Pospíšil Petr | CyberPOPE Independent Consultant | Cyber Security Architect & vCISO
> ./simulate_adversary --full_scope

Offensive Security
& Technical Audits

I find the vulnerabilities before the real attackers do.
Comprehensive testing for Humans, AI, Applications, and Infrastructure.

01 // Human Layer

Phishing Assessment

Social Engineering

I craft targeted phishing campaigns against your employees and deliver a full report of click rates, credential submissions, and detection rates.

INPUT: Employee Email List
OUTPUT: Campaign Statistics & Behaviour Report

02 // Artificial Intelligence

AI / LLM Red Teaming

Prompt Injection

Targeted testing for AI chatbots and agentic LLMs — jailbreaking, system prompt extraction, RAG pipeline attacks, and tool call hijacking.

INPUT: Chatbot / Model Access
OUTPUT: Prompt Hardening Strategies
Full scope, OWASP LLM & Agentic Top 10, pricing

03 // Application & API Security

Traditional Web Applications

Logic / XSS / SQLi

Real-world attack simulation on your application logic — data breaches, XSS, SQL injection, and authentication flaws.

INPUT: URL, Test Creds (Graybox)
OUTPUT: Technical Report with Executive Summary

GraphQL & API Testing

Modern Architecture

Manual testing for BOLA, BFLA, excessive data exposure, and injection flaws across REST, GraphQL, and WebSocket APIs.

INPUT: Swagger/OpenAPI Specs
OUTPUT: Technical Report with Executive Summary
Full scope, role requirements & pricing

04 // Infrastructure & Network

External Network PenTest

Attack Surface Management

I map your digital footprint and attempt to breach your perimeter — essential for companies with unknown asset sprawl.

INPUT: Public IPs & TLDs
OUTPUT: Attack Surface Report

Active Directory Health Check

Ransomware Prevention

90% of ransomware spreads via AD. I audit your Domain Controllers for Kerberoasting, weak service accounts, and legacy protocols.

INPUT: AD Read-Only Access
OUTPUT: AD Risk Report

05 // How We Collaborate

01
Discovery & Scoping

We define the attack surface, testing type (black/grey/whitebox), and rules of engagement on a free scoping call.

02
Proposal & Contract

I send a fixed-price proposal. After sign-off we execute a framework contract (MSA/SOW) with a 35% advance deposit.

03
Execution

I conduct testing within the agreed window, alerting you immediately on any critical (business-stopping) findings.

04
Report & Debrief

You receive a technical report with an executive summary. We walk through findings together and agree on next steps.

05
Long-Term Retainer (optional)

I remain available for ad-hoc re-tests, advice, and strategic guidance throughout the year.

Ready to test your defences?

Start with a free 30-minute scoping call. I'll tell you what I need, what I'll test, and what it will cost — before you commit to anything.

Have questions? See the FAQ →