TOWERVECTOR

About

TOWERVECTOR

Independent security research and consulting for organizations that build and run critical systems.

Based in
Portugal

Position

TowerVector works from one position: an organization defends what it understands, and understanding a system means seeing how it breaks.

We test the way an attacker would, then stay long enough to help fix what we find.

01  Overview

What we do.

We test systems the way attackers do, help the engineers and IT administrators who own them fix what we find, and put in place the controls that keep it fixed.

The work spans offensive security, product and vulnerability research, cloud and infrastructure, secure development, incident readiness, and security consulting. Clients come to us when they need to know how a system fails, before an attacker shows them.

View services

02  Expertise

Certified practitioners.

Five years of hands-on work across offensive security, application testing, and infrastructure, in environments ranging from a single product to estates spanning cloud and on-premise data centers.

Each certification below is verifiable directly with the body that issued it.

  • OSCP OffSec Certified Professional OffSec
  • OSEP Experienced Penetration Tester OffSec
  • OSWE Web Expert OffSec
  • CRTL Certified Red Team Lead Zero-Point Security
  • CRTO Certified Red Team Operator Zero-Point Security
  • CEH Certified Ethical Hacker EC-Council
  • SEC+ Security+ CompTIA

03  Research

We publish our research.

We publish our R&D, including research on new techniques, and advisories for vulnerabilities we report to vendors.

Vendor findings go through coordinated disclosure. We agree a timeline, give the vendor room to release a patch, and publish afterwards with the detail an affected organization needs to tell whether it is exposed or not.

You can find our PGP key and security contact at security.txt.

Read our research

04  How we work

Evidence, then remediation.

Three things hold across every engagement, whatever the scope.

Attacker mindset

Test systems the way attackers do

Manual, objective-driven testing against the systems you run, with every finding reproduced and evidenced.

Engineering depth

We help fix your findings

Findings come with the detail your engineers and administrators need, and we stay involved through remediation and re-testing.

Governance

Controls that survive testing

Frameworks turned into technical controls, prioritized by what reduces real risk first.

05  Contact

Tell us what you need.

TowerVector will assist you in taking your security strategy to the next level. Please feel free to contact us: