Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 27 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow External Pen Testing Companies?
EH-Net
May 25, 2013, 12:18:10 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: External Pen Testing Companies?  (Read 8111 times)
0 Members and 1 Guest are viewing this topic.
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« on: March 01, 2012, 09:34:14 AM »

Hello all:

I am looking for some suggestions on some good external / third-party pen testing companies.  I am looking for some suggestions as we are in the market for a new company to perform these.

Thanks in advance!
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Dark_Knight
Sr. Member
****
Offline Offline

Posts: 292


View Profile WWW
« Reply #1 on: March 01, 2012, 12:48:48 PM »

In no particular order :
- InGuardians
- Rapid7
- Offsec
- StrikeForce
« Last Edit: March 01, 2012, 12:51:17 PM by Dark_Knight » Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #2 on: March 01, 2012, 02:38:35 PM »

Muchos gracias!
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #3 on: March 01, 2012, 02:44:05 PM »

SecureState
and the list goes on... 

(Was gonna give you the first few that Dark_Knight provided, but he beat me to the punch)
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1060


aka dynamik


View Profile WWW
« Reply #4 on: March 01, 2012, 02:58:54 PM »

Shh, you guys. I PM'd him about consulting work. Lips sealed

I've personally had great experiences with Fishnet Security and SecureIdeas as well.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #5 on: March 01, 2012, 03:02:22 PM »

I'd stay away from the big companies unless you are spending a lot of cash. I've had bad experiences with the "bait n switch" where they send you resumes of rockstars with the SoW but then kindergartners show up on your doorstep. I find smaller firms with highly qualified folks (not all small firms have qualified folks) are hungrier for the work and more interested in delivering a quality product.
« Last Edit: March 01, 2012, 11:46:56 PM by tturner » Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #6 on: March 01, 2012, 03:03:40 PM »

Shh, you guys. I PM'd him about consulting work. Lips sealed

Sorry...  Embarrassed

 Wink
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
TheXero
Full Member
***
Offline Offline

Posts: 112


Try Harder!


View Profile WWW
« Reply #7 on: March 02, 2012, 03:46:41 AM »

You could always look at HatForce, I'm pretty sure that would end up cheaper than some other places.
Logged

MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #8 on: March 02, 2012, 11:30:32 AM »

You could always look at HatForce, I'm pretty sure that would end up cheaper than some other places.

I second that, especially if you're looking for a company where you pay per bug found (in case you choose crowd-sourced tests), but there's also the option of trusted tests, meaning only a few (trusted) testers from Hatforce will participate, where you know these are professionals, that almost competes in an ethical way to give you the best test possible, and many of them works like this while having a day job too, because they have a deep passion for infosec.  Smiley
Logged

I'm an InterN0T'er
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4169


Editor-In-Chief


View Profile WWW
« Reply #9 on: March 06, 2012, 09:08:51 AM »

At the risk of forgetting someone, here's some more:

Infogressive
Lares
Fortify's new ShadowLabs (Part of HP)
Trustwave
Booz Allen Hamilton
Core Security

And there's plenty of big accounting firms that do 'assessments' or 'audits.'

Hope this helps,
Don

PS - If I did forget anyone, sorry. Feel free to add your name to the list or just send me a note.
Logged

CISSP, MCSE, CSTA, Security+ SME
idr0p
Newbie
*
Offline Offline

Posts: 49


View Profile
« Reply #10 on: March 13, 2012, 06:16:47 PM »

Rapid7
Dell SecureWorks
IBM ISS
Logged

GCIA GCIH GPEN GWAPT
Up Next: CISA CISSP
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #11 on: March 13, 2012, 09:15:08 PM »

Coalfire!
Logged

ambient
Newbie
*
Offline Offline

Posts: 20



View Profile WWW
« Reply #12 on: March 14, 2012, 03:30:46 AM »

In UK,
Portcullis Security
NCC Group
Logged

don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4169


Editor-In-Chief


View Profile WWW
« Reply #13 on: March 29, 2012, 08:57:55 PM »

Adding a new section to our Links with the information in this thread and more. Check it out using the tabs at the top of the site... Resources > Links > Companies:

http://www.ethicalhacker.net/component/option,com_weblinks/catid,45/Itemid,27/

It's not complete, but it's a good start. What do you think?

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #14 on: March 30, 2012, 08:31:27 AM »

Good idea.  Gets the point across that there are options, and helps folks see some that they might not already have been aware of.

Thanks.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.097 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.