0x01Services

We test your defences, then help you watch them.

Two services for organisations: penetration testing to find what is broken, and SOC monitoring to notice when someone tries to use it.

0x01.1Penetration testing

An authorised attack on your systems, written up so you can fix it.

We work through your application or network the way an attacker would: mapping it, probing it, and chaining small weaknesses into real impact. Scanners find the obvious. Access control flaws and broken business logic need a person who understands what the system is supposed to do.

Sample findingIllustrates our report format. Not from a real client.
HighCBX-0x1A

Broken access control on invoice download

CVSS 3.1
8.1
Asset
GET /v1/invoices/{id}
Category
OWASP A01

Endpoint unduh faktur tidak memeriksa kepemilikan. Pengguna yang sudah login dapat mengganti parameterid dan mengunduh faktur milik pelanggan lain.

Perbaikan. Pastikan di sisi server bahwa faktur milik pengguna pada sesi tersebut sebelum berkas dikirim.

What we can test

  • Web applicationsCustomer portals, admin panels, e-commerce, internal tools.
  • APIsREST and GraphQL backends, including the ones your mobile app talks to.
  • Mobile appsAndroid and iOS apps, their local storage, and their traffic.
  • NetworksExternal perimeter and internal network, including Active Directory.

Every report includes

  • Executive summary for management
  • Severity and CVSS 3.1 score per finding
  • Reproduction steps your developers can follow
  • Remediation guidance specific to your stack
  • Bahasa Indonesia and English versions
0x01.2SOC monitoring

Someone watching the alerts, so your team does not have to at 3 a.m.

A Security Operations Center only helps if alerts are read, judged, and acted on. Our analysts take that work on and report to your team in plain language.

Alert triage
An analyst looks at each alert, decides if it matters, and records why.
Escalation
Real incidents reach your team quickly, with the evidence attached.
Incident summaries
A written account of what happened, what was affected, and what was done.
Tuning
Noisy rules get fixed so your analysts and ours spend time on real signals.

Coverage hours, log sources, and response targets are agreed per client. Tell us what you run today and we will propose a setup.

Not sure which service fits? Describe the system and we will tell you.

Write to us in Bahasa Indonesia or English. A person on our team reads every message.