CaptiveCrunch: When the Network Is the Phish
CaptiveCrunch turns the captive portal itself into the phish, and MFA does not answer it. How the chain works, and what your simulations never covered.
Read the post →Brackish is an offensive security firm. We emulate real attackers against your systems, then hand you the evidence, the impact, and the fix — not a scanner export with the logo changed.
A representative chain: external exposure to domain compromise. Individual findings rarely matter on their own — the path does.
Fifteen engagement types, one team. Each one ends with something you can act on and hand to an auditor.
External and internal testing of your network, from the perimeter an attacker meets first to the lateral movement they attempt once inside.
Read more →Authenticated, business-logic-aware application testing that goes past the scanner output and into how your application actually works.
Read more →Endpoint-by-endpoint testing of the interfaces that carry your data, with a focus on authorization, input handling, and abuse resistance.
Read more →Android and iOS testing across the whole app: static and dynamic analysis, on-device data handling, and the backend APIs behind it.
Read more →Connected device testing across firmware, radio interfaces, companion apps, and the cloud services that tie them together.
Read more →Phishing, vishing, and pretexting campaigns run as a controlled test of your people, your process, and your ability to detect them.
Read more →Full-scope adversary emulation against people, process, and technology — measuring detection and response, not just exposure.
Read more →Ad-hoc or recurring scans, with the raw output plus an analyst pass that separates the findings that matter from the noise.
Read more →Continuous discovery of what you expose to the internet, with every finding validated by a tester before it reaches you. Powered by Pincher.
Read more →Hands-on testing of AWS, Azure, and GCP — identity, misconfiguration, and the paths that turn one foothold into a tenant-wide problem.
Read more →A source-led review of the codebase itself — exploitable flaws mapped to the line that needs to change, before the code ships.
Read more →Read-only reviews of Microsoft 365, CI/CD, identity, and cloud tenants — the settings an attacker would use, without firing a shot at production.
Read more →Hands-on testing of LLMs, agents, and RAG — prompt injection, data exposure, and the tools a model should never have been allowed to call.
Read more →On-site testing of buildings, badges, and desks — tailgating, cloning, and unlocked rooms that skip every network control you own.
Read more →Testing of your Wi-Fi estate the way a nearby attacker would: join, intercept, and see how far a wireless foothold actually goes.
Read more →No surprises, no scope creep, and no report you have to translate before anyone can act on it. Every project is managed by an experienced project manager, and it all runs through portal.brackish.io.
We agree targets, constraints, escalation paths, and what success looks like — in writing, before anything is touched.
We enumerate the real attack surface, which is routinely larger than the one on the asset inventory.
We prove impact by chaining findings the way an attacker would, rather than listing issues in isolation.
You get reproducible evidence, prioritized remediation, and a retest confirming the fixes actually hold.
Recent write-ups from engagements and research — the same testers, written down.
CaptiveCrunch turns the captive portal itself into the phish, and MFA does not answer it. How the chain works, and what your simulations never covered.
Read the post →The HIPAA Security Rule overhaul slipped again, and the 240-day compliance window is the part nobody reads. Where the rule stands and what it will demand.
Read the post →One phishing simulation a year measures a single day with a single pretext. Why cadence beats the annual checkbox, and which metric is worth reporting.
Read the post →Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.