Skip to content
Garlic Threat Offensive Architecture

Offensive securityfor software thatcannot affordsurprises.

Manual attack paths, proven with evidence. Fixed, then retested.

01Exposure

See what attackers see.

Attack path · external → dataIdle

02Services

What we break, and how.

  • Manual testing of the logic scanners can't reason about.

    Access control · Business logic · Injection · Sessions

03Approach

How we attack.

  1. 01Discover

    Every host, endpoint and identity you expose.

  2. 02Map

    How those assets trust and reach each other.

  3. 03Attack

    Chain small weaknesses into a real path.

  4. 04Prove

    Reproducible evidence. No theoretical findings.

  5. 05Remediate

    Fixes your engineers can ship this sprint.

  6. 06Retest

    We verify the fix. The path stays closed.

InternetWeb appAPIAuthInternal serviceCustomer data
EvidenceGT-F-014
Starting access
Standard user
Reproduced
3 of 3 attempts
Result
Privileged session issued
Attached
Steps · screenshots · logs
Remediation

Enforce MFA state on the server before a session is issued.

Owner: Platform · Effort: ~1 day

Verified closed

Same steps. The path is no longer reachable.

The stack we test with

Burp Suite
Burp Suite
Nmap
Nmap
Metasploit
Metasploit
Wireshark
Wireshark
OWASP ZAP
OWASP ZAP
FFUF
FFUF
SQLMap
SQLMap
Amass
Amass
Nuclei
Nuclei
mitmproxy
mitmproxy
Burp Suite
Burp Suite
Nmap
Nmap
Metasploit
Metasploit
Wireshark
Wireshark
OWASP ZAP
OWASP ZAP
FFUF
FFUF
SQLMap
SQLMap
Amass
Amass
Nuclei
Nuclei
mitmproxy
mitmproxy
Burp Suite
Burp Suite
Nmap
Nmap
Metasploit
Metasploit
Wireshark
Wireshark
OWASP ZAP
OWASP ZAP
FFUF
FFUF
SQLMap
SQLMap
Amass
Amass
Nuclei
Nuclei
mitmproxy
mitmproxy
Open padlock with a fracture
Exposed

04Finding

CriticalGT-F-014 · Customer portal · Production

Authentication bypass

  1. Entry point

    Public login flow

  2. Exploitation

    Second factor could be skipped

  3. Privilege

    Full session without MFA

  4. Impact

    Takeover of any account

Open

Exploitable as reported.

05Security

Verified, in writing.

The letter
Tested scope, dates, method and remediation status — signed.
Method
OWASP • NIST SP 800-115 • PTES
Evidence for
SOC 2 • ISO 27001 • HIPAA • PCI DSS
Registered
Udyam UDYAM-AS-15-0041561

Verify Authenticity

Scan to securely verify GT-VAPT-2025-1047 on our validation portal.

06About

Engineering led.

You talk to the people doing the testing. Operating from India.

AbraarFounder & CEO
DarshilCo Founder & CTO
WanishCo Founder & CBO
UjjwalCo Founder & COO
  • Recommended

    Sprint

    External surface, web app and API testing. Report, retest and attestation letter.

    From $499per engagement

  • Retainer

    Continuous testing that follows your release cycle, with a direct channel to the tester.

    Scopedmonthly

  • Enterprise

    Cloud, internal networks and assume-breach work with compliance-mapped reporting.

    Scopedper programme

Let’s find
the path in.