Skip to content
All systems nominalMITRE ATT&CK · PTES · TIBER-EU · TLPT · DORA
OFFENSIVE SECURITYRED · PURPLE · BLUE

We model the
adversary
your tooling
is built to miss.

Full-scope red teaming, penetration testing, and malware development. Scoped, evidenced, and reproducible. Every finding ships with a working proof-of-concept and the exact path to close it.

400+
Findings shipped
8+ yrs
In offensive security
100%
Reports with PoC
ragnarops@labs:~/eng/acme-finlive
ragnarops@labs:~/eng/acme-fin$recon --target acme.fin --scope full --quiet
[*] mapping external surface ............ done
[+] 41 hosts · 6 internet-exposed · 2 shadow IT
[i] forgotten staging VPN — no MFA, default creds
[~] pivoting via CI runner → internal registry
[!] path to Domain Admin in 3 hops
ragnarops@labs:~/eng/acme-fin$report --evidence --remediation
Live engagementRT-22911 critical
// 01  —  What we do

Six disciplines. One objective: find it before they do.

// 02  —  How we work

A repeatable operation, not a one-off scan.

Five phases, one standard of proof. The shape of the work never changes — frame it, get hands on the system, evidence what we find, hand over the fix, then verify it died. Only the second phase changes with the discipline.

Aligned to

  • MITRE ATT&CK
  • PTES
  • TIBER-EU
  • TLPT
  • DORA
typical: 6 weeks
  1. Frame

    Week 0

    Objectives, boundaries, and rules of engagement — agreed and signed before a single packet moves. We pick the named threat actor your regulators actually worry about.

    [ artifact ] Signed ROE · named threat actor · crown-jewel asset map

  2. Emulate

    Weeks 1–3

    We operate like the actor in your threat model: patient, quiet, and creative. Custom tooling where off-the-shelf trips EDR. Tradecraft, not noise.

    [ artifact ] Campaign log — every action timestamped, deconflicted, attributable

  3. Evidence

    Weeks 3–4

    Every step is logged as we go. Findings arrive with reproducible PoC, blast radius, and screenshots — not a CVSS sticker.

    [ artifact ] Ranked findings · working PoC per finding · critical-path graph

  4. Hand-off

    Week 4

    We hand the blue team the exact fix and the detection rule that would have caught us — mapped to MITRE ATT&CK, ready to deploy.

    [ artifact ] Fix path + tested detection per finding

  5. Verify

    Week 6

    A working session with your engineers: reproduce, close, verify. We re-run the attack path until it dies.

    [ artifact ] Re-test report · closed-path confirmation

operator@ragnarops — C2 beaconlive
Simulated operator console — C2, BloodHound, AFL++, semgrep and nmap captures. Output is illustrative, not engagement data.
100+Engagements delivered
400+Findings shipped
8+ yrsIn offensive security
100%Reports with PoC
// 03  —  Who we are

One operator. No bench, no handoff.

The person who scopes your engagement is the person who runs it and writes the report. No account manager in between, no junior on the keyboard, no findings you cannot get an answer about.

  • 100+ engagements delivered
  • MITRE ATT&CK · PTES · TIBER-EU · TLPT · DORA
  • Coordinated disclosure, every time

// Operator certifications

Certified across three disciplines

The credentials behind the work. Select a badge to inspect it.

Pablo RuizFounder · Lead operatorOffensive security since 2018 — Madrid, Oslo, Amsterdam. Runs the intrusion, then writes the report you can act on.

Offensive security since 2018, across Spain, Norway, and the Netherlands.

The certification path is deliberate rather than decorative: OSCP first, then the full OSCE³ chain — OSEP for evasion, OSWE for the web layer, OSED for exploit development — with GPEN and GCIH covering the defensive side, CRTO for red-team operations, and AWS Security Specialty for the cloud work.

Read for his degree at Universidad de León part-time while working full-time, finishing with first-class honours.

The practice operates from the Netherlands and works remotely, worldwide.

LanguagesSpanish · English · Norwegian

Certifications11 held across offensive, defensive and cloud disciplines

Trusted where the blast radius is real

  • Railway
  • Public sector
  • Financial
  • Entertainment
  • Critical infrastructure
// 04  —  From the Labs

We publish what we learn.

All field notes
// 05  —  Get in contact

Schedule a scoping call.

Tell us what keeps you up. We come back with a threat model, a proposed scope, and a price — inside 48 hours.

  • Aligned to TIBER-EU · TLPT · DORA
  • Mutual NDA before scoping
  • 48h response

// Engagement request

scope://
Interested inRed teamPentestMalware devPurple teamCloud securityAI / ML

By submitting you agree to a mutual NDA before any technical detail is shared. We reply from contact@ragnaropsec.com.