Pentest team · Luxembourg & Greater Region

Penetration testing in Luxembourg.Our team thinks like attackers to secure your systems.

PENTESTLAB brings together a team of certified pentesters in Luxembourg. We audit your web applications, infrastructure and cloud environments, and run realistic Red Team engagements — to find your vulnerabilities before attackers do, in line with NIS2, DORA and GDPR.

68 Hauptstrooss, L-9753 Heinerscheid · Luxembourg
team@pentestlab: ~

$ nmap -sV -sC client.lu

PORT     STATE  SERVICE   VERSION

22/tcp   open   ssh       OpenSSH 8.9

443/tcp  open   https    nginx 1.24

$ scan complete — 3 findings prioritized

80+
Engagements delivered
300+
Vulnerabilities identified
6
Certified experts
24 h
Critical response time
// Services

Full-spectrum offensive coverage

Every engagement is tailored to your context, your stack and your security maturity.

Web application pentest

In-depth audit of your applications and APIs following the OWASP methodology: injections, access control, authentication, business logic.

OWASP Top 10REST/GraphQL APIBusiness logic

Internal & external infrastructure

Mapping and exploitation of your network: Active Directory, privilege escalation, lateral movement, external exposure.

Active DirectoryPivotingPost-exploitation

Red Team

Realistic, stealthy attack simulation to assess your detection and response capabilities against a determined adversary.

Social engineeringEDR evasionC2

Cloud security

Configuration review and pentest of your AWS, Azure and GCP environments: IAM, buckets, secrets, cloud attack paths.

AWS / Azure / GCPIAMMisconfigurations

Mobile applications

Static and dynamic analysis of your Android and iOS apps: local storage, communication, protection bypass.

AndroidiOSMASVS

Report & compliance

A clear, prioritised and actionable deliverable — remediation- and compliance-focused (NIS2, DORA, GDPR) — with technical and executive debriefs.

CVSSRemediationNIS2 / DORA
// Team

A pentest team based in Luxembourg

Complementary profiles covering your entire attack surface, from web to cloud to Red Team.

MW

Marc Wagner

Technical Director & Red Team

Engagement leadership, offensive operations and Red Team scenarios.

OSCP · OSCE³

SK

Sophie Klein

Web & API pentester

Web applications, REST/GraphQL APIs, business logic and OWASP.

OSWE

TR

Tom Reuter

Infrastructure & AD specialist

Active Directory, privilege escalation, lateral movement.

OSEP

LH

Léa Hoffmann

Cloud security engineer

AWS, Azure, Kubernetes and cloud environment hardening.

CARTP · CKS

NB

Nico Berg

Red Team operator

Social engineering, EDR evasion and C2 infrastructure.

CRTO

AF

Anne Faber

Quality & compliance lead

Report delivery, remediation and NIS2 / DORA compliance.

CISSP

// Methodology

A rigorous approach, from scoping to remediation

Aligned with industry standards (PTES, OWASP, MITRE ATT&CK) and transparent at every step.

01

Scoping

Defining the perimeter, objectives, rules of engagement and intervention windows.

02

Reconnaissance

Information gathering, attack surface mapping and identification of entry points.

03

Exploitation

Controlled exploitation of vulnerabilities, privilege escalation and impact demonstration.

04

Reporting

Detailed, prioritised and actionable report, followed by a debrief and remediation support.

// Expertise

A proven technical arsenal

Skills constantly updated to keep pace with emerging threats and attack techniques.

Offensive security

Web / APIActive DirectoryRed TeamPrivilege escalationEDR evasion

Tools

Burp Suite ProNmapMetasploitBloodHoundCobalt StrikeImpacket

Cloud & containers

AWSAzureKubernetesDockerTerraform

Compliance

NIS2DORAGDPRISO 27001PCI-DSS

Team certifications

OSCP

Offensive Security Certified Professional

2021

OSEP

Offensive Security Experienced Penetrator

2023

CRTO

Certified Red Team Operator

2023

CARTP

Certified Azure Red Team Professional

2024

Engagements covered by professional liability insurance and carried out within a strict legal framework (written authorisation, rules of engagement, confidentiality).

// Contact

Ready to find your flaws before attackers do?

Let's discuss your scope and objectives. Reply within 24 h, free quote — in Luxembourg and the Greater Region.