KNULL / ABRIENDO CANAL

The calm is
skin deep.

What you do not see is there too.

Solicita una evaluación de seguridad ofensiva: cuéntanos qué quieres poner a prueba, en qué plazo y en qué modalidad.

Ver servicios
01 / SERVICES

Beneath the
surface.

We test applications, people and everything your company left exposed without noticing. Every finding is demonstrated, prioritised by impact and tested again after you fix it.

01

Web and API penetration testing

APPLICATIONS

Authentication, business logic, permission control and data exposure. We follow the paths that connect an apparently minor flaw to real impact on your operation.

Manual testing · Reproducible evidence · Impact prioritisation · Retest
02

Mobile penetration testing

IOS / ANDROID

What stays on the device and what travels to your backend. We analyse the app and its connections to find where trust between the two breaks.

Static and dynamic analysis · Storage · Communications · APIs
03

Corporate OSINT

PEOPLE · ASSETS · INFRASTRUCTURE

Your attack surface starts long before the login page. We connect public information, forgotten assets and digital footprint to understand what an adversary sees before the first attempt.

External inventory · Digital footprint · Public exposure · Risk paths
04

Threat intelligence

DEEP / DARK WEB

Mentions of your brand, your employees' credentials and signs that someone is already preparing. We investigate open sources and closed spaces, and validate every signal before handing it to you.

Intelligence by scope · Finding validation · Context · Recommendations
05

Social engineering

PEOPLE

Agreed phishing simulations and practical training for the people who face these threats every day. Every exercise ends in judgement to recognise them and respond in time.

Controlled simulation · Metrics · Workshops · Improvement plan
06

Exploit development

RESEARCH TRACK

Original vulnerability research and proof of concept work on custom software. Not for hire yet: when it opens, it will open with published work behind it.

Every project starts with an agreed scope and explicit written authorisation. It ends with evidence, context and the concrete steps to close what we found.

02 / GLOBAL REACH

From Mexico.
No borders.

Offensive security available for operations in Mexico, the United States, Europe and India. The same technical rigour, wherever you operate.

Our methodology
  1. 01 / ORIGINMexicoHome base
  2. 02 / CONNECTIONUnited StatesNorth America
  3. 03 / CONNECTIONEuropeRegional coverage
  4. 04 / CONNECTIONIndiaBengaluru
Remote coordination. Routes are illustrative.KEEP DESCENDING
03 / METHODOLOGY

Two ways in.
The same standard.

We choose how to work with you before the first test. Scope, use of AI and the handling of your data are all put in writing.

METHODOLOGY / 01IA + CRITERIO HUMANO

Hybrid AI

Machine breadth.
Human judgement.

  1. 01 / WIDEN

    Connect the signals.

    AI for reconnaissance, source correlation and prioritisation across the authorised scope.

  2. 02 / VALIDATE

    Put them to the test.

    A person exploits, chains and reproduces every finding. The technical decision is human.

  3. 03 / DEMONSTRATE

    Deliver evidence.

    Verifiable results, impact and remediation steps. Retest after you fix them.

Volume gets automated. Responsibility has a name.DATA AND SCOPE
HYBRID AI / IN PRACTICE

Coverage with control.

For large attack surfaces, multiple applications and threat intelligence. AI helps with the volume work; specialists decide what deserves a test and what can be backed by evidence.

  • Agreed data. We define what may be processed, redact identifiable information and agree on models that do not train on your data.
  • Manual validation. No model-generated result is presented as a finding without being reproduced.
  • Traceability. We document the use of AI and the tools employed.
METHODOLOGY / 02NO ARTIFICIAL INTELLIGENCE

AI-less

Human depth.
Data under control.

  1. 01 / UNDERSTAND

    Read the logic.

    Reconnaissance and analysis by specialists, with tooling on controlled infrastructure.

  2. 02 / GO DEEPER

    Follow the hypothesis.

    Manual testing of permissions, business logic and attack chains within scope.

  3. 03 / STAND BEHIND IT

    Prove every result.

    A report written by people, reproducible evidence and a statement of no AI use.

No phase of the service passes through an AI model.DATA AND SCOPE
AI-LESS / IN PRACTICE

Your information.
Your rules.

For sensitive information, strict confidentiality agreements and companies that need AI excluded from the service. Your code, data and findings stay on the agreed infrastructure.

  • Zero models. Reconnaissance, exploitation, analysis and reporting carried out without artificial intelligence.
  • Depth over breadth. The effort concentrates on understanding the operation and validating concrete risk paths.
  • Tooling record. We deliver a statement of no AI use and documentation of the work carried out.
CHOOSE THE APPROACH

Your operation sets the method.

Differences between the AI-less and Hybrid AI modes
Criterion AI-less Hybrid AI
Use of AI None, in any phase Reconnaissance, correlation and prioritisation
Your data Never sent to any model or third-party service Only what the contract allows, redacted and never used for training
Exploitation Human Human
Finding validation Manual Manual
Coverage Deep over a narrow scope Broad over large surfaces
Pace Slower per surface Faster at volume
Best for Regulated sectors and strict NDAs Short deadlines and continuous monitoring

Both modes start from written authorisation and end with verifiable evidence. Where your team sits does not change the agreed limits on your data.

Let us define your assessment
04 / ABOUT US

We test like
someone trying to get in.

An attacker does not follow a checklist, does not stop at six in the evening and does not hand over a PDF to satisfy an audit. That is the standard we work to, and that is the reason to hire us.

  1. You hire the person doing the work

    No sales layers, no juniors rotating through your project. The person testing your system is the same one who explains the finding and answers when your team asks.

  2. Attack chains, not lists of findings

    A scanner hands you loose symptoms and false positives. We show you how far someone gets by chaining them: what data they reach, what privileges they gain and what they can do with them.

  3. Reports your team can act on

    Every finding comes with steps to reproduce it, evidence, impact translated into your business and a concrete fix. The retest is included: we do not close until we confirm it is closed.

  4. Discipline, not improvisation

    Scope and authorisation in writing before the first test, testing windows agreed with your team, a direct channel throughout the engagement and immediate notice if something critical appears. The aggression goes into the testing, never into how it is run.

  5. People selected for what they find

    We gather the people who research out of obsession rather than office hours. You get in here by showing work, so what reaches your company is the result of that obsession and not the CV of a partner you will never meet.

We do not deliver a report.
We deliver how far an attacker would have got.

Knull exists because the talent that actually finds things rarely has the CV that opens doors, and because too many companies are paying for audits nobody really carried out. We brought those people together and gave them a place where their work speaks first. What your company receives is that difference.

Request an assessment
05 / TALENT

Your work
speaks first.

A finding, a tool, a write-up, a piece of research nobody asked you to do. Show us how you think.

WHAT WE CARE ABOUT

Curiosity that never switches off.
Rigour to prove it.
Judgement to act.

You do not need a degree.
You need something to show.
Full registration
06 / QUESTIONS

Before you
ask.

What is the difference between the AI-less and Hybrid AI modes?

In AI-less no phase of the work passes through an artificial intelligence model: reconnaissance, exploitation, analysis and reporting are done by a person, and none of your data goes to third-party services. In Hybrid AI, AI handles the volume work — reconnaissance, source correlation, prioritisation — while exploitation and validation stay human. In both, no finding reaches the report without manual verification.

In Hybrid AI, does my data enter an AI model?

Only what the contract allows before we start. Information identifying your company or your people is redacted, the models used do not train on what is sent to them, and there is a record of what was processed. If you prefer that nothing leaves your perimeter, AI-less is the right mode.

How is this different from a vulnerability scanner?

A scanner reports isolated symptoms and false positives your team has to filter. Our work starts where the scanner stops: chaining those symptoms until we demonstrate what data is reached, what privileges are gained and how far someone already inside can go.

What do you need to start?

An agreed scope in writing, explicit authorisation from whoever can grant it over the assets to be tested, the testing windows and a technical contact for incidents. Without signed authorisation no test is run.

What does the deliverable include?

Every finding prioritised by business impact, the steps to reproduce it, the evidence, the recommended fix and an executive summary for whoever decides. It includes a retest of what was fixed and a session with your technical team.

Do you sign an NDA?

Yes, before receiving any technical information. The AI-less mode exists precisely for the strictest agreements.

Do you need a degree to work here?

No. Selection is based on demonstrable work: a finding, a tool, a piece of research or a public write-up. We assess how you think, what you have built and how you document what you find.

KNULL / DATOS
DATA / CONTACT

Only what
we need.

What we store

For company requests: organisation name, services of interest, context, timeframe, chosen mode and email. For applications: handle, email, a public link to your work and whatever context you choose to share. Your consent and its date are stored with it.

What for

To assess the request and continue the conversation about a project or collaboration. These forms are not used to sign you up to any marketing list.

Where

Requests are stored on the server hosting this site. The form does not use an AI model and does not send your answers to analytics services.

What to avoid

Do not include passwords, secrets, third-party data or confidential vulnerability details. Exchanging sensitive information is agreed after the contact and scope are defined.

Share only information you are authorised to provide. Keep your request reference so we can identify it when the conversation continues.