Offensive IT security
We show you where your systems are vulnerable
Wisp Security GmbH, based in Wiesbaden, delivers penetration tests, alarm tests and code security audits, and builds software for offensive security teams. We work independently, free from vendor interests – our sole focus is strengthening your security.
Services
Four services, one goal: knowing what an attacker can reach
Every finding is assessed in the context of your organisation and rated against realistic threat actors – so you know what to fix first.
- Penetration testing
- Risk-based testing of web applications, infrastructure and external attack surface – including Microsoft Entra (Azure AD) and Active Directory: attack paths, privilege escalation and lateral movement.
- Learn more →
- Alarm tests
- Realistic threat-actor emulation as a service partner of RedMimicry. We test whether your SOC, EDR, NDR and SIEM actually detect an attack – reproducibly, and usable in a DORA context.
- Learn more →
- Offensive development
- Tailored software for pentest, red-team and internal security teams: automation, operator tooling, integrations and the edge cases standard products do not cover.
- Learn more →
- Application & code security audits
- Security analysis of architecture, common vulnerability classes and critical areas – plus source code audits focused on security-relevant paths and data flows.
- Learn more →
Personal certifications
Certified senior expertise
Whoever tests you should be tested themselves: OSCP, OSWE, OSEP, OSED and OSCE³ from Offensive Security cover the breadth of offensive work – from networks and web applications to exploit development and evasion.
OSCP
OSWE
OSEP
OSED
OSCE³
First conversation
Get in touch – no strings attached.
Tell us about your systems and your question – we will tell you honestly which assessment makes sense and which does not.