BrickellTechnologies

Miami, FL · Offensive security

Penetration testing that reads like an attack, not a scan report.

Brickell Technologies is a small offensive security shop. We test networks, web apps, APIs, mobile builds and cloud accounts by hand, then hand you the route in with the evidence attached. Once you have fixed it, the retest is included.

GXPN · GMOB · CSAP · CySA+ · Security+ · CEH · eCPPT · eJPT

How an engagement runs

Five steps, no mystery in the middle.

  1. Scoping call

    Half an hour. What you run, what is off limits, what is driving the date. You get a fixed price and a start week in writing after it.

  2. Authorization

    Signed rules of engagement, source IPs for your allowlist, test window, and a named emergency contact on both sides. Nothing gets touched before this is done.

  3. Testing

    Daily notes in a shared channel. Anything critical gets a call the day we find it, not a paragraph you discover in week three.

  4. Report and walkthrough

    One page your board can read, then the technical detail: reproduction steps, evidence, and the specific change that closes each issue. We walk your engineers through it live.

  5. Retest

    When the fixes ship, we verify them and reissue the report with findings marked closed. Included in the original price for 90 days.

What you actually receive

  • Executive summary written for people who do not do this for a living
  • Technical findings with working reproduction steps
  • Evidence: requests, responses, screenshots, recordings where it helps
  • Remediation guidance specific to your stack, not a link to OWASP
  • An attestation letter for auditors, customers, or a security questionnaire
  • Retest and a clean reissued report

Why bother with a small shop

The person on the sales call is the person testing.

Big firms staff the pitch with principals and the engagement with whoever is on the bench. That is not a moral failing, it is how utilization works at scale, but you feel it when the report arrives full of template text about a stack nobody looked at closely.

Here you talk to a tester, get tested by that tester, and argue with that tester about severity if you disagree. Which happens, and it is fine.

We also say when something is boring. Inflating a self-signed certificate on an internal jump box into a "high" so the report looks meaty wastes a quarter of your engineering time on nothing; you stop trusting the severities, and then you stop reading the reports.

Tools run in the background because they are good at coverage. The findings that matter come from somebody sitting with your application until the logic gives.

Partnership

CrowdStrike Falcon, deployed by people who attack endpoints.

Most EDR rollouts stall in the same place: the agent is on every host, the policies are still whatever shipped in the box, and nobody has tested whether a detection actually fires. We deploy Falcon, tune it against real techniques, and show you the telemetry from the attempt.

Where we usually start

  • Migration off legacy AV without a coverage gap in the middle
  • Policy tuning: prevention on, and the exclusions written down with a reason
  • Detection validation against the techniques we use on engagements
  • Identity Protection and Falcon module rollout beyond the base agent
  • Handover runbooks, so your team owns it instead of renting us

Credentials

Certifications held by the team.

Certificates do not find bugs, people do. They are here because procurement asks, and because GXPN and GMOB in particular take a while to earn.

Questions we get asked

What does a penetration test cost?

Price follows the day count, and the day count follows the scope. A single web application with two user roles is a much smaller job than a 400-host internal network, so we quote flat after a short scoping call rather than publishing a number that would be wrong for most people. You will have the figure in writing before anyone touches anything, and it does not move unless you change the scope.

How long does an engagement take?

Most jobs run one to three weeks of active testing, plus a few days for the report. Booking is usually the longer wait; we tend to be scheduling two to four weeks out. If you are up against an audit date, say so on the first call and we will tell you honestly whether we can hit it.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment answers "what is wrong here" across everything you own; it is broad, largely tool-driven, and repeatable on a schedule. A penetration test answers "what can someone actually do with it" by chaining those weaknesses together until something breaks. Assessments give you a list. Tests give you a story with proof attached. Compliance frameworks usually want both, at different intervals.

Will testing knock our systems over?

Denial-of-service is excluded by default and we do not run it unless you ask for it in writing. Everything else gets throttled, and fragile hosts get flagged during scoping so we can treat them carefully or leave them out. You get a phone number that reaches a tester, not a ticket queue, for the whole test window.

Can you produce the report our SOC 2 or PCI auditor wants?

Yes. We map findings to the control the assessor is going to ask about, and the report carries the scope, dates, methodology and tester credentials that auditors look for. See compliance readiness for the frameworks we work in.

Do you only work with companies in Miami?

We are based in Miami and we like being close enough to show up for internal and physical work across Miami, Miami-Dade County, Fort Lauderdale and the rest of South Florida. External, web, API, cloud and mobile testing is remote work, so location stops mattering there. Plenty of our engagements are outside the state.

Know what an attacker would reach first.

Tell us what you run and what worries you. We will come back with a scope, a fixed price and the earliest week we can start.