Penetration testing Every system has a heel.

Achilles looks for it before someone else does. Penetration testing and vulnerability research for companies that would rather know where they're exposed than find out afterwards.

Independent research, not partnership

Where we do research

  • IntigritiResearcher on the platform
  • YesWeHackResearcher on the platform
  • CompTIACompTIA certification

Alongside client engagements, we hunt for vulnerabilities in bug bounty programmes on Intigriti and YesWeHack. We are not partners of either platform: we work there as independent researchers. It's where the method stays sharp, against real systems defended by real teams.

Four kinds of engagement

What we test

They can be combined, but each has its own scope and its own outcome. Every engagement is built around your environment and what worries you.

Application penetration test

We attack the application the way someone who really wants in would: authentication, access control, business logic, data handling. By hand, because scanners don't know what your application is supposed to do, so they can't tell when it does something else.

You get the vulnerabilities we found, each with proof that it can be exploited and guidance on closing it.

Request this test

Network and infrastructure test

We start from whatever is reachable from the internet, or from an ordinary workstation inside the network, and see how far it goes: exposed services, weak configurations, reused credentials, paths to the systems that matter.

You get the attack path step by step, so it is clear which link is worth breaking first.

Request this test

Vulnerability assessment

A broad sweep of everything that is exposed, with findings verified by hand and cleared of false positives. Shallower than a penetration test, wider: useful as a starting point or as a periodic check.

You get a list ordered by real severity, not by the score a tool assigned.

Request this test

Retest

After the fixes we go back to the same spots and retry the same attacks, plus the obvious variants. A patch that blocks the proof but not the cause is the most common case.

You get a verdict for each vulnerability: closed, partial or still open.

Request this test

Always in the same order

How an engagement runs

Five steps. Nothing starts without written authorisation.

Step 1 / 5

Scope

We agree on what gets tested, during which hours and within which limits. It all goes into a signed document before anything is touched.

Step 2 / 5

Reconnaissance

We map the attack surface: what you know is exposed, and what you didn't know was still switched on.

Step 3 / 5

Attack

Manual testing, chained vulnerabilities, concrete proof. If something critical turns up we tell you straight away, without waiting for the report.

Step 4 / 5

Report

Every vulnerability with severity, steps to reproduce and a recommended fix. A summary for those who decide, the detail for those who build.

Step 5 / 5

Retest

Once you have fixed things, we verify. The engagement ends when the problems are closed, not when the PDF is delivered.

The firm

Offensive security is all we do

Achilles is an offensive security firm based in Cuneo, Italy. Every engagement has an agreed scope, a single technical point of contact and a report written by whoever ran the test.

Alongside client engagements, Achilles does independent vulnerability research in the bug bounty programmes of Intigriti and YesWeHack and works with CompTIA-certified skills. It is the same method we bring to companies that want a tailored test.

Cuneo, as it happens, is also the Italian word for wedge: the tool you drive into a crack to open it. That's the job.

The Achilles practice in Cuneo
Based in
Cuneo, Italy
Platforms
Intigriti, YesWeHack
Certifications
CompTIA
Working languages
Italian, English

Frequently asked questions

Before you request a penetration test

What is the difference between a penetration test and a vulnerability assessment?

A vulnerability assessment is a broad sweep: it lists what is exposed and orders it by severity. A penetration test goes deep on a defined scope: it tries to actually exploit vulnerabilities and chain them, to show how far an attacker could get.

Do you need authorisation to run a penetration test?

Yes, always. No test starts without a signed document that sets out what is tested, during which hours and within which limits. Testing a system without the authorisation of whoever is responsible for it is a crime.

Can a penetration test take production systems down?

The risk is handled before we start: hours, limits and techniques to exclude are agreed in the scope. If something critical turns up during the test, we tell you straight away without waiting for the report.

What does a penetration test report contain?

Every vulnerability with its severity, the steps to reproduce it and the recommended fix. It opens with a summary for those who decide; the technical detail is for those who build and run the systems.

Do you check that the problems are closed after the fixes?

Yes, with a retest: we go back to the same spots, retry the same attacks and the obvious variants, and for each vulnerability we state whether it is closed, partial or still open.

Ready?

Tell us what you want tested.

Two lines on what you have and what worries you are enough. We reply with precise questions and then with a quote for a defined scope.

When you submit the form, your data is transmitted through Formspree and delivered to Achilles. We use it only to reply to your request. This form is protected by Google reCAPTCHA.Privacy Policy

Or write to info@achillessecurity.it