DISCLAIMER: This is entirely fictional content. GreyFern, all people, clients, tooling, and engagements described herein are fictional and were created for runhacks.sh, an interactive cybersecurity training platform. Nothing on this site represents a real organization, person, or event. Any resemblance to real entities or individuals is coincidental and unintentional.

The firm

Offensive work, done with restraint.

GreyFern grew out of a single conviction: offensive work can be done with rigor and restraint, or it can be done recklessly — and the difference is not talent. It is discipline.

The name

Grey for the space we work in. Fern for how we move through it.

Grey is the grey-hat, grey-area, low-profile space we operate in. Everything we do is legal and authorized — but our raw material is what the world leaves exposed in the open.

Fern is the logo: an unfurling frond, quiet organic growth in the understory, spreading without being noticed. It is how we think about reconnaissance. You unfurl slowly, you touch nothing you don't have to, and by the time anyone looks, you are already everywhere.

The firm keeps a deliberately low public profile. We do not publish operator headshots, we do not name clients, and most of what we do never appears anywhere our targets can see it. That discretion is not marketing. It is tradecraft.

An empty glass boardroom above London at dusk

Founding story

Founded on the inverse of a reckless shop.

Before GreyFern, founders Iris Calloway and Alan Voss worked at a firm the industry still calls, when it calls it anything, a cowboy shop: technically excellent, operationally reckless, and inclined to treat scope as a suggestion.

On a red-team engagement against a regulated client, an operator followed an exposed path well outside the authorized scope, pivoted into a live production system, and tripped a real security incident. Alan — the firm's scoping and authorization lead — had flagged the risk in writing and been overruled. Iris was the operator who refused to continue once she saw where the path led, and escalated instead.

Both left within the month. In 2016 they founded GreyFern on the inverse of everything that shop stood for: authorized work only, scope treated as sacred, passive-first, and reconnaissance — not aggression — as the core craft. The firm has never had a scope-breach incident. That clean record is the entire brand.

The house method

Collect. Correlate. Enumerate. Assess. Report.

Our method mirrors how an unfurling frond grows — slowly, from the base, into the space available. Five steps, run in order.

1
Collect

Gather everything the target has left exposed: websites, filings, directories, calendars, data feeds, and the people who talk.

2
Correlate

Cross-reference every source against every other. Where the press kit and the live site and the API disagree, that gap is the finding.

3
Enumerate

Where a source is incomplete, find the structured version a GUI won't show you: the undocumented endpoint, the next page of results, the raw file the browser won't render.

4
Assess

Decide what matters and what it means for the client's decision.

5
Report

Hand the client an accurate, sourced, decision-grade picture.

Rules of engagement

The Frond Doctrine.

Six rules we treat as non-negotiable. Every operator is drilled on them before they touch a live engagement.

01
Authorized only
No signed scope, no engagement.

An engagement without an authorization letter does not exist. No exceptions.

02
Scope is sacred
Exactly as far as authorized. Not one step further.

An operator who exceeds scope has failed the engagement, regardless of what they found.

03
Passive first
Exhaust the open before you touch the target.

Most of what a client needs is already exposed. The craft is reading it correctly.

04
Minimal footprint
Being seen is a defect.

We leave as little trace as the objective allows.

05
Corroborate
One source is a lead, not a finding.

Cross-reference until the picture holds. Disagreement is itself intelligence.

06
Stop on breach
Restraint is not caution. It is the job.

Outside authorization, or real-world safety at risk — stop and escalate immediately.

“We're not the people who break in. We're the people who could, and choose the paperwork.” — the line every new operator hears once. We are a legitimate firm; the grey-hat name is aspirational irony. We work in the grey space of what is publicly discoverable, and we operate strictly inside the law and inside our clients' authorization.

Tradecraft platform

A toolchain built to enforce the doctrine, not just support it.

GreyFern maintains an internal toolchain that operators live inside. It is never exposed to clients or targets. If an engagement isn't authorized, the tooling literally will not run it.

FROND

Collection management and correlation. Its core assumption is that contradiction is signal — where sources disagree, it flags the conflict rather than silently picking a winner.

SPORE

Surface & Passive Open-source Reconnaissance Engine. Maps a target's exposed infrastructure, feeds, and undocumented endpoints without touching production.

UNDERSTORY

Engagement management. Signed scope, rules of engagement, authorization letters, and evidence chain. If it isn't in UNDERSTORY, the engagement doesn't exist.

DRYAD

Secure operator-to-handler comms. Engagement traffic never rides a client's or a target's infrastructure.

Everyone can find something. The job is to find everything.

Decide what matters, and never once be seen looking. If that's the picture you need, start with a scoped conversation.

Discuss an engagement