YLB Security is an offensive security partner. We break your web apps, APIs, networks and AI systems the way real attackers would — then give you the evidence, fixes and tools to stay ahead of them.
We live in the same intelligence ecosystem
No scanner noise. No checkbox reports. We combine senior manual testing with purpose-built tooling to find what actually matters in your stack.
Web apps, APIs, mobile, network and infrastructure testing with validated, exploit-level evidence — not automated scan dumps.
Learn moreLLM prompt injection, data exfiltration, agentic tool abuse and model-policy testing — mapped to OWASP LLM and MITRE ATLAS.
Learn moreBranguard, PhishAnna, SecPulse and SentriX — offensive tools we built to hunt impostor domains, score suspicious mail, track vendor advisories and probe LLM & MCP security.
See the toolsFour tools that automate the boring, repetitive parts of offensive security so your team focuses on the decisions that matter.
Find every domain that looks like yours before a phishing campaign does. Branguard enumerates hundreds of look-alike domains in one sweep, live-tests each one, and captures screenshots so you can compare an impostor page against your real site side-by-side.
Upload a .eml or paste a raw email record and PhishAnna breaks it down: headers, authentication
results (SPF/DKIM/DMARC), sender reputation, link and attachment analysis, and behavioural red flags —
fused into a single 0–100 risk score.
.eml upload or paste raw email headers/body
One place for the vulnerability information your stack actually runs on. SecPulse aggregates advisories from NVD, Ubuntu, Red Hat, Microsoft, OSV and more, filters them by the tech you bookmarked, and pushes what matters straight to your Slack channel.
send_http1_request exposed — SSRF to cloud metadata confirmed
Automated security assessment for LLM applications and MCP servers. SentriX runs the full OWASP LLM Top 10 attack suite against your chat endpoint and audits MCP servers for tool exposure, prompt injection via tools, auth gaps, data exfiltration and resource abuse — delivering scored reports with evidence and remediation.
Compliance for your AI systems, built for the EU AI Act and ISO/IEC 42001. Inventory every model you ship, classify it against Art. 5 / Art. 6 / Annex III triggers with a stored rationale, run weighted risk assessments with auto-generated mitigations, and track 22 controls — then export one audit-ready report.
We map your attack surface, define rules of engagement and pull open-source intel before touching anything.
Manual, methodology-driven testing with targeted tooling. Every finding is validated and stripped of false positives.
Exploit-level evidence, reproduction steps and business impact — written in a language engineers and executives both read.
We stay after the report to validate every remediation and retest until each finding is closed.
Book a scoping call and we'll map your surface, recommend the right engagement, and show you exactly what your risk looks like.