DISCLAIMER: This is entirely fictional content. GreyFern, all people, clients, tooling, and engagements described herein are fictional and were created for runhacks.sh, an interactive cybersecurity training platform. Nothing on this site represents a real organization, person, or event. Any resemblance to real entities or individuals is coincidental and unintentional.
An analyst at a window overlooking the City of London at dusk

Offensive security · Competitive intelligence

See first.
Move last.

GreyFern maps what a competent adversary can already learn about you from the outside — under signed scope, before you move on it.

London · Est. 2016 Authorized-only Operators distributed
City of London · GreyFern operations

Most organizations don't actually know what a competent adversary can learn about them. And most firms that offer to tell them go loud, or hand over a scan report and call it intelligence.

A single fern frond, unfurling, on a dark background

What GreyFern does

We do the patient version.

We map an organization's real structure — its people, its exposed systems, its habits — and the gap between what it believes is private and what is sitting in the open for anyone who knows how to look.

We do it under strict authorization, working exactly as far as the client signed off and not one step further. Most of what a client needs is already exposed; the discipline is reading it correctly, corroborating it, and never once being seen looking.

We are privately held and independently operated. We take only authorized work, under signed scope — and we turn down more engagements than we accept.

Service lines

Four standing lines. Every engagement scoped, signed, and bounded.

01

Passive Reconnaissance & OSINT

No-touch collection, footprinting, and exposure assessment. We show you exactly what an adversary can already see from the outside — without touching a single production system.

Typical client needTell me what we're leaking.

02

Pre-Engagement Recon Packages

The intelligence groundwork that precedes an active security test — org structure, access windows, attack surface. The recon operator's package becomes the active team's plan.

Typical client needMap the target before we test it.

03

Red-Team & Adversary Emulation

Authorized active engagements that model a real threat actor end to end — under written rules of engagement, with every step recorded and every artifact accounted for.

Typical client needProve whether we can be breached.

04

Competitive Intelligence & Due Diligence

Pre-acquisition, partnership, and third-party-risk research. A decision-grade picture of a target organization's real ownership, history, and undisclosed exposure.

Typical client needTell me who I'm really dealing with.

The house method

Unfurl slowly. Touch nothing you don't have to.

Our method mirrors how a frond grows — from the base, into the space available. Five steps, run in order.

1
Collect

Gather everything the target has left exposed: websites, filings, directories, calendars, data feeds — and the people who talk.

2
Correlate

Cross-reference every source against every other source. Where the press kit, the live site, and the API disagree, that gap is the finding — not a nuisance to smooth over.

3
Enumerate

Where a source is incomplete, find the structured version a GUI won't show you: the undocumented endpoint, the next page of results, the raw file the browser won't render.

4
Assess

Decide what matters and what it means for the client's decision. A pile of sources is not intelligence until someone has weighed it.

5
Report

Hand the client an accurate, sourced, decision-grade picture — every claim corroborated, every artifact traceable to where it came from.

Contradiction is signal

A single source is a lead, not a fact.

Sources always disagree. Amateur collection picks a winner and moves on. We treat the disagreement itself as the intelligence — and chase it until the picture holds.

Press kit
Head of Research: A. Whitfield
Live site
Head of Research: vacant
Directory feed
Head of Research: N. Tanaka — joined 8 mo ago
The finding
The published record lags a leadership change the target never announced. That gap is the report.

The Frond Doctrine

Six rules we treat as non-negotiable.

Every operator is drilled on them before they touch a live engagement. Discipline — not talent — is what separates a clean engagement from an incident.

01
Authorized only
No signed scope, no engagement.

An engagement without an authorization letter does not exist. No exceptions, no favors, no “just this once.”

02
Scope is sacred
Exactly as far as authorized. Not one step further.

An operator who exceeds scope has failed the engagement, regardless of what they found.

03
Passive first
Exhaust the open before you touch the target.

Most of what a client needs is already exposed. The craft is in reading it correctly.

04
Minimal footprint
Being seen is a defect.

We leave as little trace as the objective allows, and never more than the client authorized.

05
Corroborate
One source is a lead, not a finding.

We cross-reference until the picture holds. Where sources disagree, the disagreement is itself intelligence.

06
Stop on breach
Restraint is not caution. It is the job.

If an operator lands outside authorization or a client's real-world safety is at risk, they stop and escalate immediately.

2016
Founded on the inverse of a reckless shop
Zero
Scope-breach incidents, ever
100%
Authorized, signed-scope engagements

Know the ground before you move on it.

Every engagement begins with a scoped conversation. We take only authorized work — and we'll tell you straight if what you need can't be done inside the lines.

Start an engagement inquiry