Offensive IT security

We show you where your systems are vulnerable

Wisp Security GmbH, based in Wiesbaden, delivers penetration tests, alarm tests and code security audits, and builds software for offensive security teams. We work independently, free from vendor interests – our sole focus is strengthening your security.

Services

Four services, one goal: knowing what an attacker can reach

Every finding is assessed in the context of your organisation and rated against realistic threat actors – so you know what to fix first.

Penetration testing
Risk-based testing of web applications, infrastructure and external attack surface – including Microsoft Entra (Azure AD) and Active Directory: attack paths, privilege escalation and lateral movement.
Learn more →
Alarm tests
Realistic threat-actor emulation as a service partner of RedMimicry. We test whether your SOC, EDR, NDR and SIEM actually detect an attack – reproducibly, and usable in a DORA context.
Learn more →
Offensive development
Tailored software for pentest, red-team and internal security teams: automation, operator tooling, integrations and the edge cases standard products do not cover.
Learn more →
Application & code security audits
Security analysis of architecture, common vulnerability classes and critical areas – plus source code audits focused on security-relevant paths and data flows.
Learn more →

Personal certifications

Certified senior expertise

Whoever tests you should be tested themselves: OSCP, OSWE, OSEP, OSED and OSCE³ from Offensive Security cover the breadth of offensive work – from networks and web applications to exploit development and evasion.

OSCP

OSCP

OSWE

OSWE

OSEP

OSEP

OSED

OSED

OSCE³

OSCE³

First conversation

Get in touch – no strings attached.

Tell us about your systems and your question – we will tell you honestly which assessment makes sense and which does not.