Web Pentest
Manual, in-depth application penetration testing.
- OWASP methodology (WSTG)
- Web apps & APIs
- Auth, sessions & access control
- Business logic & injections
// INDEPENDENT OFFENSIVE SECURITY
DISRUPT. CHALLENGE. SECURE.
VEX OFFENSIVE helps companies find the vulnerabilities in their web applications and APIs. Independent expertise, a manual approach, focused on real-world impact.
// Round 1 — Recon
Which endpoint would you probe first?
Find the most exposed entry point.
Services
Manual, in-depth application penetration testing.
Open-source intelligence on an organisation, brand or individual: gathering and cross-checking public information to inform a decision.
Source-code review for the flaws dynamic testing misses.
Methodology
A framed process, from scope to a verified fix. Every engagement builds on industry standards — not an automated scan.
Standards: OWASP WSTG · PTES · CVSS 3.1
Scope, goals and rules of engagement are defined with you before any work begins.
Manual testing guided by OWASP WSTG and business logic, backed by tooling. Controlled exploitation, no production impact.
An actionable report: executive summary, reproducible technical detail, prioritised fixes.
Research
Write-ups, CVEs, bug bounty findings and tools, from my offensive security work. Vulnerabilities are published in line with responsible disclosure.
// no publications yet
The first publications are coming soon.
Coming soon: my write-ups, bug bounty findings, CVEs and tools around application security.
Discuss an auditAbout
A full-stack development and cybersecurity engineer, I have worked in development and security for about a decade — first self-taught, then earning a Master’s degree in cybersecurity. My web development background feeds my offensive approach: understanding how an application is built to better find its flaws. I’m also active in bug bounty, which keeps my methods sharp against real production targets.
— Lionel Miceli« Jenova » · Founder & independent pentester
LinkedInAix-Marseille area, France · on-site or remote
Tell us about your projectContact
A web app to assess, an API to audit, a vulnerability research need? Describe your project — let’s talk directly about your goals, scope and terms.
Email us directly
contact@vexoffensive.com