See your exposure before attackers do.
Prox Offensive is a founder-led offensive security practice. External attack surface assessments, penetration testing, and application security testing help you understand what is exposed, what can be validated within scope, and what to fix first. Delivery stays direct from scoping through final review.
What we do
Four ways to work with us, from a fixed-scope external sprint to deep, goal-driven testing.
External Exposure Audit Sprint
A timeboxed review of your public-facing attack surface. Typical delivery is 3–5 business days after scope, prerequisites, and the start date are confirmed.
- Fixed scope, fixed price
- External-only, non-intrusive
- From $2,500
Penetration Testing
Goal-driven testing that validates attack paths where discovered conditions and written rules permit.
- Controlled proof-of-concept where conditions and rules permit
- Reproducible evidence appropriate to what was safely validated
- Scoped and authorized in writing before the first packet
Application Security Testing
Manual testing for the flaws scanners miss: broken auth, IDOR, business-logic abuse.
- Broken authentication, IDOR, and business-logic testing by hand
- Requests and responses your engineers can replay
- OWASP Top 10 and the logic flaws outside it
Mentoring
One-on-one mentorship for people breaking into offensive security.
- Live labs: Hack The Box, TryHackMe, home-lab builds
- Certification study planning and lab preparation
- Résumé, portfolio, and GitHub review
What is offensive security?
Offensive security is the attacker's half of cybersecurity, put to work on your side: the same tools, tactics, and techniques real adversaries use, run legally and under written authorization to find your weaknesses before someone hostile does.
Where authorized, controlled testing can help distinguish theoretical weaknesses from attack paths that can be safely validated, so remediation effort is directed toward the conditions with the greatest practical significance.
How we work
A structured engagement, from scope to practical verification guidance.
Scope
We confirm authorized targets and sign a clear scope agreement before any testing begins.
Test
Techniques are selected for the service and written scope; active proof-of-concept is reserved for authorized penetration and application testing.
Prioritize
Findings are validated, deduplicated, and ranked by what they would cost you in practice.
Deliver
You get evidence, a remediation roadmap, and verification steps, plus a findings review call.
Why Prox Offensive
Authorized & ethical
Every engagement requires written authorization. No testing without explicit owner permission.
Evidence-based
Confirmed findings include supporting evidence such as screenshots, requests, and reproducible steps.
Business-context first
We translate technical exposure into impact your leadership and auditors actually understand.
Remediation-focused
Reports prioritize remediation and include verification guidance where it fits the scope.
Founder-led delivery
Your point of contact owns scope, testing decisions, evidence review, reporting, and the final findings call. If specialist support would improve an engagement, it is disclosed before work begins and used only with client approval.

Felix Gutierrez
Founder & Offensive Security Specialist
I lead delivery from scope through final review. Testing, evidence, and report conclusions stay under my review; any approved specialist contribution is identified rather than hidden behind a handoff.
I publish research in the open: LLM red-teaming, adversary emulation, and recon automation. Studying how attackers read a public attack surface sharpens the service design without turning lab work into a client claim.
More about how I work →Proof, in the open
- research
- ai-redteam-lab ↗Reproducible harness for prompt injection, data leakage, tool misuse, and other LLM security failure modes
- research
- apt33-scythe-case-study ↗Adversary-emulation case study with detections and hunting queries
- research
- prox-recon ↗Offline-first reconnaissance core: linPEAS parsing, CVE matching
From the field
Explainers and research notes from the practice: the thinking behind the method.
Three Local Models, and the Two Attacks That Beat All of Them
We ran seventeen adversarial prompts at three local language models. The toughest one refused fifteen. The two that got through it were not the clever ones. They were the ones that arrived through a channel the model already trusted.
Read →Put Weight On It: An Open LLM Red-Team Lab
Most teams ship an LLM feature after prompting it a few times and calling it safe. We built a local-first, open-source harness that puts real adversarial pressure on a model and scores what breaks across a versioned adversarial test corpus.
Read →Security Assessment Before a SOC 2 Audit: What You Actually Need
SOC 2 doesn't name a penetration test as a hard requirement, but its criteria expect vulnerability management, and an external exposure assessment beforehand is the cheapest way to avoid findings. Here's what to run, and when.
Read →Reporting designed for decisions and remediation.
The reporting format covers an executive summary, prioritized findings with evidence, remediation guidance, and verification steps where applicable. Preview the structure.
Ready to find out what's exposed?
Book a short call, tell us what you're running, and we'll scope the right engagement.
