its senior people run each engagement end to end, no engagement is delivered by automated scanning alone, and no defensive cross-sell dilutes the core work. It typically runs between five and fifty specialists with deep offensive certification, and takes on fewer engagements each year than a large consultancy. For European companies that take their security posture seriously, that matters because the attacker you face will not use a scan-and-deliver template, and neither should the team you hire to test you.

Three differences. First, who does the work: the senior specialists who scope your engagement are the ones who run it, walk you through the findings in our platform, and retest your remediation. You deal with those specialists directly. And we rotate auditors between engagements, so the next look at the same scope comes from someone who has not seen it before: whoever already mapped a system starts reading it the way it was explained to them and stops questioning the parts they have accepted, while a new auditor has nothing to take for granted. Second, scope discipline: we only do offensive work (red team, pentesting, and Dark Web Monitoring). We do not upsell SIEM, managed SOC, or GRC. Third, deliverable: every engagement closes with a live walkthrough, not with a PDF dropped in an inbox. The report is evidence, not the product.

Yes. Our red team practice runs the same way regardless of regulatory context: multi-week, goal-driven, manual, end-to-end against your live production environment within scope. When the engagement is framed under TIBER-EU or under the threat-led penetration testing provisions of DORA, we work with your control function and the regulator’s white-team representative, and we deliver against the framework’s evidence and reporting requirements.

Yes, completely free. You enter your company’s domain and we run it against a continuously updated intelligence feed: forums, paste sites, breach dumps, credential exposure, executive exposure. Results land in your inbox. No credit card, no auto-subscription, no follow-up sales call unless you ask for one. It is free because it answers one specific question ("is anything of ours already exposed?") and that conversation tends to lead naturally into a longer one if the exposure is material enough to act on.

Senior offensive specialists. Our team holds OSCP, OSCE³, OSWE, OSEP, CRTO, and CRTP credentials, and most have prior experience inside enterprise security teams or research-led red team units before joining us. We are NASA Bug Bounty-verified contributors, which means our findings on a public aerospace target meet a published quality bar reviewed by NASA’s security team. For sector context, our specialists have run engagements in fintech, healthcare, SaaS, energy, industrial, and Spanish public administration.