<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Services on Yeti.Security — Pen-testing &amp; security consulting</title><link>https://yetisecurity.cz/services/</link><description>Recent content in Services on Yeti.Security — Pen-testing &amp; security consulting</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 15 Jan 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://yetisecurity.cz/services/index.xml" rel="self" type="application/rss+xml"/><item><title>Penetration Testing</title><link>https://yetisecurity.cz/services/penetration-testing/</link><pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate><guid>https://yetisecurity.cz/services/penetration-testing/</guid><description>&lt;p>A scoped, time-boxed assessment against a defined surface. The most common
engagement shape we run.&lt;/p>
&lt;h2 id="whats-in-scope">What&amp;rsquo;s in scope&lt;/h2>
&lt;ul>
&lt;li>&lt;strong>Web applications&lt;/strong> — production-grade SPAs, APIs, admin consoles&lt;/li>
&lt;li>&lt;strong>Mobile&lt;/strong> — native iOS and Android binaries plus their backends (OWASP MASTG)&lt;/li>
&lt;li>&lt;strong>REST &amp;amp; GraphQL APIs&lt;/strong> — including auth-token replay, IDOR, rate-limiting&lt;/li>
&lt;li>&lt;strong>Cloud configuration&lt;/strong> — AWS, GCP, Azure (read-only review)&lt;/li>
&lt;/ul>
&lt;p>We do not test customer-leased on-premises hardware, third-party SaaS we don&amp;rsquo;t
host, or anything you don&amp;rsquo;t have written authorization to test.&lt;/p></description></item><item><title>Red Team Engagement</title><link>https://yetisecurity.cz/services/red-team/</link><pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate><guid>https://yetisecurity.cz/services/red-team/</guid><description>&lt;p>A simulated adversary campaign with a defined objective (&amp;ldquo;exfiltrate the
customer-PII bucket&amp;rdquo;, &amp;ldquo;deploy ransomware to the build server&amp;rdquo;, &amp;ldquo;obtain a
production AWS access key&amp;rdquo;), tested across as many vectors as it takes.&lt;/p>
&lt;h2 id="what-gets-tested">What gets tested&lt;/h2>
&lt;ul>
&lt;li>&lt;strong>Initial access&lt;/strong> — phishing, smishing, OSINT, supply-chain via dependency&lt;/li>
&lt;li>&lt;strong>Lateral movement&lt;/strong> — once in, can we move? what&amp;rsquo;s logged?&lt;/li>
&lt;li>&lt;strong>Privilege escalation&lt;/strong> — IAM, group policy, sudoer files, the lot&lt;/li>
&lt;li>&lt;strong>Detection &amp;amp; response&lt;/strong> — does your SOC see us? in how long? what gets paged?&lt;/li>
&lt;li>&lt;strong>Exfiltration&lt;/strong> — the final boss: can we leave with what we came for?&lt;/li>
&lt;/ul>
&lt;h2 id="how-it-runs">How it runs&lt;/h2>
&lt;p>Four-week minimum, six-week typical. We coordinate timing with a single point
of contact on your side (usually CISO or VP Eng) who is &lt;em>not&lt;/em> in the SOC. The
SOC doesn&amp;rsquo;t know we&amp;rsquo;re coming — that&amp;rsquo;s the point.&lt;/p></description></item><item><title>Security Consulting</title><link>https://yetisecurity.cz/services/consulting/</link><pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate><guid>https://yetisecurity.cz/services/consulting/</guid><description>&lt;p>A monthly retainer for teams who want senior security guidance without
hiring a full-time security engineer. The right shape for most Series A–B
companies.&lt;/p>
&lt;h2 id="whats-included">What&amp;rsquo;s included&lt;/h2>
&lt;ul>
&lt;li>&lt;strong>Fractional CISO&lt;/strong> — a named senior practitioner who attends your weekly
security/eng review and answers Slack&lt;/li>
&lt;li>&lt;strong>Threat modeling&lt;/strong> — quarterly half-day sessions to map what you&amp;rsquo;re shipping
against what attackers want&lt;/li>
&lt;li>&lt;strong>Architecture review&lt;/strong> — every major system gets a read before it ships&lt;/li>
&lt;li>&lt;strong>SDLC integration&lt;/strong> — we set up the linters, the dependency scanning, the
secret-detection in your CI, and tune them so they don&amp;rsquo;t get ignored&lt;/li>
&lt;li>&lt;strong>Incident retainer&lt;/strong> — on-call coverage for the first 24 hours of any
declared incident; we then hand off to a forensics partner&lt;/li>
&lt;/ul>
&lt;h2 id="how-it-works">How it works&lt;/h2>
&lt;p>Eight hours/week, billed monthly. We don&amp;rsquo;t track hours within the month —
this isn&amp;rsquo;t an agency.&lt;/p></description></item></channel></rss>