BSBlackmoor Security (919) 555-0154
Independent since 2016

Find out how you get breached, first

We run real penetration tests against your environment and watch it around the clock, so the first person inside your network is on your payroll.

9 yrsin operation
24/7staffed SOC
310+tests delivered
< 15 mincritical alert triage
Engagements

How companies work with us

Testing is fixed fee and scoped up front. Monitoring is priced per endpoint per month.

From $14,500

External penetration test

Manual testing of internet-facing assets with a report your auditors and your engineers can both use.

From $19,000

Internal network and Active Directory test

Assumed-breach testing of lateral movement, privilege escalation and domain compromise paths.

From $16,000

Web and API application testing

Authenticated testing against OWASP ASVS, with proof-of-concept for every finding we report.

From $9 /endpoint/mo

Managed detection and response

24/7 SOC monitoring with human triage and containment actions defined in your playbook.

From $18,000 /yr

Incident response retainer

Guaranteed four hour response, with unused retainer hours applied to advisory work.

From $6,500

Phishing and social engineering

Targeted campaigns with training that fires at the moment someone clicks.

Who we are

Testers, not a scan reseller

Blackmoor was founded in 2016 by three people who left a larger consultancy tired of automated scans being sold as penetration tests. Every tester on staff holds OSCP or equivalent and every engagement includes manual exploitation. We are independent and sell no security products, so our recommendations are not tied to a vendor's margin.

•Every tester holds OSCP or an equivalent hands-on certification
•No product resale, so findings carry no vendor bias
•Retest of remediated findings included for 90 days
Cybersecurity professionals working on computer systems, focusing on data protection in a dimly lit room.
Reviews

What security leaders say

“Their report separated what would actually get us owned from what was noise. Our board understood the first section and my engineers used the second.”

Priya N., CISO, healthcare SaaS

“Called the hotline at 11pm on a Sunday during a ransomware event. A responder was on a bridge in eighteen minutes and we contained it that night.”

Mark T., VP Infrastructure, manufacturing
FAQ

Scoping and engagement questions

How is a penetration test different from a vulnerability scan?

A scan produces a list of possible weaknesses from a signature database. A penetration test has a human chaining those weaknesses together to reach something that matters, like domain admin or your customer database. We run scans as an input, never as the deliverable.

Will testing take our systems down?

Rarely, and we plan against it. We agree on out-of-scope systems, testing windows and a stop condition before we start, and denial of service testing is excluded unless you specifically ask for it. You get a direct line to the lead tester for the entire engagement.

How long does an engagement take?

A typical external test runs two weeks of testing plus one week for reporting and quality review. Internal and application tests usually run three to four weeks total. We book four to six weeks out, sooner if you have an audit deadline, so tell us the date.

Do you help fix what you find, or just report it?

Both. Every finding includes reproduction steps and specific remediation guidance, and we hold a technical readout call with your engineers. Retesting of remediated findings is included for 90 days, and we issue an updated letter you can hand to customers or auditors.

Contact

Start with a scoping call

Thirty minutes to understand your environment and your deadline, then a fixed-fee proposal within three business days.

Phone(919) 555-0154
Address402 Glenwood Ave, Suite 600, Raleigh, NC 27603, Raleigh, North Carolina
HoursSOC staffed 24/7, business office Mon to Fri 8am to 6pm Eastern
AreaClients across North America