Find it before they do.
HADESS is an offensive security team. We map what you expose, read the code you ship, attack your environment the way a real adversary would, and dig into the software you depend on. The same people write the research in this magazine.
Three products.
Two services.
Products you run continuously. Services where our operators and researchers work directly on your environment. Most teams start with one and add the rest as they mature.
Products
Attack Surface Management
Continuous discovery of everything you expose to the internet — before someone else maps it.
Explore ASM ProductSAST
Static analysis that finds exploitable flaws in source code while it is still cheap to fix.
Explore SAST ProductCareer
Career intelligence for security professionals and the teams that hire them.
Explore CareerServices
Your perimeter, as an attacker sees it.
Shadow IT, forgotten subdomains, test servers that never got switched off. HADESS ASM continuously discovers the assets you expose, fingerprints what runs on them, and tells you which ones are actually exploitable — not just which ones exist.
- Continuous discoveryDomains, subdomains, IP ranges, cloud assets and certificates, re-scanned on a schedule.
- Service fingerprintingWhat is listening, which version, and what it is connected to.
- Exploitability firstFindings ranked by real-world exploitability, not raw CVSS.
- Change alertsKnow the day a new host, port or login page appears.
- Misconfiguration checksExposed admin panels, open storage, default credentials, weak TLS.
- Analyst-verifiedCritical findings are confirmed by an operator before they reach you.
From the research library
Catch the flaw in the pull request, not the incident report.
HADESS SAST analyses source code before it is compiled or deployed, tracing untrusted input from where it enters to where it can do damage. Developers get the finding, the data flow and the fix in the place they already work.
- Taint-flow analysisSource-to-sink tracing for injection, deserialization, SSRF and more.
- CI/CD nativeRuns in your pipeline and fails builds only on what matters.
- Major web languagesCoverage for the languages and frameworks modern web teams use.
- Fast triageEach finding ships with context, data flow and a suggested fix.
- Portfolio viewTrack risk across every repository and application you own.
- Standards mappingFindings mapped to CWE and OWASP for compliance reporting.
From the research library
User-controlled customer reaches a SQL query through string concatenation. Use a parameterised query.
A real attack, on your terms.
A penetration test finds as many vulnerabilities as it can in a short window. A red team operation runs for weeks against an objective — and measures whether your people, processes and tooling notice. Intelligence-led, scoped with you, and stopped the moment you say so.
- Objective-drivenReach the segmented network, the director’s mailbox, the server room.
- Intelligence-ledTradecraft modelled on the threat actors that target your sector.
- Detection scoringEvery step logged: what you saw, what you missed, how fast you reacted.
- Physical & socialPhishing, pretexting and on-site access when it is in scope.
- Penetration testingExternal and internal tests when you need breadth over depth.
- Purple-team debriefReplay the operation with your SOC and close the gaps together.
- Not detectedReconnaissanceOSINT · staff & infrastructure mapping
- Not detectedInitial accessT1566 · targeted phishing
- Not detectedCredential accessT1558.003 · Kerberoasting
- Alert · 4h laterLateral movementT1021 · remote services
- Day 11Objective reachedRead access to finance file share
When the scanner has nothing left to say.
Scanners know the vulnerabilities that are already public. Our researchers go after the ones that aren’t — in your product before launch, in the third-party software you can’t replace, or in the patch a vendor just shipped without explaining.
- Product security reviewsPre-release research on your own software, firmware or devices.
- Third-party riskIndependent research into critical vendor software you depend on.
- Patch diffingUnderstand what a security update really fixes, and how fast it is exploitable.
- Exploit developmentProof-of-concept exploits that turn “theoretical” into evidence.
- Reverse engineeringBinary, protocol and Windows-internals analysis.
- Coordinated disclosureWe handle vendor coordination responsibly, on an agreed timeline.
Build the team that does all of the above.
The hardest part of security is people. HADESS Career turns what we know about security roles — what each level actually expects, which skills and certifications matter, and what the market pays — into career paths for individuals and upskilling plans for teams.
- Career pathsRole-by-role progression from junior to principal.
- Skill matricesWhat each level is expected to know and do.
- Certification roadmapsWhich certifications help, in which order, and which don’t.
- Market & salary dataCompensation and demand across roles and regions.
- Team upskilling plansMap your team’s skills against the roles you need to fill.
- Hiring supportRole definitions and interview loops for security hires.
Clear scope. Real evidence. Verified fixes.
Scope
We agree on objectives, targets, rules of engagement and who to call if something goes wrong.
Discover
Assets, code and attack paths are mapped before anything is touched.
Validate
Findings are exploited safely to prove impact — no unverified scanner noise.
Report
An executive summary for leadership, reproducible detail for engineers.
Retest
We confirm the fixes hold, and close the loop with your team.
Research-led, offense-first.
Published articles
Our research is public. Read how we think before you hire us.
Disciplines, one team
The people who find the exposure are the people who exploit it.
Free research PDFs
In-depth guides on exploitation, Active Directory, red teaming and more.
Based in Berlin
A European team, working under European data-protection rules.
Frequently asked
What’s the difference between a penetration test and a red team operation?
Depth and scope. A penetration test aims to identify and exploit as many vulnerabilities as possible over a short period. A red team operation is a deeper assessment run over weeks, designed to test your detection and response against a set objective — such as reaching sensitive data in a segmented environment.
Where does SAST fit in our development process?
As early as possible. SAST analyses source code before it is compiled, so it can run in the IDE, on every pull request, and as a gate in your CI/CD pipeline — catching flaws while they are cheapest to fix.
How is attack surface management different from a vulnerability scan?
A scan checks the targets you give it. ASM first works out what you actually expose — including assets you didn’t know about — and keeps watching for changes, so new exposures are found the day they appear rather than at the next scheduled scan.
Can we combine products and services?
Yes, and most teams do. ASM findings often seed a red team operation, and red team or research results feed back into SAST rules and developer training.
Tell us what keeps you up at night.
Pick a topic and we’ll route your message to the right lead. Every conversation starts with scoping — no commitment, no sales script.