ops@shreksec:~$ whoami
shreksec-llc
ops@shreksec:~$ ./engage --scope target.corp
offensive security consultancy // est. 2026
ops@shreksec:~$

We attack your systems first, so real attackers don't get the chance.

ShrekSec, LLC is a security consultancy delivering red team operations, hardware evaluation, reverse engineering, and vulnerability research. Security has layers, and we test every one of them.

// 01 services

What we do

Each engagement is scoped to your threat model and ends with findings you can act on, not a 300-page PDF of noise.

🎯

Red Team Pen Testing

Goal-driven adversary simulation against your people, process, and technology.

  • Network and Active Directory compromise
  • Web, API, and cloud assessments
  • Social engineering and phishing
  • Physical and wireless testing
  • Detection and response validation
🔌

Hardware Evaluation

Security review of devices, from IoT gadgets to embedded and industrial gear.

  • UART, JTAG, and SWD debug interface analysis
  • Firmware extraction and analysis
  • Secure boot and storage review
  • Bus sniffing and fault-injection feasibility
  • Radio protocols (BLE, Wi-Fi, sub-GHz)
🔬

Reverse Engineering

We take apart binaries and protocols to learn what they really do.

  • Native and firmware binary analysis
  • Protocol and file-format reversing
  • Malware and implant triage
  • Interoperability and legacy-system analysis
  • Patch diffing
🐞

Vulnerability Services

Finding, proving, and helping fix the bugs that matter.

  • Vulnerability research and fuzzing
  • Source code and binary audits
  • Exploitability and impact assessment
  • Proof-of-concept development
  • Coordinated disclosure support
// 02 engagement process

How an engagement works

Predictable, transparent, and safe. No surprises on your production systems.

Scope & Rules of Engagement

We define targets, objectives, constraints, and contacts, backed by a signed agreement and written authorization before any testing begins.

Recon & Threat Modeling

We map the attack surface and prioritize paths based on what a real adversary would pursue against you.

Testing & Exploitation

Hands-on, expert-driven testing with regular check-ins. Critical findings are reported immediately, not at the end.

Reporting & Debrief

Clear findings with evidence, risk ratings, and remediation guidance, plus an executive summary and a live walkthrough.

Retest

After you fix, we verify. A retest to confirm remediation is part of how we close the loop.

// 03 about

About ShrekSec

ShrekSec, LLC is a small, senior-led consultancy. The name is a joke; the work isn't. Every engagement is run by practitioners with hands-on offensive experience, not handed to a junior team after the sales call.

We keep our client list small so we can go deep, and we write reports that engineers and executives can both use.

$ cat principles.txt

  • Authorized testing only, always in writing
  • Client data is confidential and handled minimally
  • Findings are evidence-backed and reproducible
  • Honest scoping, no inflated severity
Red TeamEmbeddedFirmwareREVuln Research
// 04 disclosure policy

Responsible disclosure

If we find a vulnerability in a product or service during independent research, we follow coordinated disclosure: we notify the vendor privately, share technical details, and allow a reasonable remediation window (default 90 days) before publishing.

Found something in our own site or infrastructure? Please tell us. Send details to the address below, encrypted with our PGP key if possible. We will acknowledge reports promptly and will not pursue good-faith researchers acting within reasonable limits.

Our security.txt is published at the standard location.

Client engagement findings are confidential and are never disclosed without the client's written consent.

// 05 contact

Let's talk

Tell us what you need tested and we'll reply with a scoping call and quote.

PGP fingerprint:
64BD 62BF 36CA 8F10 9100  C1E4 DC21 E081 8C4C DE25

-----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEasfS2BYJKwYBBAHaRw8BAQdAsuSzLoGCSmwRvGxn9JLbQrzLG0FtNoOgUce2
fjQHrw+0JFNocmVrU2VjLCBMTEMgPGNvbnRhY3RAc2hyZWtzZWMuY29tPoiWBBMW
CAA+FiEEZL1ivzbKjxCRAMHk3CHggYxM3iUFAmrH0tgCGwMFCQPCZwAFCwkIBwIG
FQoJCAsCBBYCAwECHgECF4AACgkQ3CHggYxM3iVD0AEAj8Vu5jCtsJk9pZVoiL6p
joGrkblSEbecV/RYuUEVe+ABAI7WUrhQeH9ozx+QOmc8u/cfzydpBRCSTTpm1XaX
4moEuDgEasfS2BIKKwYBBAGXVQEFAQEHQDwTjdZdv6rm+r2RLpGeyFoywycVFFGp
QW2mxw9Jt24VAwEIB4h+BBgWCAAmFiEEZL1ivzbKjxCRAMHk3CHggYxM3iUFAmrH
0tgCGwwFCQPCZwAACgkQ3CHggYxM3iXdZQD/S0awoXQOtzRAR6wB2aiJGJFjDEUz
aR/vM7zbYikPaJAA/085BbdpS/bUDCAPoTZtP2Y1CkVTNg9k/VSxmiLkWO8L
=awHj
-----END PGP PUBLIC KEY BLOCK-----