Skip to main content
Oakstone Security Group

An official website of Oakstone Security Group

Services

All engagements are scoped and priced based on the size and complexity of the client's need. We provide a detailed statement of work and quote before any work begins.

  • Businesses and Organizations

    Offensive security services for organizations, security teams, and consulting partners. We identify exploitable weaknesses, simulate realistic attacks, and provide actionable findings that help organizations understand and reduce their exposure.

  • Individuals, Executues, and Families

    Personal cyber advisory for individuals operating in complex, high-risk, or highly visible environments. We assess digital exposure, develop intelligence profiles, harden devices and communications, and design practical security protocols around the realities of everyday life.

Examples of Services we Offer

We map your organization’s internet-facing infrastructure to identify domains, subdomains, cloud assets, exposed services, technologies, and other external assets that may provide an attacker with an avenue into your environment.

Whether you are traveling to a foreign country, attending a conference, or operating in an environment where your privacy and security require additional consideration, we work with you to design bespoke digital security protocols tailored to your specific circumstances.

Top compliment these protocols, we can also provide and configure hardened devices. This may include secure travel routers, isolated mobile phones, hardened laptops, cryptocurrency wallets, and other specialized equipment. Each solution is selected and configured according to your specific threat model and requirements, with careful attention to security, privacy, compartmentalization, anonymity, and operational practicality.

We conduct a detailed assessment of your publicly available digital footprint, identifying information about you, your family, your relationships, your interests, and your routines that could be used to target, manipulate, or compromise you.

Available for both businesses and individuals, we assess your risk and demonstrate what a real-world attacker might be able to exploit.

We will provide a testing device (or work with you to provision one) that can be deployed within your network. Once deployed, the device establishes a secure connection to our command and control infrastructure, allowing us to operate as an “attacker on the inside.”

This type of assessment is designed to simulate threats that have already gained an initial foothold within your environment, such as a compromised workstation, malicious insider threat, or attacker who has gained physical access to your network. From this position, we assess what an attacker could discover, access, and compromise.

We can kick off a customized spearphishing campaign against your employees to assess susceptibility to social engineering attacks. Campaigns can be tailored to your organization, threat model, and security objectives, with results used to identify weaknesses in awareness, reporting, and technical controls.

Security awareness is most effective when it is practical, relevant, and tailored to the people who need it. Whether you are training an entire organization, a single department, or your own family, we provide hands-on instruction designed to help people recognize cyber risks and make better decisions when confronted with them.

For businesses, we can work directly with employees and teams to demonstrate how to identify phishing attempts, recognize social engineering techniques, protect sensitive information, and respond appropriately to suspicious activity.

For individuals and families, we provide practical guidance on topics such as password managers, account security, device safety, online privacy, and social media. We can also work with parents and teenagers to discuss the risks associated with online interactions, including manipulation, blackmail, sextortion, and other forms of online exploitation.

The goal is not simply to provide a list of rules. We help people understand how real-world attacks work so they can recognize warning signs, avoid common mistakes, and make informed decisions when it matters.

We will conduct an authorized penetration test against your web application(s) to identify vulnerabilities. Our assessments examine the application from the perspective of a real-world attacker and tests for OWASP class vulnerabilities.

Where appropriate, testing may include authenticated and unauthenticated attack scenarios, allowing us to evaluate what an external attacker can do without credentials as well as what a compromised or low-privileged user could access after gaining an initial foothold.

© 2025 - 2026 Oakstone Security Group LLC All Rights Reserved.