SensePost
SensePost is an ethical hacking team within Orange Cyberdefense, founded in 2000 in Pretoria, South Africa, providing enterprise penetration testing, vulnerability assessments, conference-based cybersecurity training, and managed security services to global enterprise clients and security professionals.
- Company typePrivate
- Founded2000
- HeadquartersPretoria, South Africa
- Headcount51–100
- GTM typeB2B
- OfferingServices
What SensePost does
SensePost is an ethical hacking consultancy founded in 2000 in Pretoria, South Africa, operating since approximately 2018 as a team within Orange Cyberdefense. The firm provides three core service lines: security assessments (penetration testing and vulnerability assessment for enterprise applications, infrastructure, and networks), hacking training (structured curricula from novice to expert delivered at global security conferences), and managed security services (vulnerability management and threat detection implementation). Its go-to-market is enterprise field sales supported by a research-driven content engine: the company has published technical research continuously on its blog since 2007 and releases proprietary open-source offensive security tools including Mallet (a Netty-based proxy framework for arbitrary protocols), Apostille (certificate chain forgery for pinning bypass), slimjim (network-namespace-based MITM isolation), hostapd-mana and berate_ap (rogue WiFi access point tools), and pipetap (Windows named pipe proxy). SensePost delivers training at Black Hat (22 years), DEF CON, RingZer0, and BSides conferences globally, with course offerings spanning Hands on Hacking Fundamentals, Web Application Hacking, Infrastructure Hacking, Introduction to Red Teaming, and Modern WiFi Hacking.
The business model is professional services and managed services revenue, sold via direct enterprise engagement and conference-based training registration. Pricing is not publicly disclosed. Customer segments are horizontal: enterprise organizations seeking independent security validation, individual security professionals seeking offensive security training, and organizations requiring managed security operations support. As a wholly-owned subsidiary of Orange Cyberdefense (part of Orange Group), SensePost benefits from the parent's global delivery network and enterprise customer base while maintaining its own brand identity, research focus, and conference presence. Headcount is in the 51-100 range, consistent with a boutique specialist team rather than a large-scale MSSP. Revenue, funding history, and customer logos are not publicly disclosed.
SensePost firmographics
Firmographics- Name
- SensePost
- Legal name
- SensePost
- Website
- https://sensepost.com
- Company type
- Private
- Founded year
- 2000
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- SensePost is an ethical hacking team within Orange Cyberdefense, founded in 2000 in Pretoria, South Africa, providing enterprise penetration testing, vulnerability assessments, conference-based cybersecurity training, and managed security services to global enterprise clients and security professionals.
- Ownership category
- akta.pro rank
SensePost industry classification
Industry- Product category
- Penetration Testing and Cybersecurity Consulting Services
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
- akta.pro secondary industry
- Endpoint Security Managed Services (EDR/XDR) (BPAEADAH)
Keywords
Where SensePost is headquartered
LocationHeadquarters
- HQ city
- Pretoria
- HQ country
- South Africa
- HQ region
- Africa
Offices1 record
Markets served
SensePost business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Security Assessments: Senior team-backed security assessment services for businesses, applications, and networks. Provides penetration testing and vulnerability assessment engagements.
- Hacking Training: Cybersecurity skills training with curriculum from novice to expert levels. Training covers developers, managers, penetration testers, and other professionals needing cyber skills. Delivered at conferences and through dedicated courses.
- Managed Services: Managed security services including vulnerability management, threat detection, and other security operations support.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels3 records
SensePost product offering
Product offeringCore offering
SensePost is an ethical hacking consultancy that delivers Security Assessments (penetration testing and security assurance of business applications and networks), Hacking Training (structured cybersecurity skills courses from novice to expert), and Managed Security Services (vulnerability management and threat detection implementation). Backed by a senior team with a 20-year track record, the firm supplements its services with proprietary open-source security tools and a long-running technical research blog.
Product overview
SensePost is an ethical hacking team of Orange Cyberdefense offering a portfolio of cybersecurity services and training. The company provides three core service offerings: Security Assessments (backed by 20+ years of research-lead innovation), Hacking Training (with curriculum from novice to expert levels), and Managed Services (vulnerability management and threat detection). Their training portfolio includes multiple specialized courses including Hands on Hacking Fundamentals, Web Application Hacking, Infrastructure Hacking, Introduction to Red Teaming, and Unplugged; Modern WiFi Hacking. The company also publishes open-source security tools and research through their blog.
Differentiator
Problem solved
Functional benefit
Products and services
- Security Assessments Penetration testing and security assurance engagements for business applications, infrastructure, and networks. Backed by a senior team with 20+ years of research-lead innovation.
- Hacking Training Cybersecurity skills training with curriculum from novice to expert level, covering developers, managers, penetration testers, and others needing offensive and defensive security skills. Delivered as structured courses.
- Managed Security Services Managed security services helping organizations implement or scale vulnerability management, threat detection, and other security operations efforts.
- Hands on Hacking Fundamentals (HHF) Introductory training course covering technical skills and basic concepts required for a foundation in information security, targeting novice-level participants.
- Web Application Hacking Training course focused on web application security testing and exploitation techniques for security professionals and developers.
- Infrastructure Hacking Training course covering infrastructure security testing and penetration testing techniques for network and systems assessments.
- Introduction to Red Teaming Entry-level course covering red team methodologies and techniques for simulating real-world adversarial attacks against organizations.
- Unplugged; Modern WiFi Hacking Advanced WiFi security training covering modern wireless attack techniques, rogue access points, and wireless defenses.
Quantifiable outcome
- Thousands of students trained in offensive and defensive security techniques
Companies that use SensePost
Customer profileSegments3 records
Ideal customer profiles3 records
SensePost technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
SensePost partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Orange CyberdefensecoreSensePost is now a team within Orange Cyberdefense. Their website redirects to orangecyberdefense.com for services. The company operates as part of Orange Cyberdefense's global ethical hacking and security assessment practice.
Scale indicators2 records
Recent moves6 records
Expansion highlights4 records
SensePost competitors and assessment
Company assessmentBroad incumbents
- Trustwave: Large MSSP and security consultancy offering penetration testing alongside managed detection, MDR, and consulting. Broader portfolio than SensePost, but overlapping in pentest and managed services.
- Rapid7: Security analytics and services firm behind Metasploit and a managed services practice. Comparable to SensePost through Metasploit's open-source offensive heritage and managed services overlap.
- Secureworks: Global MSSP with offensive security, MDR, and threat intelligence. Comparable to Orange Cyberdefense/SensePost at the parent-portfolio level, with overlapping managed and assessment services.
Direct peers
- Bishop Fox: Elite US-based offensive security consultancy offering penetration testing, red teaming, and security research. Highly comparable to SensePost in service mix, research-led culture, and senior-practitioner model.
- Offensive Security (OffSec): Creator of the OSCP certification and Kali Linux; deep overlap with SensePost in offensive security training delivery, particularly in the hands-on, practitioner-focused segment.
- NCC Group: Global security consultancy with strong presence in penetration testing, red teaming, and security advisory. Directly competes with SensePost in enterprise offensive security engagements.
- Trail of Bits: Research-driven security firm specializing in application security, code auditing, and cutting-edge offensive research. Closely comparable to SensePost's research-led, niche consultancy model.
- NetSPI: Enterprise-focused penetration testing and attack surface management firm with both services and platform offerings. Overlaps with SensePost in pentest delivery and managed vulnerability services.
Emerging players
- HackerOne: Crowdsourced security testing platform connecting organizations to a researcher community. Represents the platform-based alternative to traditional consultancy-led pentests that SensePost delivers.
- Synack: Crowdsourced penetration testing platform with a curated researcher network. Comparable to SensePost in the elite-pentest segment, but delivered via a tech-enabled platform model rather than direct consultancy.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
SensePost social profiles
Digital presenceSensePost financial estimates
Financial estimateRevenue estimate
Valuation estimate
SensePost leadership team
Management profileNumber of profiles
SensePost funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SensePost M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SensePost
What does SensePost do?
SensePost is an ethical hacking consultancy that delivers Security Assessments (penetration testing and security assurance of business applications and networks), Hacking Training (structured cybersecurity skills courses from novice to expert), and Managed Security Services (vulnerability management and threat detection implementation). Backed by a senior team with a 20-year track record, the firm supplements its services with proprietary open-source security tools and a long-running technical research blog.
Is SensePost a public or private company?
SensePost is a private company. It is classified as corporate owned and is currently operating.
When was SensePost founded?
SensePost was founded in 2000. It employs 51 to 100 people.
Where is SensePost based?
SensePost is headquartered in Pretoria, South Africa, in the Africa region.
How does SensePost make money?
Three revenue lines are on record. Security Assessments are the primary driver. The others are hacking Training and managed Services.
Who are SensePost's main competitors?
Broad incumbents on record are Trustwave, Rapid7 and Secureworks. Direct peers are Bishop Fox, Offensive Security (OffSec), NCC Group, Trail of Bits and NetSPI. Emerging players are HackerOne and Synack.
Does SensePost have an API?
No public API is recorded for SensePost.
What industry is SensePost in?
SensePost's product category is Penetration Testing and Cybersecurity Consulting Services. Its primary akta.pro industry code is EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking, with a secondary code of BPAEADAH, Endpoint Security Managed Services (EDR/XDR). Its NAICS code is 54151 and its SIC code is 7370.