Skip to content

Hybrid
offensive security.

We combine AI agents and human specialists to identify, validate and exploit vulnerabilities. We test your security within an agreed scope, with authorized actions.

Web & API · Infrastructure · Cloud · IdentityExplore the scope ↓

Technology extends reach.
Judgment sets direction.

Rekon is far more than a scanner: we are professional pentest operators in offensive security, powered by our proprietary software ARGUS.

Before testing

Agree on the boundary.

Assets, access, exclusions and the testing window are written down.

During the assessment

Explore and validate.

ARGUS connects hypotheses. Specialists authorize intrusive actions and verify impact.

At delivery

Leave evidence.

Reproducible findings, priorities and limits. A person signs the result.

Explore ARGUS capabilities
./argus.
  1. Massively Multi-Agent Architecture

    Dozens of agents work the same objective in parallel, not a single model walking the surface in series.

  2. Specialized Hacking Agents

    Each agent is trained on a specific capability: reconnaissance, exploitation, evasion, credentials or privilege escalation.

  3. Collaborative Attack Intelligence

    Agents share findings and build on each other's results to push the attack forward.

  4. Autonomous Attack Planning

    Defines and rewrites its strategy from what it discovers inside the environment.

  5. Dynamic Attack Chaining

    Combines multiple weaknesses into attacks no single finding would reveal.

  6. Adaptive Exploitation

    Adjusts payloads, techniques and attempts in real time to how the system responds.

  7. Parallel Attack Exploration

    Tests thousands of hypotheses and possible entry paths at once.

  8. Goal-Driven Offensive Reasoning

    Pursues concrete objectives: reaching sensitive data, taking over an account, touching a critical asset.

  9. Novel Vulnerability Discovery

    Surfaces logic flaws and combinations that no rule or signature covers.

  10. Controlled Real-World Exploitation

    Actually exploits the vulnerabilities, inside safe and authorized limits.

  11. Autonomous PoC Generation

    Delivers a reproducible proof with the steps, payloads and evidence of compromise.

  12. Collective Learning

    Every agent builds on what the whole operation learned to make later decisions sharper.

  13. Industry-Adaptive Offensive Intelligence

    Agents train on each industry's context, stack and threats, and attack like an adversary of that sector.

What can we test?

Where could an attacker get in?

ARGUS evaluates the organization's security the way a real attacker would, deploying offensive agents specialized and adapted to its industry to identify, exploit and chain vulnerabilities within the authorized environment.

What we can assess

  • External Attack Surface

    What is exposed?

    Domains, apps, APIs, infrastructure and services exposed to the internet.

  • Internal Infrastructure

    What connects your systems?

    Internal networks, servers, endpoints and corporate systems.

  • Web & API Security

    What does your application allow?

    Technical vulnerabilities and business-logic flaws.

  • Cloud Environments

    How is your cloud configured?

    Configurations, identities, permissions, workloads and storage.

  • Identity & Access

    Who can access what?

    Credentials, privileges, Active Directory and lateral movement between accounts.

How we put it to the test

  1. Industry-Specific Testing

    Scenarios adapted to the business, its stack and its threat landscape.

  2. Attack Path Validation

    Paths from the entry point to critical assets.

  3. Controlled Exploitation

    Safe exploitation within the scope and limits agreed up front.

  4. Remediation Validation

    Fresh tests to confirm the gaps were actually closed.

You define the limits. We test how far an attacker can get.

Evidence to decide.
Context to fix.

The report connects the flaw to its consequence.

Your team gets reproduction steps and remediation actions. Leadership gets the impact and priority explained. What was not tested is documented too.

Inside a pentest report ↗

Synthetic example · not a real finding

A session accesses another organization's object.

Proof
Identity A → object B → unauthorized access.
Remediation
Check object ownership on every access.
Limit
Demonstration identities and data only.

Proof of Concept Generation

Get hard evidence, not alerts

Every confirmed finding ships with a reproducible PoC showing how it was exploited and what access it granted.

Exploitability-Based Prioritization

Focus resources on what actually matters

We rank gaps by proven exploitability and impact, so your team knows exactly what to fix first.

Business Impact Analysis

Understand what each gap means for the business

We turn technical findings into plain consequences: data exposure, account takeover, fraud or operational disruption.

Actionable Remediation Guidance

Get a concrete path to close every gap

Each finding comes with its root cause and specific remediation actions, so the owning team can move fast.

Attack Path Mapping

See how they could compromise your company

We map the routes an attacker would take from the first entry point to your most critical assets.

Technical & Executive Reporting

Communicate results to the whole organization

Detailed evidence for technical teams and a clear executive view for leadership, audit, clients and board.

Industry-Adaptive Offensive Intelligence

Test against threats relevant to your business

Agents adapt their strategy to your industry, infrastructure, operations and specific risks.

MITRE ATT&CK Mapping

Understand the real techniques an adversary would use

We map every executed attack to the real-world tactics and techniques of the MITRE ATT&CK standard.

Remediation Validation

Check the outcome of the fix

During the agreed retest, we repeat the tests and document verified fixes, unresolved findings and limitations.

Who are we?

Federico Segredo

CEO

Federico Segredo

Federico built his career around understanding how to make large organizations work better: automation, product, operations, integrations and data. At Tiendamia and PedidosYa he worked leading robotic process automation initiatives, redesign and optimization of operational processes, reductions in production times and improvements to critical KPIs. Fede eliminates manual tasks, reduces friction points and takes operational improvements to scale.

His differentiator is understanding an operation from end to end, finding where the bottleneck really is and turning it into an opportunity for improvement. He combines business vision, technology and an obsession with execution. At Rekon he applies that ability to turn ARGUS into a product, define the strategy and build a company capable of scaling.

LinkedIn
Federico López

CTO

Federico López

Ethical hacker, developer and responsible for creating ARGUS, our proprietary offensive cybersecurity software. He started programming and getting into hacking at 15, and turned the obsession into an exceptional ability to understand systems, find their weak points and build tools to exploit them.

LinkedIn

Questions that hurt to answer

The ones any serious buyer asks. Answered before the first call.

What does an engagement cover?

External attack surface, internal infrastructure, web applications and APIs, cloud environments and identity. Scope is fixed in writing before we start. Anything found outside scope gets reported, not exploited.

Who authorizes intrusive actions?

A person. The agent platform proposes and accelerates; every intrusive action passes a human gate and gets logged. Nothing is exploited without explicit authorization under the agreed rules of engagement.

What do I receive at the end?

A report signed by the person who supervised the test: validated findings, reproducible PoCs, MITRE ATT&CK mapping and priority by real impact, not scanner score. The delivery window is fixed in the contract.

How do I verify a finding?

Every finding documents conditions, steps and evidence. We state when risk or scope limits exploitation. A failed attempt does not prove the absence of vulnerabilities: we distinguish confirmed results, inconclusive tests and verified controls.

Is a retest included?

Retest scope and conditions are agreed in the contract. We repeat the agreed cases and document whether the fix works, the finding persists or the test remains limited.

What would an attacker do if they found you today?

Tell us what you need to validate. We start with context and agree on scope before testing.

Do not include credentials or sensitive information. Read our privacy policy.

hello@rekon.sh