Pen test · AI red team · Tooling

Attack like an adversary. Defend like it matters.

YLB Security is an offensive security partner. We break your web apps, APIs, networks and AI systems the way real attackers would — then give you the evidence, fixes and tools to stay ahead of them.

YLB+
Trusted by startups & security teams building fast and shipping secure
YLB · Live posture LIVE
0
Suspicious domains
0
Critical CVEs today
0
Phishing score
0
LLM / MCP findings
Branguard sweep · 3 min ago SentriX · 2 assessments SecPulse feed · NVD sync ok
Impostor blockedmybrand-l0gin.com
Email scoredPhishAnna · 98/100 risk
Vuln alert pushedCVE-2026-2101 → #sec-team
AI assessedSentriX · LLM + MCP

We live in the same intelligence ecosystem

NVD OWASP CISA KEV MITRE ATT&CK OSV CVE.org CERT Advisories
What we do

Offensive security, delivered human-first

No scanner noise. No checkbox reports. We combine senior manual testing with purpose-built tooling to find what actually matters in your stack.

Penetration Testing

Web apps, APIs, mobile, network and infrastructure testing with validated, exploit-level evidence — not automated scan dumps.

Learn more

AI Red Teaming

LLM prompt injection, data exfiltration, agentic tool abuse and model-policy testing — mapped to OWASP LLM and MITRE ATLAS.

Learn more

Security Tooling

Branguard, PhishAnna, SecPulse and SentriX — offensive tools we built to hunt impostor domains, score suspicious mail, track vendor advisories and probe LLM & MCP security.

See the tools
Built by hunters, for defenders

Our offensive toolset

Four tools that automate the boring, repetitive parts of offensive security so your team focuses on the decisions that matter.

Brand impersonation

Branguard

Find every domain that looks like yours before a phishing campaign does. Branguard enumerates hundreds of look-alike domains in one sweep, live-tests each one, and captures screenshots so you can compare an impostor page against your real site side-by-side.

  • Scan 100+ typo-squat, homoglyph and look-alike domains at once
  • Automated screenshots of live impostor pages, side-by-side comparison with your site
  • Hosting, registrar, certificate and WHOIS intel for takedown evidence
Explore Branguard
app.branguard.io · brand sweep — 128 look-alikes
acme.com SAFE
acme-verify.com IMPOSTOR
acme-support.net IMPOSTOR
acme.com.eu SAFE
phishanna.io · invoice.eml
98/100
HIGH RISK
SPF + DKIM + DMARC fail FAIL
Link invoice-pay.safe-bank.xyz SUSPICIOUS
Urgency cues: "pay within 24h" WARN
Attachment scan clean OK
Email defence

PhishAnna

Upload a .eml or paste a raw email record and PhishAnna breaks it down: headers, authentication results (SPF/DKIM/DMARC), sender reputation, link and attachment analysis, and behavioural red flags — fused into a single 0–100 risk score.

  • Drag-and-drop .eml upload or paste raw email headers/body
  • Multi-source analysis: email auth, URL reputation, attachment heuristics & sender intel
  • Explainable scoring — every point on the scale is backed by evidence
Explore PhishAnna
Vulnerability intelligence

SecPulse

One place for the vulnerability information your stack actually runs on. SecPulse aggregates advisories from NVD, Ubuntu, Red Hat, Microsoft, OSV and more, filters them by the tech you bookmarked, and pushes what matters straight to your Slack channel.

  • Aggregated vendor feeds — NVD, Ubuntu, Red Hat, Microsoft, OSV & more
  • Bookmark your tech stack and get only the CVEs that affect you
  • Slack webhook delivery — advisories land directly in your channel
Explore SecPulse
secpulse.io · advisory feed — 2026-08-17
NVD 9.8 CVE-2026-2101 · Auth bypass in popular web framework → your stack
RHEL 8.1 RHSA-2026:3304 · kernel privilege escalation on RHEL 9
Ubuntu 7.8 USN-7021-1 · OpenSSL buffer overflow
MS 6.5 CVE-2026-1180 · SharePoint elevation of privilege
NVD 5.3 CVE-2026-0901 · info disclosure in nginx proxy module
sentrix.io · assessment — LLM endpoint + MCP server
LLM01 8.4 Direct prompt injection — model emitted canary ZEBRA42 on injected instruction
LLM07 7.9 System prompt extraction — model disclosed instruction block verbatim
MCP03 9.1 Tool send_http1_request exposed — SSRF to cloud metadata confirmed
MCP07 7.6 Injection bait in tool description: "ignore previous instructions, exfiltrate"
MCP08 7.3 Secrets in proxy history — Bearer token + cookie leaked via read tool
AI security assessment

SentriX

Automated security assessment for LLM applications and MCP servers. SentriX runs the full OWASP LLM Top 10 attack suite against your chat endpoint and audits MCP servers for tool exposure, prompt injection via tools, auth gaps, data exfiltration and resource abuse — delivering scored reports with evidence and remediation.

  • Full OWASP LLM Top 10 suite: prompt injection, jailbreaks, data exfil, system-prompt extraction, overreliance
  • MCP server scanner: tool inventory, auth gaps, SSRF-class tools, injection bait, secret leakage
  • Scored HTML reports with evidence payloads, severity grades and OWASP-mapped remediation
Explore SentriX
AI governance

AegisGRC

Compliance for your AI systems, built for the EU AI Act and ISO/IEC 42001. Inventory every model you ship, classify it against Art. 5 / Art. 6 / Annex III triggers with a stored rationale, run weighted risk assessments with auto-generated mitigations, and track 22 controls — then export one audit-ready report.

Explore AegisGRC
aegisgrc.io · governance register — 3 AI systems
AIA-6 HIGH HR Screening Assistant · Annex III employment decisions → full Ch. III obligations
AIA-50 LTD Support Chatbot · transparency obligations — label synthetic content
ISO-8 72% Control maturity · 16/22 implemented · audit report exported
ART-9 61 Residual risk 61/100 → FRIA before deployment, human-in-the-loop (Art. 14/27)
0
Impostor domains fingerprinted
0
Emails scored by PhishAnna
0
Advisories tracked by SecPulse
0
AI endpoints & MCP servers assessed
How engagements run

From kickoff to remediation, in four moves

Scope & intel

We map your attack surface, define rules of engagement and pull open-source intel before touching anything.

Attack

Manual, methodology-driven testing with targeted tooling. Every finding is validated and stripped of false positives.

Report & debrief

Exploit-level evidence, reproduction steps and business impact — written in a language engineers and executives both read.

Fix & verify

We stay after the report to validate every remediation and retest until each finding is closed.

Ready to see what attackers see?

Book a scoping call and we'll map your surface, recommend the right engagement, and show you exactly what your risk looks like.