From serialised bytes to shell: exploiting Java deserialisation
Case study from an authorised pentest: Remote Code Execution via insecure Java deserialisation in Spring HttpInvoker.
Read →Bănci · Energie · Infrastructură critică · Sector public
Testăm sistemele unde o greșeală nu se repară cu un patch luni dimineața. Manual, ca un adversar real — nu cu un scanner care scoate 400 de pagini pe care nu le citește nimeni.
Activi în România, Republica Moldova și Uniunea Europeană. Firmă certificată ISO 27001 și ISO 9001, cu asigurare de răspundere profesională.
Fiecare constatare e găsită și verificată manual, cu lanț de exploatare demonstrat. Un scanner îți spune ce versiune rulezi. Noi îți arătăm ce se poate face cu ea.
Nu inflăm criticalitatea ca să pară raportul mai valoros. Primești o listă scurtă de lucruri care contează — și pe care echipa ta le poate închide.
ISO 27001:2023 și ISO 9001:2023 la nivel de companie. OSCP, OSWP, CEH, LPT, CISA și GICSP la nivel de echipă. Rapoarte bilingve.
A well-executed penetration test correlates vulnerabilities, configurations and access rights into a realistic attack scenario. The result shows which assets are exposed, which controls work and where intervention is most urgent.
Cloud, industrial systems, digital identity, AI models and software supply chains have radically expanded the attack surface. Our capabilities cover these environments without sacrificing the rigour of traditional testing.
We assess industrial control systems in energy, water, district heating and manufacturing. Testing is planned to limit operational risk and uses protocols and scenarios specific to industrial environments.
We assess public, private and government cloud, Kubernetes configurations, containers, IAM policies, pipeline secrets and the gap between infrastructure declared in code and what actually runs in production.
We build offensive scenarios from relevant threats and explicit business objectives. Exercises can be aligned with the TIBER-EU framework, national implementations and DORA operational resilience requirements.
We pentest with our own AI platform — a frontier or self-hosted LLM, plus a proprietary methodology with iteration loops, strict safety instructions and an interactive-pentester mode. The tools cut dead time; judgement and control stay with the tester.
We test prompt injection, data exposure through context, tool-equipped agent abuse, insufficient isolation and escalation through model integrations. The assessment tracks risks introduced when an AI system gets access to real data and processes.
We analyse embedded devices, firmware, hardware interfaces and communication protocols, including black-box scenarios and controlled physical access conditions.
We assess identity verification flows against synthetic presentations: generated images and video, manipulated documents, cloned voice, replay and liveness bypass. Testing is relevant for banking onboarding, fintech and payment institutions.
We execute attack techniques alongside the defence team and measure what the SOC, EDR and correlation rules detect, what goes unseen and how long the response takes. The result is a concrete plan for improving detection.
Ne-am format expertiza în proiecte complexe de securitate: cercetare, învățare și predare. De la retail la apărare națională, de la proiecte caritabile la ICS/SCADA — suntem prezenți într-o piață în continuă schimbare de peste 15 ani.
Ne place ce facem. Învățăm continuu, pe măsură ce apar tehnologii noi, și intrăm în fiecare proiect cu ambiția de a livra aceeași calitate fiecărui client.
Indiferent de industrie, știm că ești mândru de ce ai construit. Vrei să fie în siguranță și vrei să crească. Nu suntem doar experți tehnici — croim securitatea pe forma afacerii tale.
From one-off assessments to multi-year programmes, we define scope, depth and reporting based on critical systems, relevant threats and compliance requirements.
Web applications, REST and GraphQL APIs, API-first architectures and B2B integrations. Manual testing focused on application logic, authorisation and data impact.
Details →External perimeter, internal network, Active Directory, sensitive segments and wireless networks. We identify access paths, escalation and lateral movement.
Details →iOS and Android applications, including mobile banking, authentication mechanisms and RASP protections. We analyse the app, communications and associated APIs; retesting is included.
Details →Assessments against national authority and financial supervisor requirements, as well as frameworks and standards such as NIST CSF, ISO 27001, PCI DSS, NIS2 and DORA.
Details →Security assessments for industrial systems, networks and protocols, planned around safety, availability and process continuity requirements.
Details →Governance, risk analysis, policies, compliance programmes and security coordination for organisations that don’t need or don’t yet have a full-time in-house CISO.
Details →Every sector has different technologies, threats, obligations and risk tolerances. The methodology stays rigorous, but the scenarios and evaluation criteria are adapted to the operational context.
Commercial banks, credit institutions, fintech, payment institutions and processors, in heavily regulated contexts with strict resilience requirements.
Generation, transmission and distribution, hydropower, district heating and supply, with interdependent IT and OT infrastructures.
Water and sewage operators, where IT infrastructure, communications systems and the SCADA environment must be assessed together.
Organisations in nuclear, oil and gas and continuous-process manufacturing, where safety and availability take priority.
Pharmaceutical manufacturers, medical institutes and organisations managing sensitive data, laboratory systems and connected equipment.
Central and local authorities, digitalisation agencies and publicly funded projects, with high requirements for transparency, continuity and compliance.
Most projects are protected by non-disclosure agreements. The examples below are anonymised but preserve the type of organisation, the scale and the nature of the work.
Multi-year penetration testing and security audit programme for one of the largest banking institutions in Romania.
External, internal, interbank and wireless testing, complemented by vulnerability assessments, for a state’s central bank.
PCI DSS v4.0.1 audit for a payment application, with documentation accepted by the banking regulator.
Security audits and penetration tests for seven energy and critical-infrastructure companies, within a programme coordinated by an international development organisation.
Security assessment for application migration to a government private cloud, carried out under a framework agreement funded through the NRRP.
Penetration tests for organisations in the nuclear sector and the oil and gas industry.
Vigilum deploys credible decoy artefacts across your infrastructure — credentials, sessions, files, services and cloud keys — that no legitimate user or process has a reason to touch.
When one of these artefacts is accessed, you get an early, context-rich signal: the source of the activity, the pivot points and the path taken through the infrastructure.
Technical articles, project lessons and explanations of risks worth understanding. No marketing noise.

Case study from an authorised pentest: Remote Code Execution via insecure Java deserialisation in Spring HttpInvoker.
Read →
NIST PQC standards, the Harvest Now Decrypt Later threat and a migration framework for the financial and energy sectors.
Read →
Strategic study: from DARPA AIxCC results to risks for Romania and short-, medium- and long-term recommendations.
Read →Briefly describe the system, objective and estimated timeline. We’ll get back to you within one business day. For sensitive information, you can use our PGP key.