// INDEPENDENT OFFENSIVE SECURITY

DISRUPT. CHALLENGE. SECURE.

Web pentesting and vulnerability research.

VEX OFFENSIVE helps companies find the vulnerabilities in their web applications and APIs. Independent expertise, a manual approach, focused on real-world impact.

Mini challenge

// Round 1 — Recon

Which endpoint would you probe first?

Services

Three areas of expertise, one standard.

Web Pentest

Manual, in-depth application penetration testing.

  • OWASP methodology (WSTG)
  • Web apps & APIs
  • Auth, sessions & access control
  • Business logic & injections
Web Pentest —The method

OSINT

Open-source intelligence on an organisation, brand or individual: gathering and cross-checking public information to inform a decision.

  • Exposure & data leaks
  • Footprint & online reputation
  • Due diligence & background checks
  • Investigation & cross-checking
OSINT —Talk to us

Code Audit

Source-code review for the flaws dynamic testing misses.

  • Manual or AI-assisted review
  • Secrets & risky dependencies
  • Injections & bad patterns
  • Concrete in-code fixes
Code Audit —Talk to us

Methodology

An offensive method,
actionable reporting.

A framed process, from scope to a verified fix. Every engagement builds on industry standards — not an automated scan.

Standards: OWASP WSTG · PTES · CVSS 3.1

  1. Scope

    Scope, goals and rules of engagement are defined with you before any work begins.

    • Scope & rules of engagement
    • Test accounts & environment
    • Confidentiality agreement (NDA)
    • Communication & escalation channel
  2. Test

    Manual testing guided by OWASP WSTG and business logic, backed by tooling. Controlled exploitation, no production impact.

    • Recon & mapping
    • Controlled manual exploitation
    • Vulnerability chaining
    • CVSS 3.1 scoring
  3. Report

    An actionable report: executive summary, reproducible technical detail, prioritised fixes.

    • Executive summary
    • Reproducible proofs of concept
    • Fixes prioritised by severity
    • Debrief with your team

Research

Research & findings.

Write-ups, CVEs, bug bounty findings and tools, from my offensive security work. Vulnerabilities are published in line with responsible disclosure.

// no publications yet

The first publications are coming soon.

Coming soon: my write-ups, bug bounty findings, CVEs and tools around application security.

Discuss an audit

About

Offensive security,
rooted in code.

A full-stack development and cybersecurity engineer, I have worked in development and security for about a decade — first self-taught, then earning a Master’s degree in cybersecurity. My web development background feeds my offensive approach: understanding how an application is built to better find its flaws. I’m also active in bug bounty, which keeps my methods sharp against real production targets.

— Lionel Miceli« Jenova » · Founder & independent pentester

LinkedIn

Aix-Marseille area, France · on-site or remote

Tell us about your project

Certifications

Principles

Manual
Human analysis and controlled exploitation, beyond automated scanners.
Impact
Flaws rated by their exploitability and real consequences for your business.
Transparency
A single point of contact, a clear method, documented results at every step.

Contact

Let’s talk about your scope.

A web app to assess, an API to audit, a vulnerability research need? Describe your project — let’s talk directly about your goals, scope and terms.

Email us directly