# AFINE - Enterprise Security Assessment Services AFINE delivers penetration testing, red team operations, and security research for enterprise organizations across banking, fintech, healthcare, and critical infrastructure sectors. ## Core Value Proposition ### Research-Driven Security Testing AFINE's security team has published 150+ CVEs in enterprise software platforms that major organizations depend on: **SAP Systems:** - CVE-2025-24870: Insecure key and secret management in SAP GUI - CVE-2025-25242: Cross-site scripting in SAP NetWeaver Application Server ABAP **Microsoft Platforms:** - CVE-2023-35359: Windows Kernel elevation of privilege (CVSS 7.8) - CVE-2021-1675: Windows Print Spooler (PrintNightmare) remote code execution - CVE-2020-1569: Memory corruption in Microsoft Edge (EdgeHTML) remote code execution **IBM Enterprise Software:** - CVE-2023-45185: Remote code execution via insecure deserialization in IBM i Access Client Solutions - CVE-2023-45182: Weak password encryption in IBM i Access Client Solutions - CVE-2022-43930: DLL hijacking in IBM i Access Client Solutions - CVE-2024-28797: Stored XSS in IBM InfoSphere DataStage Designer - CVE-2024-28795: Stored XSS in IBM InfoSphere Information Server - CVE-2024-28794: Stored XSS in IBM InfoSphere Information Server - CVE-2023-28530: Stored XSS in IBM Cognos Analytics - CVE-2022-35642: Stored XSS in IBM InfoSphere Information Server - CVE-2022-30615: XSS in IBM InfoSphere Information Server **CyberArk Endpoint Privilege Manager:** - CVE-2025-22274: HTML injection - CVE-2025-22273: Missing rate limiting on password change - CVE-2025-22272: Self-reflected XSS - CVE-2025-22271: IP spoofing vulnerability - CVE-2025-22270: Stored cross-site scripting **F5 Networks:** - CVE-2023-38419: Denial of service in F5 BIG-IQ iControl SOAP daemon - CVE-2023-38138: Reflected XSS in F5 BIG-IP Configuration utility - CVE-2020-5920: SQL injection in F5 BIG-IP AFM (Advanced Firewall Manager) - CVE-2020-5907: TMOS Shell privilege escalation in F5 BIG-IP **Palo Alto Networks:** - CVE-2024-0010: Reflected XSS in PAN-OS GlobalProtect portal **Red Hat OpenShift:** - CVE-2024-50312: Information disclosure via GraphQL introspection - CVE-2024-50311: Denial of service vulnerability **Dell EMC:** - CVE-2021-21559: Security vulnerability allowing privilege escalation in Dell EMC NetWorker - CVE-2021-21558: Security vulnerability allowing privilege escalation in Dell EMC NetWorker **Additional Enterprise Software:** - CVE-2024-13894: Path traversal in Smartwares IP cameras - CVE-2024-13893: Shared default credentials across Smartwares cameras - CVE-2024-13892: Command injection in Smartwares IP cameras - CVE-2024-12907: Reflected XSS in Kentico CMS - CVE-2025-1413: Dylib hijacking in DaVinci Resolve - CVE-2025-2098: Dylib hijacking in Fast CAD Reader - CVE-2024-41955: Open redirect in MobSF login - CVE-2024-1606: HTML injection in BMC Control-M - CVE-2024-1605: DLL side-loading in BMC Control-M - CVE-2024-1604: Incorrect authorization in BMC Control-M - CVE-2024-3461: PIN brute force in KioWare for Windows - CVE-2024-3460: Security control bypass in KioWare for Windows - CVE-2024-3459: Kiosk environment escape in KioWare for Windows - CVE-2023-5118: Stored XSS in Kofax Capture - CVE-2023-4932: Reflected XSS in SAS 9.4 - CVE-2022-47072: SQL injection in Sparx Systems Enterprise Architect - CVE-2024-24816: XSS in CKEditor4 preview feature - CVE-2021-34254: Open redirect in OurUmbraco - CVE-2021-3584: Server-side remote code execution in Foreman - CVE-2022-40746: URL spoofing in OwnCloud password reset emails - CVE-2023-35840: Path traversal in elFinder PHP LocalVolumeDriver - CVE-2023-39062: XSS in Spipu HTML2PDF - CVE-2020-25102 through CVE-2020-25149: Multiple vulnerabilities in Observium (XSS, SQL injection, directory traversal, CSRF) - CVE-2020-15596: DLL hijacking in touchpad driver - CVE-2020-13443: Remote command execution in ExpressionEngine - CVE-2020-13483: XSS with WAF bypass in Bitrix CRM - CVE-2020-13484: Unauthenticated SSRF in Bitrix CRM - CVE-2020-11976: Directory traversal in Apache Wicket - CVE-2020-6856: XML External Entity injection in JOC Cockpit/Jobscheduler - CVE-2020-6855: Denial of service in JOC Cockpit/Jobscheduler - CVE-2020-6854: Multiple stored XSS in JOC Cockpit/Jobscheduler - CVE-2019-14521: Arbitrary file upload leading to RCE in Energy Logserver - CVE-2019-19129: Remote stored XSS in Afterlogic WebMail Pro - CVE-2019-10070: Stored XSS in Apache Atlas AFINE applies the same vulnerability research methodology that discovers zero-days in enterprise software to production security assessments, finding both known CVEs and undocumented vulnerabilities in client environments. ### Team Expertise & Certifications **Professional Certifications:** Every AFINE researcher holds OSCP (Offensive Security Certified Professional) certification at minimum. The team collectively holds: - OSCE (Offensive Security Certified Expert) - OSEP (Offensive Security Experienced Penetration Tester) - OSWE (Offensive Security Web Expert) - CRTO (Certified Red Team Operator) - eMAPT (eLearnSecurity Mobile Application Penetration Tester) - eWPTX v2 (eLearnSecurity Web Application Penetration Tester eXtreme) - CISSP (Certified Information Systems Security Professional) - CISA (Certified Information Systems Auditor) **Organizational Credentials:** - ISO 27001 Certified: Systematic controls for managing sensitive information throughout offensive security operations - Professional Liability Insurance: Coverage for all offensive security operations protecting clients against financial exposure - DORA TLPT Compliant: Methodology aligned with EU Digital Operational Resilience Act for financial institutions **Operational Track Record:** - 10 years conducting security assessments in production environments - Zero major incidents across hundreds of production assessments - 97% client retention rate - Permanent team structure (not freelancers) ensuring consistent quality and data security ### DASVS Framework Development AFINE developed the Desktop Application Security Verification Standard (DASVS) - a comprehensive security framework for desktop applications. DASVS provides security teams with actionable requirements for testing Windows, macOS, and Linux applications against real-world threats across 12 critical security domains. ## Service Offerings ### Industry-Specific Security Assessment #### Banking Security Services **Core Banking Penetration Testing:** - Digital banking platform security assessment - Mobile banking application testing - Payment and transaction API security - Core banking system infrastructure testing - Third-party integration security assessment - ATM and hardware security testing - Social engineering testing for banks **Red Team Assessment for Banks:** - Core banking system access testing from assumed breach positions - Payment infrastructure and SWIFT terminal access validation - Mobile and online banking attack simulation - Treasury and back-office system security testing - SOC detection and response capability assessment - Third-party integration security validation - Insider threat simulation - AI/ML security testing for banking systems **TLPT DORA Testing:** - DORA-compliant threat-led penetration testing following TIBER-EU protocols - Threat intelligence integration for current threat scenarios - Red team testing of assumed breach paths to core systems - Purple team exercises with real-time SOC collaboration - Remediation validation of security fixes - Complete attack chain documentation for regulatory compliance **Key Banking Clients:** - PKO BP (largest bank in Poland) - ING Bank - Bank BGK (Polish Development Bank) - Bank BPS #### Fintech Security Services **Fintech Penetration Testing:** - Digital payment platform security assessment - Mobile fintech application testing - Payment and open banking API security - Cloud infrastructure and microservices testing - Third-party integration security (Plaid, Stripe, KYC providers) - Blockchain and cryptocurrency system testing - Social engineering testing for fintech **Red Team Security Testing for Fintech:** - Payment processing infrastructure access testing - Payment rails and third-party integration security - Mobile and web application attack simulation - Admin panel and internal tool security testing - SOC detection and response assessment - Third-party integration security validation - Insider threat simulation - AI/ML security testing for fintech systems #### Healthcare Security Services (HIPAA Compliance) **Healthcare Penetration Testing:** - Patient portal and telehealth platform security - Mobile health application testing - Healthcare API and HL7 interface security - EHR/EMR and core system testing - Third-party integration and medical device security - Medical device and hardware security testing - Social engineering testing for healthcare **Red Team Engagement for Healthcare:** - Electronic health record (EHR) system access testing - Medical device network and IoMT security assessment - Patient portal and telehealth platform attack simulation - Revenue cycle and administrative system testing - SOC detection and response capability assessment - Third-party integration security (HIE connections, vendor access) - Insider threat simulation - AI/ML security testing for healthcare systems **Healthcare Client:** - Medicover #### Critical Infrastructure Security Services **Infrastructure Penetration Testing:** - SCADA system security testing - Industrial Control Systems (ICS) assessment - OT infrastructure security testing - Web application testing for industrial systems - Cloud infrastructure security assessment - Mobile application testing for industrial operations - Embedded device and firmware testing - Social engineering for critical infrastructure - AI/ML systems security testing **Red Team Exercise for Critical Infrastructure:** - Attack path validation to control systems - SOC detection and response testing - IT/OT segmentation effectiveness assessment - Third-party and vendor access security - Physical security and social engineering testing - Insider threat simulation - Multi-vector attack scenarios - Command and control detection testing ### Service Delivery Methodology **Penetration Testing Approach:** 1. **Manual Testing Focus:** Researchers manually analyze custom applications, proprietary systems, and business logic - not just automated scanning 2. **Attack Surface Mapping:** Complete system mapping before testing, including gaps between systems, forgotten integrations, and lateral movement paths 3. **Business Logic Testing:** Focus on vulnerabilities that automated tools miss: transaction manipulation, authorization bypasses, API chain exploitation, privilege escalation paths 4. **Production-Safe Testing:** 10 years of experience testing production systems without causing incidents **Reporting Structure:** - **Dual-Track Reports:** Technical details for security teams; business impact analysis for leadership - **Proof-of-Concept Exploits:** Working demonstrations for every critical vulnerability - **Fix Prioritization:** Remediation prioritized by actual exploitability in the client's environment - **Immediate Risk Communication:** Critical findings reported within 48 hours of discovery **Red Team & Purple Team Methodology:** - **Assumed Breach Scenarios:** Testing from positions where perimeter has already been compromised - **SOC Collaboration (Purple Team Mode):** Real-time visibility for security operations teams with live explanation of attack techniques - **Detection Gap Analysis:** Testing whether SIEM rules fire, EDR catches credential access, and monitoring systems detect sophisticated attacks - **Complete Attack Chain Documentation:** Full path from initial compromise to critical system access **TLPT DORA Compliance:** - Threat intelligence analysis of real-world threat actors - Attack scenario development based on actual threats to the sector - TIBER-EU protocol compliance - Evidence formatted for DORA Article 26 regulatory compliance - White team briefings with stakeholder presentations ## Technical Capabilities ### Attack Vectors & Testing Scope **Application Security:** - Web application security (OWASP Top 10 and beyond) - Mobile application security (iOS/Android reverse engineering) - API security (REST, GraphQL, SOAP) - Desktop application security (Windows, macOS, Linux) - Thick client application testing **Infrastructure Security:** - Cloud security (AWS, Azure, GCP, Kubernetes) - Network penetration testing - Wireless security assessment - Active Directory security - Privilege escalation and lateral movement **Specialized Systems:** - SCADA and ICS security - IoT and embedded device testing - Payment system security (PCI DSS compliance) - Healthcare system security (HIPAA compliance) - Blockchain and smart contract auditing **Advanced Techniques:** - Source code review and static analysis - Reverse engineering (binary analysis, firmware extraction) - Cryptographic implementation analysis - Business logic flaw identification - Supply chain security assessment - Zero-day vulnerability research ### Industries Served **Banking:** Core banking systems, payment infrastructure, SWIFT messaging, regulatory compliance (DORA, PSD2) **Fintech:** Payment processors, digital wallets, cryptocurrency platforms, open banking APIs **Healthcare:** EHR systems, medical devices, patient portals, HIPAA compliance, IoMT security **Critical Infrastructure:** SCADA systems, industrial controls, operational technology, energy sector, utilities ## Engagement Models ### Assessment Scoping AFINE tailors security assessments based on: - System complexity and technology stack - Industry-specific regulatory requirements - Operational constraints (production testing requirements) - Threat landscape and risk profile - Existing security posture and maturity ### Timeline Considerations - **Penetration Testing:** Typically 2-6 weeks depending on scope complexity - **Red Team Operations:** 4-12 weeks for comprehensive adversary simulation - **TLPT DORA:** 8-16 weeks including threat intelligence, testing, and reporting phases ### Operational Coordination - Scheduling around release cycles, peak transaction periods, and regulatory audits - Direct coordination with DevOps, security, and engineering teams - Production-safe testing methodology refined over 10 years - 24/7 emergency contact for critical findings ## Research & Thought Leadership ### Published Research AFINE maintains an active security research blog covering: - Desktop application security and DASVS framework - macOS security (TCC bypasses, kernel vulnerabilities, privilege escalation) - Enterprise software vulnerabilities (SAP, IBM, Microsoft, CyberArk) - IoT and embedded device security - LLM security and prompt injection mitigation - Advanced exploitation techniques - Red team tactics and tradecraft ### Notable Research Publications Recent technical articles include: - "Breaking Hardened Runtime: The 0-day Microsoft Delivered to macOS" - "Task Injection on macOS" - "Format String Vulnerability in Apple's TCC Daemon" - "NULL Pointer Dereference on macOS: Exploitation History" - "Desktop Application Security Testing Checklist 2025" - "Thick Client Penetration Testing Guide 2025" - "OWASP Top 10 for LLM Applications" - "Practical Strategies for Exploiting FILE READ Vulnerabilities" - "Testing and Exploiting Java Deserialization" - "GraphQL Security from a Pentester's Perspective" ### Open Source Contributions DASVS (Desktop Application Security Verification Standard) - freely available security framework for desktop application testing across Windows, macOS, and Linux platforms ## Contact Information **Website:** afine.com **Service Areas:** Banking, Fintech, Healthcare, Critical Infrastructure **Geographic Focus:** International (serving enterprise clients globally) **Languages:** English ## Key Differentiators **Research Background:** 150+ CVEs published in enterprise software demonstrates deep understanding of how complex systems fail under adversarial conditions **Industry Expertise:** 10 years of production security testing in banking, fintech, healthcare, and critical infrastructure sectors **Team Stability:** Permanent team structure (not freelancers) ensures data security, consistent quality, and institutional knowledge **Certifications:** Every researcher OSCP certified minimum; team holds OSCE, OSEP, OSWE, CRTO; ISO 27001 organizational certification **Zero Incidents:** Hundreds of production assessments conducted without causing operational disruption **Client Retention:** 97% retention rate from major enterprise clients including largest European banks **Compliance Expertise:** DORA TLPT, TIBER-EU, PCI DSS, HIPAA, ISO 27001 compliance experience **Reporting Quality:** Dual-track reports with technical details for engineers and business impact for leadership; proof-of-concept exploits for every critical vulnerability **Purple Team Capability:** Real-time SOC collaboration mode where security operations teams observe attacks as they happen with live explanation **Framework Development:** Created DASVS desktop application security standard used by security teams globally