Offensive Security & Ethical Hacking

Find the hole
before they do.

Derivee runs real penetration tests and red team engagements against real infrastructure, then trains the operators who run the next one. No dashboards pretending to be defense — just evidence, exploit chains, and fixes that hold.

OSCP · CREST · OSWE operators / 140+ engagements delivered / Reports built for auditors, not marketing
engagement.log — derivee/scope-042
TLP:CLEAR

Trusted by security & engineering teams at

Northwire Ledgerly Portway Logistics Fennick Health Cascade Cloud
How an engagement runs

Same phases an attacker uses. We just tell you when it works.

Fixed order because each phase depends on evidence from the last — this is the actual sequence, not a stylistic list.

01

Scope

Define targets, rules of engagement, and what "success" means for your business, in writing.

02

Recon

Map the real attack surface: assets, exposed services, identities, and third-party trust.

03

Exploit

Chain weaknesses into proven impact — data access, lateral movement, privilege escalation.

04

Report

Evidence-backed findings, severity, and reproduction steps — built for engineers, not slideware.

05

Remediate

Retest each fix until the finding is closed, not just marked "in progress."

140+Engagements delivered since 2019
1,900+Verified findings reported
36Zero-days responsibly disclosed
4.9/5Average client debrief rating
Engagement tiers

Transparent starting points. Every quote is scoped on the call, not guessed from a form.

Custom scopes, multi-year programs, and Academy team bundles are quoted separately.

Essential Scan

$3,900
starting · single application or network segment
  • External or internal network test, or one web app
  • Manual testing, not just automated scanning
  • Written report with reproduction steps
  • One 30-minute debrief call
Request a scope call

Enterprise Program

Custom
annual programs · red team & ongoing testing
  • Quarterly or continuous testing cadence
  • Red team simulation with purple-team option
  • Dedicated engagement lead
  • Academy training bundled for your team
Talk to us
Derivee Academy

Training built by people who still do the work on Monday morning.

Cohort-based, hands-on, graded against live vulnerable infrastructure — not multiple choice.

Foundations

Ethical Hacking Fundamentals

Networking, Linux, and the legal & reporting foundation every tester needs before touching a target — for career-changers and junior analysts.

6 weeks · cohort$690
Practitioner

Web Application Exploitation

Manual testing against deliberately vulnerable apps: auth bypass, injection, IDOR, and logic flaws — building toward OSWE-style rigor.

8 weeks · cohort$1,190
Advanced

Red Team Operations

C2 tradecraft, evasion, and adversary emulation against a monitored range with a live blue team on the other side.

10 weeks · cohort$1,890
Meet the operators

Certified, hands-on testers — the people named in your report signed it themselves.

Upload real photos any time from Appearance → Customize → Derivee — Photos.

Mara Osei
Mara Osei
Founder & Lead Red Teamer

OSCE3, 9 years offensive security across fintech and critical infrastructure.

Diego Fenner
Diego Fenner
Principal Web App Tester

OSWE, built the exploitation curriculum used in the Academy cohorts.

Priya Nandan
Priya Nandan
Cloud & Identity Lead

CREST CCSAM, specializes in IAM trust-path and misconfiguration reviews.

From the debrief calls

What clients say once the report actually lands.

"Most pentest reports are 40 pages of restated CVSS scores. Derivee's had eleven findings we could actually reproduce and fix the same sprint."

RK
R. Kapoor
VP Engineering, fintech platform

"The red team exercise found a trust relationship between two acquisitions that nobody on either security team knew existed."

JM
J. Mensah
CISO, logistics group

"Sent two analysts through the Web Exploitation cohort. Both were shipping real findings in our bug bounty program within a month."

AS
A. Suleiman
Security Lead, SaaS company
Questions we get on every scope call

Frequently asked questions

Most engagements run 1–3 weeks depending on scope, followed by a written report and a live debrief. Red team simulations typically run 3–6 weeks.

Yes. Every engagement includes one round of retesting so findings are confirmed closed, not just marked resolved.

Rules of engagement are agreed in writing before testing starts, including which techniques are in or out of scope for production environments, to avoid unnecessary risk of downtime.

A penetration test looks for as many exploitable vulnerabilities as possible in a defined scope. A red team engagement is objective-based and tests detection and response, often without your defenders knowing in advance.

Yes — reports are formatted to satisfy auditor requirements for SOC 2, ISO 27001, and PCI DSS penetration testing evidence requests.

Ethical Hacking Fundamentals assumes no prior security experience, just basic comfort with computers. The two advanced courses do expect that foundation first.

Free: the Attack Surface Checklist

The 20-point checklist our testers run through before scoping any engagement — find your obvious exposure before you pay anyone to find it for you.

Start an engagement

Tell us what you're protecting. We'll scope the rest.

A scope call is 30 minutes with a senior tester, not a salesperson. You'll leave with a rough estimate of timeline and cost.