HADESS
Cyber Security Magic
Latest Articles Case Study Skills & Certifications Career Guide White Paper Search Products & Services Talk to an Expert
Products & Services

Find it before they do.

HADESS is an offensive security team. We map what you expose, read the code you ship, attack your environment the way a real adversary would, and dig into the software you depend on. The same people write the research in this magazine.

5products & services
360published research articles
BerlinGermany
The lineup

Three products.
Two services.

Products you run continuously. Services where our operators and researchers work directly on your environment. Most teams start with one and add the rest as they mature.

Products

Services

Product · Attack Surface Management

Your perimeter, as an attacker sees it.

Shadow IT, forgotten subdomains, test servers that never got switched off. HADESS ASM continuously discovers the assets you expose, fingerprints what runs on them, and tells you which ones are actually exploitable — not just which ones exist.

  • Continuous discoveryDomains, subdomains, IP ranges, cloud assets and certificates, re-scanned on a schedule.
  • Service fingerprintingWhat is listening, which version, and what it is connected to.
  • Exploitability firstFindings ranked by real-world exploitability, not raw CVSS.
  • Change alertsKnow the day a new host, port or login page appears.
  • Misconfiguration checksExposed admin panels, open storage, default credentials, weak TLS.
  • Analyst-verifiedCritical findings are confirmed by an operator before they reach you.
asm / example.comIllustrative
214assets discovered
9new this week
3exploitable
vpn.example.com
SSL-VPN appliance · version with a known-exploited CVE
CRITICAL
jenkins.dev.example.com
CI server reachable from the internet · anonymous read
HIGH
api.example.com
Swagger UI exposed · internal endpoints documented
HIGH
backup-eu.example.com
Object storage listing enabled
MEDIUM
staging2.example.com
First seen today · login page, no SSO
NEW
Product · Static Application Security Testing

Catch the flaw in the pull request, not the incident report.

HADESS SAST analyses source code before it is compiled or deployed, tracing untrusted input from where it enters to where it can do damage. Developers get the finding, the data flow and the fix in the place they already work.

  • Taint-flow analysisSource-to-sink tracing for injection, deserialization, SSRF and more.
  • CI/CD nativeRuns in your pipeline and fails builds only on what matters.
  • Major web languagesCoverage for the languages and frameworks modern web teams use.
  • Fast triageEach finding ships with context, data flow and a suggested fix.
  • Portfolio viewTrack risk across every repository and application you own.
  • Standards mappingFindings mapped to CWE and OWASP for compliance reporting.
app/routes/orders.pyIllustrative
14@app.route("/orders") 15def orders(): 16 customer = request.args.get("customer") # source 17 cur = db.cursor() 18 cur.execute("SELECT * FROM orders WHERE customer = '" + customer + "'")19 return jsonify(cur.fetchall())
CRITICAL SQL injection CWE-89

User-controlled customer reaches a SQL query through string concatenation. Use a parameterised query.

request.args→customer→cur.execute()
Service · Red Team Operations

A real attack, on your terms.

A penetration test finds as many vulnerabilities as it can in a short window. A red team operation runs for weeks against an objective — and measures whether your people, processes and tooling notice. Intelligence-led, scoped with you, and stopped the moment you say so.

  • Objective-drivenReach the segmented network, the director’s mailbox, the server room.
  • Intelligence-ledTradecraft modelled on the threat actors that target your sector.
  • Detection scoringEvery step logged: what you saw, what you missed, how fast you reacted.
  • Physical & socialPhishing, pretexting and on-site access when it is in scope.
  • Penetration testingExternal and internal tests when you need breadth over depth.
  • Purple-team debriefReplay the operation with your SOC and close the gaps together.
operation / objective: finance segmentIllustrative
  1. Reconnaissance
    OSINT · staff & infrastructure mapping
    Not detected
  2. Initial access
    T1566 · targeted phishing
    Not detected
  3. Credential access
    T1558.003 · Kerberoasting
    Not detected
  4. Lateral movement
    T1021 · remote services
    Alert · 4h later
  5. Objective reached
    Read access to finance file share
    Day 11
Service · Vulnerability Research

When the scanner has nothing left to say.

Scanners know the vulnerabilities that are already public. Our researchers go after the ones that aren’t — in your product before launch, in the third-party software you can’t replace, or in the patch a vendor just shipped without explaining.

  • Product security reviewsPre-release research on your own software, firmware or devices.
  • Third-party riskIndependent research into critical vendor software you depend on.
  • Patch diffingUnderstand what a security update really fixes, and how fast it is exploitable.
  • Exploit developmentProof-of-concept exploits that turn “theoretical” into evidence.
  • Reverse engineeringBinary, protocol and Windows-internals analysis.
  • Coordinated disclosureWe handle vendor coordination responsibly, on an agreed timeline.
research / engagement workflow
01MapAttack surface, trust boundaries, inputs.
02HuntFuzzing, code review, reverse engineering.
03Root-causeWhy it breaks, and what else breaks the same way.
04ProveWorking proof-of-concept and impact.
05FixRemediation guidance and variant hunting.
06DiscloseCoordinated, on an agreed timeline.
Windows internalsActive DirectoryWeb applicationsBinary exploitationBrowsersKernel & driversMobileBlockchain
Product · Career

Build the team that does all of the above.

The hardest part of security is people. HADESS Career turns what we know about security roles — what each level actually expects, which skills and certifications matter, and what the market pays — into career paths for individuals and upskilling plans for teams.

  • Career pathsRole-by-role progression from junior to principal.
  • Skill matricesWhat each level is expected to know and do.
  • Certification roadmapsWhich certifications help, in which order, and which don’t.
  • Market & salary dataCompensation and demand across roles and regions.
  • Team upskilling plansMap your team’s skills against the roles you need to fill.
  • Hiring supportRole definitions and interview loops for security hires.
career / devsecops-engineerIllustrative
Staff
Security architecturePlatform strategyOrg-wide standards
Senior
Threat modellingPolicy as codeCKSAWS Security
Mid
SAST/DAST in CISecrets managementIaC scanningCKA
Junior
LinuxGit & CI basicsContainersSecurity+
Current level highlighted4 levels · skills · certifications
How we engage

Clear scope. Real evidence. Verified fixes.

Scope

We agree on objectives, targets, rules of engagement and who to call if something goes wrong.

Discover

Assets, code and attack paths are mapped before anything is touched.

Validate

Findings are exploited safely to prove impact — no unverified scanner noise.

Report

An executive summary for leadership, reproducible detail for engineers.

Retest

We confirm the fixes hold, and close the loop with your team.

Why HADESS

Research-led, offense-first.

360

Published articles

Our research is public. Read how we think before you hire us.

5

Disciplines, one team

The people who find the exposure are the people who exploit it.

116

Free research PDFs

In-depth guides on exploitation, Active Directory, red teaming and more.

EU

Based in Berlin

A European team, working under European data-protection rules.

Questions

Frequently asked

What’s the difference between a penetration test and a red team operation?

Depth and scope. A penetration test aims to identify and exploit as many vulnerabilities as possible over a short period. A red team operation is a deeper assessment run over weeks, designed to test your detection and response against a set objective — such as reaching sensitive data in a segmented environment.

Where does SAST fit in our development process?

As early as possible. SAST analyses source code before it is compiled, so it can run in the IDE, on every pull request, and as a gate in your CI/CD pipeline — catching flaws while they are cheapest to fix.

How is attack surface management different from a vulnerability scan?

A scan checks the targets you give it. ASM first works out what you actually expose — including assets you didn’t know about — and keeps watching for changes, so new exposures are found the day they appear rather than at the next scheduled scan.

Can we combine products and services?

Yes, and most teams do. ASM findings often seed a red team operation, and red team or research results feed back into SAST rules and developer training.

Talk to an expert

Tell us what keeps you up at night.

Pick a topic and we’ll route your message to the right lead. Every conversation starts with scoping — no commitment, no sales script.

[email protected] Berlin, Germany LinkedIn

Know your exposure before attackers do.

Attack surface management, SAST, red team operations and vulnerability research — from the team behind HADESS research.

Explore Products & Services