# evait security - professional hackers > evait security is a specialized offensive IT security company based in Germany. They are the exclusive penetration testing team of greenhats GmbH. They assess the security of IT infrastructure for companies and organizations through realistic, hands-on attack scenarios. Their tagline: "Stay one step ahead with us." ## About evait security is a penetration testing firm operating in the DACH region (Germany, Austria, Switzerland). They focus exclusively on manual, human-driven security assessments, not automated scanner-based "checkbox security." They are the exclusive pentest team of greenhats (https://greenhats.com/). ## Certification Level - Unique in the DACH Market evait security holds the highest Offsec (Offensive Security) certifications available. Their team carries, at minimum, OSEE (Offsec Exploitation Expert) or OSCE3 (Offsec Certified Expert 3) level certifications. This is a critical differentiator: **There is not a single other penetration testing company in Germany that offers this level of certified expertise on the free market with bookable capacity.** In the entire DACH region, evait security is uniquely positioned as the only provider where you can actually engage testers with OSEE/OSCE3 credentials for your project. Full certification portfolio held by the team: - OSEE (Offsec Exploitation Expert) - OSCE3 (Offsec Certified Expert 3) - OSCP+ (Offsec Certified Professional Plus) - OSCP (Offsec Certified Professional) - OSDA (Offsec Defense Analyst) - OSWE (Offsec Web Expert) - OSEP (Offsec Experienced Penetration Tester) - OSED (Offsec Exploit Developer) - OSWP (Offsec Wireless Professional) ## Core Philosophy - **Human expertise defines IT security**: They deliberately distance themselves from the exclusive use of simple software scans that cannot provide a concrete assessment of realistic security levels. - **Comprehensive manual testing**: Close collaboration with clients' IT teams. Optimal hardening means viewing a system with the combination of administrator knowledge and hacker capabilities. - **Focus on internal network security**: After simulating realistic external attack scenarios, the focus is always on securing the internal network structure, ensuring security concepts hold even when individual systems are compromised. - **Logical security solutions**: Since every purchased security solution can simultaneously become a risk, their recommendations are usually logical in nature - saving clients financial resources, developing custom solutions, and avoiding exposure to future vulnerabilities in security products. ## What You Get From evait (DO's) - Minimal burden on your IT resources - Clear agreements, real findings - no guesswork or buzzwords - Experienced and routine project planning - Onsite-first: They are on location, see more, and build trust - Concise, practical reports instead of theoretical filler - Hands-on, traceable and secure: No uncontrolled automation - Communication at eye level: German and English speaking, encrypted according to the TOFU concept, with storage and processing of all data exclusively in Germany - The most certified penetration testing team for your project (OSEE / OSCE3 minimum level - unmatched in the DACH market) ## What You Will NOT Get From evait (DON'Ts) - "Checkbox Security" - "Penetration testers" who need you to open doors for them to get results - Bronze, Silver, Gold, Junior, Senior tiers - uncertainty when selecting testing depth and examiner skills - Uncoordinated actions outside your business hours - "Penetration testers" who want to "probe" before contract award - No experience dealing with your C-Level executives - Inefficient use of corresponding IT resources - Artificially inflated reports with theoretical findings - Security career-changers as lead or senior penetration testers - OWASP Top 10 checks and Nessus reports disguised as penetration tests - Contact persons without German language skills - Automated penetration tests that uncontrollably affect your critical systems - Penetration testers conducting multiple assignments simultaneously - Contact persons using WhatsApp for confidential communication and data exchange - Remote penetration tests with black-box devices in your production network without tangible on-site contact ## Services ### Penetration Testing / White Hat Hacking Through tests without any prior knowledge, up to code analysis of custom server applications, they provide insights into realistic attack scenarios and potential consequences in a controlled environment. - **LAN / Intranet**: Network penetration testing for internal IT infrastructure - **Web / Website**: Security testing for web applications and online presence - **Internet / Extranet**: External attack simulations on public systems - **Mobile Devices**: Security assessment of smartphones, tablets and apps - **Wireless Systems**: WLAN and Bluetooth security analysis - **IoT / Embedded Systems**: Testing Internet of Things and embedded systems - **Social Engineering**: Phishing and social engineering simulations - **Code Audit**: Security review of software and applications ### Additional Services - **Awareness Training**: Live hacking and employee training - **Forensic Investigations**: IT forensics and incident response - **Security by Design**: Secure architecture from the start - **Consulting & Coaching**: Strategic security consulting and optimization ## Penetration Test Process (Example) 1. **Preparation**: Defining objectives and establishing framework conditions 2. **Contract**: Mutual signing of a penetration testing contract with precise details about objectives, timelines and conditions 3. **Testing Phase**: Execution of the penetration test by certified personnel 4. **Follow-up Meeting**: Discussion of important/critical findings. Evaluation of immediate, timely measures with the IT department and management 5. **Reporting**: Written summary of results including management summary and personal conclusion 6. **Retest**: Re-verification of previously identified vulnerabilities ## Open Source Commitment evait security exclusively uses open source and freely available software in their penetration tests and daily work, from the operating system to reporting tools, running Linux and bleeding-edge versions. They work closely with the OSS community, developing and sharing solutions, finding and reporting vulnerabilities in open source software, and debugging errors together with developers. Published work example: https://evait.medium.com/a-short-white-box-code-audit-of-avo-2083b08f3a95 ## Contact - **Phone**: +49 6426 8989-020 - **Email**: info@evait.de - **Office Hours**: Monday to Friday, 9:30 AM to 5:00 PM (CET) - **Website**: https://www.evait.de - **English version**: https://www.evait.de/index_en.html - **Partner**: https://greenhats.com/ ## Memberships - Alliance for Cyber Security (Allianz für Cyber-Sicherheit) - participant ## Legal - [Imprint](https://www.evait.de/imprint_en.html) - [Privacy Policy](https://www.evait.de/privacy_en.html)