Skip to content

Cybersecurity Offensive Security

Break to
understand. Build to
endure.

HavocSec is a cybersecurity firm focused on offensive security, ethical hacking, application security, and security engineering.

HV/IDX-001

Scroll

Philosophy HV/PHL-000

We don't assume systems are secure.

We test them.

We break them.

We understand why they failed.

We build from what we learned. .

01 Offensive Security


Find the weakness before someone else does.

Security assessments built around the way real attackers think.

01

Penetration Testing

Authorized testing of applications, APIs, infrastructure, and exposed attack surfaces.

02

Web Application Security

Assessment of authentication, authorization, access control, business logic, session management, input handling, and data exposure.

03

API Security

Assessment of authentication, authorization, access control, business logic, endpoint exposure, and sensitive data handling.

04

Infrastructure Security

Assessment of exposed services, configurations, network attack surfaces, and externally accessible infrastructure.

05

Adversarial Security

Attacker-oriented thinking applied to identify realistic attack paths and weaknesses.

06

Security Engineering

Security-focused tooling, automation, and engineering solutions built around real problems.

All security testing is performed only with explicit authorization and agreed scope.

All services in detail

02 How We Work


From scope
to security.

Every engagement runs the same disciplined arc. Clear boundaries first, controlled testing second, understanding last.

HV/OPS-PRO / SIX PHASES

  1. Scope

    STEP 01

    Understand objectives, assets, environment, and boundaries.

  2. Authorization

    STEP 02

    Establish explicit authorization and rules of engagement.

  3. Assess

    STEP 03

    Perform controlled security testing.

  4. Report

    STEP 04

    Document evidence, impact, severity, and remediation guidance.

  5. Remediate

    STEP 05

    Help understand and address identified weaknesses.

  6. Retest

    STEP 06

    Where applicable, verify remediation.

The Field Notes havocsec.dev

What we're learning.

Technical writeups, security discoveries, experiments, and ideas from the work. Published on the HavocSec blog, a separate publication that runs alongside this site.

Read the HavocSec blog

Recent subjects

  • Hack The Box writeups FN/01
  • CTF walkthroughs FN/02
  • Pentesting notes FN/03
  • OSINT FN/04
  • Security experiments FN/05

03 About


Security from the
offensive side.

HavocSec was built around a simple idea: the best way to understand how secure a system is, is to understand how it can be broken.

We combine offensive security, technical research, and engineering to uncover weaknesses and turn those lessons into stronger technology.

  • Authorization first 01

    No testing without explicit permission and agreed scope.

  • Evidence over claims 02

    Every finding comes with proof, impact, and context.

  • Offense informs defense 03

    Understanding the attack is what makes the fix hold.

Portrait of Daniel Wambua

FOUNDER / HV/FOU-001

Daniel Wambua

Known as Havoc

Daniel is the offensive security researcher behind HavocSec and the HavocSec blog. He works across penetration testing, security research, and security engineering, and builds the tooling HavocSec uses in the field.

04 Contact

Have something that needs breaking?

Let's identify the weaknesses before someone else does.

All security testing is performed only with explicit authorization and agreed scope.