RedTeam Pentesting
RedTeam Pentesting is a German boutique firm in Aachen that provides customized penetration testing services for enterprise and cloud provider clients. It operates with permanent staff only, no subcontractors, and complements services with original CVE research and open-source offensive security tools.
- Company typePrivate
- Founded2004
- HeadquartersAachen, Germany
- Headcount1–10
- GTM typeB2B
- OfferingServices
What RedTeam Pentesting does
RedTeam Pentesting is a German boutique penetration testing firm headquartered in Aachen, founded around 2004, and legally organized as RedTeam Pentesting GmbH (HRB 14004). The company is represented by founders and managing directors Patrick Hof and Jens Liebchen. It operates exclusively in the penetration testing services market, deliberately not bundling testing with broader IT security or managed services, and serves enterprise organizations and cloud service providers that require independent, third-party security assessments of their networks, web applications, and IT infrastructure.
The firm's core product is customized penetration testing engagements executed by small, co-located specialist teams. Its technology footprint is a combination of proprietary testing methodologies for Active Directory, Windows domain, and web application security, plus a portfolio of open-source offensive security tools published on GitHub: pretender (cross-platform MITM/relay attack tool for Windows networks), monsoon (HTTP enumerator), resocks (encrypted SOCKS proxy for pivoting), and wspcoerce (Windows Search Protocol authentication coercion tool). The firm also produces original vulnerability research, including CVE-2025-33073 (Reflective Kerberos Relay Attack, advisory rt-sa-2025-002) and CVE-2025-27892 (Shopware Security Plugin SQL injection, advisory rt-sa-2025-001), and publishes advisories, blog posts, whitepapers, and conference talks (e.g., DFN, hack.lu). All employees are permanent staff, with no use of subcontractors or freelancers even at peak load, which the firm positions as a quality and confidentiality differentiator.
Commercially, RedTeam Pentesting runs a sales-led, B2B direct engagement model. Customers initiate contact via the website contact form, email, or phone, followed by a preliminary scoping meeting, a defined-scope pentest over an agreed period, and a final personal presentation of findings with live demonstrations and a detailed report. Pricing is not publicly disclosed and is quote-based per engagement. The firm markets through technical content (blog, advisories, whitepapers, conference talks), open-source tooling as community/developer relations, and broad social media presence (X, Mastodon, Bluesky, LinkedIn, Reddit, GitHub). It currently serves Germany and Europe, has 1-10 employees, and is owner-operated with no external funding, no M&A history, and no disclosed parent company.
RedTeam Pentesting firmographics
Firmographics- Name
- RedTeam Pentesting
- Legal name
- RedTeam Pentesting GmbH
- Website
- https://redteam-pentesting.de
- Company type
- Private
- Founded year
- 2004
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- RedTeam Pentesting is a German boutique firm in Aachen that provides customized penetration testing services for enterprise and cloud provider clients. It operates with permanent staff only, no subcontractors, and complements services with original CVE research and open-source offensive security tools.
- Ownership category
- akta.pro rank
RedTeam Pentesting industry classification
Industry- Product category
- Cybersecurity Penetration Testing Services
- NAICS
- Testing Laboratories and Services (541380)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKAHAF)
- akta.pro secondary industries
- Penetration Testing & Red Teaming (BPAKADAE), Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where RedTeam Pentesting is headquartered
LocationHeadquarters
- HQ city
- Aachen
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
RedTeam Pentesting business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Infrastructure
Revenue model
- Penetration Testing Services: Customized penetration testing engagements for networks, applications, and devices. Revenue generated through project-based professional services with defined scope, timeline, and deliverables including detailed reports and personal presentations.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels11 records
RedTeam Pentesting product offering
Product offeringCore offering
RedTeam Pentesting GmbH is a German penetration testing firm that delivers customized security assessments of IT networks, applications, and devices for enterprise clients. Its teams of permanent staff specialists conduct bespoke penetration tests culminating in detailed reports and in-person presentations with live demonstrations of discovered vulnerabilities. Beyond its service work, the company also releases open-source security tools and publishes security advisories derived from engagement findings.
Product overview
RedTeam Pentesting is a German penetration testing company that provides specialized security testing services. Their portfolio consists of a core penetration testing service accompanied by open-source security tools: wspcoerce (Windows authentication coercion), pretender (MiTM/relay attack tool), monsoon (HTTP enumerator), and resocks (SOCKS proxy). They also publish security advisories documenting vulnerabilities discovered during engagements. The company operates exclusively as a service provider without a SaaS platform or product suite.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing Services
Quantifiable outcome
- Identification of security vulnerabilities that organizations would never have thought of, creating awareness and insight into attacker methodologies
Companies that use RedTeam Pentesting
Customer profileNamed customers2 records
Segments2 records
Ideal customer profiles2 records
RedTeam Pentesting technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
RedTeam Pentesting partnerships and signals
Strategic signalRecent moves6 records
Expansion highlights4 records
RedTeam Pentesting competitors and assessment
Company assessmentDirect peers
- Syss GmbH: Syss is a German penetration testing firm with a long-standing reputation for bespoke red team and application testing work. It is comparable as a DACH-focused, custom pen-test specialist serving similar enterprise buyers.
- Cure53: Cure53 is a Berlin-based independent penetration testing boutique with a similar pure-play, research-driven model, publishing CVEs and security advisories. It directly competes with RedTeam Pentesting for DACH enterprise and OSS-tooling mindshare.
- Trail of Bits: Trail of Bits is a US-based security research and consulting firm that publishes advisories and open-source security tools. It is comparable as a research-driven, high-end boutique competitor for sophisticated enterprise testing work.
- Secarma: Secarma is a UK-based independent penetration testing firm focused on bespoke enterprise engagements. Comparable to RedTeam in service model and target customer profile.
- ERNW Enno Rey Netzwerke: ERNW is a Heidelberg-based independent security consultancy specializing in network and Active Directory security assessments, technical research publications, and community engagement. It overlaps heavily with RedTeam's AD/Windows-domain testing niche.
- Bishop Fox: Bishop Fox is a US-based independent penetration testing and red team firm with a strong research and open-source tooling culture (e.g., Sliver). Comparable to RedTeam in its boutique, research-led approach and similar enterprise target segments.
Broad incumbents
- NCC Group: NCC Group is a large global cybersecurity services firm with a substantial dedicated penetration testing practice. It competes for the same enterprise buyers as RedTeam, but at much larger scale and with broader service offerings.
- Orange Cyberdefense: Orange Cyberdefense is the cybersecurity arm of Orange Business with a significant MSSP and security testing portfolio across Europe. It competes with RedTeam for enterprise pentest mandates, but with much broader offerings and geographic reach.
Emerging players
- HackerOne: HackerOne operates a bug bounty and vulnerability disclosure platform, representing an alternative, productized model for buyers seeking external testing. It is comparable as a competitor for testing budgets, though via crowdsourced rather than boutique engagements.
Others
- PortSwigger (Burp Suite): PortSwigger is the maker of Burp Suite and provides web application security research and training. While not a direct pen-test services competitor, it shares RedTeam's web-application testing and research-publishing culture and shapes the tooling ecosystem RedTeam operates in.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks6 records
Key highlights7 records
Customer concentration
RedTeam Pentesting social profiles
Digital presenceRedTeam Pentesting financial estimates
Financial estimateRevenue estimate
Valuation estimate
RedTeam Pentesting leadership team
Management profileNumber of profiles
Profiles2 records
RedTeam Pentesting funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
RedTeam Pentesting M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about RedTeam Pentesting
What does RedTeam Pentesting do?
RedTeam Pentesting GmbH is a German penetration testing firm that delivers customized security assessments of IT networks, applications, and devices for enterprise clients. Its teams of permanent staff specialists conduct bespoke penetration tests culminating in detailed reports and in-person presentations with live demonstrations of discovered vulnerabilities. Beyond its service work, the company also releases open-source security tools and publishes security advisories derived from engagement findings.
Is RedTeam Pentesting a public or private company?
RedTeam Pentesting is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was RedTeam Pentesting founded?
RedTeam Pentesting was founded in 2004. It employs 1 to 10 people.
Where is RedTeam Pentesting based?
RedTeam Pentesting is headquartered in Aachen, Germany, in the Europe region.
How does RedTeam Pentesting make money?
One revenue line is on record: penetration Testing Services.
Who are RedTeam Pentesting's main competitors?
Direct peers on record are Syss GmbH, Cure53, Trail of Bits, Secarma, ERNW Enno Rey Netzwerke and Bishop Fox. Broad incumbents are NCC Group and Orange Cyberdefense. HackerOne is listed as an emerging player. PortSwigger (Burp Suite) is listed as an others.
Does RedTeam Pentesting have an API?
No public API is recorded for RedTeam Pentesting.
What industry is RedTeam Pentesting in?
RedTeam Pentesting's product category is Cybersecurity Penetration Testing Services. Its primary akta.pro industry code is BPAKAHAF, Penetration Testing & Red Teaming, with a secondary code of BPAKADAE, Penetration Testing & Red Teaming. Its NAICS code is 541380.