Miami, FL · Offensive security
Penetration testing that reads like an attack, not a scan report.
Brickell Technologies is a small offensive security shop. We test networks, web apps, APIs, mobile builds and cloud accounts by hand, then hand you the route in with the evidence attached. Once you have fixed it, the retest is included.
GXPN · GMOB · CSAP · CySA+ · Security+ · CEH · eCPPT · eJPT
What we get hired for
Five things, done properly.
We turn work down when it is outside these. You are better off with somebody who does that thing every week than with us learning on your budget.
Penetration Testing
Network, web app, API, mobile and internal testing done by hand. You get the attack path, the proof, and a retest once it is fixed.
Penetration Testing →Vulnerability Assessments
Full-estate scanning, then a human pass to strip the noise and rank what is left by real reachability instead of raw CVSS.
Vulnerability Assessments →Endpoint Security
CrowdStrike Falcon rollouts, policy tuning and legacy AV migrations, run by people who break into endpoints for a living.
Endpoint Security & CrowdStrike Falcon →Cloud Security
AWS, Azure, GCP and Kubernetes reviews that chase IAM privilege escalation paths rather than stopping at a benchmark score.
Cloud Security Posture Assessments →Compliance Readiness
Gap assessment first, then the recurring scanning and pentest evidence your SOC 2, HIPAA, PCI DSS or CMMC auditor asks for.
Compliance Readiness & Scanning →Not sure which one?
Describe what you are running and what is driving the deadline. If a vulnerability assessment is the honest answer, we will tell you that instead of selling you a pentest.
Talk it through →Why bother with a small shop
The person on the sales call is the person testing.
Big firms staff the pitch with principals and the engagement with whoever is on the bench. That is not a moral failing, it is how utilization works at scale, but you feel it when the report arrives full of template text about a stack nobody looked at closely.
Here you talk to a tester, get tested by that tester, and argue with that tester about severity if you disagree. Which happens, and it is fine.
We also say when something is boring. Inflating a self-signed certificate on an internal jump box into a "high" so the report looks meaty wastes a quarter of your engineering time on nothing; you stop trusting the severities, and then you stop reading the reports.
Tools run in the background because they are good at coverage. The findings that matter come from somebody sitting with your application until the logic gives.
Partnership
CrowdStrike Falcon, deployed by people who attack endpoints.
Most EDR rollouts stall in the same place: the agent is on every host, the policies are still whatever shipped in the box, and nobody has tested whether a detection actually fires. We deploy Falcon, tune it against real techniques, and show you the telemetry from the attempt.
Where we usually start
- Migration off legacy AV without a coverage gap in the middle
- Policy tuning: prevention on, and the exclusions written down with a reason
- Detection validation against the techniques we use on engagements
- Identity Protection and Falcon module rollout beyond the base agent
- Handover runbooks, so your team owns it instead of renting us
Research
We publish what we find.
Some of the work ends up upstream rather than in a client report. It is the same habit either way: check whether the fix closes the path, rather than only the reproducer.
August 31, 2026
Does SOC 2 require a penetration test?
The honest answer is no, and it does not help you much, because the reason people ask is usually a customer contract rather than the framework.
Read it →August 31, 2026
How much does a penetration test cost?
Every vendor dodges this question. The reason is real, but you can still work out roughly what you should be paying, and spot a quote that is wrong.
Read it →Credentials
Certifications held by the team.
Certificates do not find bugs, people do. They are here because procurement asks, and because GXPN and GMOB in particular take a while to earn.
EC-Council
INE / eLearnSecurity
Questions we get asked
What does a penetration test cost?
Price follows the day count, and the day count follows the scope. A single web application with two user roles is a much smaller job than a 400-host internal network, so we quote flat after a short scoping call rather than publishing a number that would be wrong for most people. You will have the figure in writing before anyone touches anything, and it does not move unless you change the scope.
How long does an engagement take?
Most jobs run one to three weeks of active testing, plus a few days for the report. Booking is usually the longer wait; we tend to be scheduling two to four weeks out. If you are up against an audit date, say so on the first call and we will tell you honestly whether we can hit it.
What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment answers "what is wrong here" across everything you own; it is broad, largely tool-driven, and repeatable on a schedule. A penetration test answers "what can someone actually do with it" by chaining those weaknesses together until something breaks. Assessments give you a list. Tests give you a story with proof attached. Compliance frameworks usually want both, at different intervals.
Will testing knock our systems over?
Denial-of-service is excluded by default and we do not run it unless you ask for it in writing. Everything else gets throttled, and fragile hosts get flagged during scoping so we can treat them carefully or leave them out. You get a phone number that reaches a tester, not a ticket queue, for the whole test window.
Can you produce the report our SOC 2 or PCI auditor wants?
Yes. We map findings to the control the assessor is going to ask about, and the report carries the scope, dates, methodology and tester credentials that auditors look for. See compliance readiness for the frameworks we work in.
Do you only work with companies in Miami?
We are based in Miami and we like being close enough to show up for internal and physical work across Miami, Miami-Dade County, Fort Lauderdale and the rest of South Florida. External, web, API, cloud and mobile testing is remote work, so location stops mattering there. Plenty of our engagements are outside the state.
Know what an attacker would reach first.
Tell us what you run and what worries you. We will come back with a scope, a fixed price and the earliest week we can start.