DISCLAIMER: This is entirely fictional content. GreyFern, all people, clients, tooling, and engagements described herein are fictional and were created for runhacks.sh, an interactive cybersecurity training platform. Nothing on this site represents a real organization, person, or event. Any resemblance to real entities or individuals is coincidental and unintentional.

Services

Scoped engagements, not subscriptions.

We don't sell retainers or tiers. We sell scoped engagements — each one signed, bounded, and graded against objectives an operator can actually be held to. Four standing lines.

01

Passive Reconnaissance & OSINT

No-touch collection, footprinting, and exposure assessment. We map your real external footprint from public and semi-public sources and show you exactly what an adversary can already assemble — without touching a single production system.

Typical client needTell me what we're leaking.

02

Pre-Engagement Recon Packages

The intelligence groundwork that precedes an active security test: org structure, people, access windows, and attack surface. Most engagements begin here. The recon operator's package becomes the active team's attack plan.

Typical client needMap the target before we test it.

03

Red-Team & Adversary Emulation

Authorized active engagements that model how a real threat actor would operate, end to end — under written rules of engagement, with every step recorded and every artifact traceable. Many recon packages escalate here once the ground is mapped.

Typical client needProve whether we can be breached.

04

Competitive Intelligence & Due Diligence

Pre-acquisition, partnership, and third-party-risk research. A decision-grade picture of a target organization's real ownership, history, litigation and regulatory record, and the gap between the story it tells and the story its paper trail tells.

Typical client needTell me who I'm really dealing with.

How engagements run

Recon is where the ground gets mapped — and where every engagement starts.

Most engagements begin with a recon package. Many stop there; some escalate into an active red-team once the ground is mapped. The passive picture the recon operator builds becomes the active team's plan — which is why recon is the discipline we hold everything else to.

Every engagement is scoped by our client office with the founder, authorized in writing, and recorded before an operator touches it. We work exactly as far as you signed off, and we turn down more work than we accept — including work that can't be done inside the law or targets a client has no standing to authorize.

You get an accurate, sourced, decision-grade deliverable: every claim corroborated, every artifact traceable to where it came from and under what authorization it was collected.

What every engagement includes

The discipline is the deliverable.

01
Signed scope
Written rules of engagement.

Exactly what may and may not be touched, by whom, and when — agreed before anything begins.

02
Passive-first collection
The open sources, exhausted.

We read everything the target has left exposed before we ever consider active measures.

03
Corroborated findings
Nothing rides a single source.

Every claim cross-referenced. Where sources disagree, we chase the gap until the picture holds.

04
Full evidence chain
Traceable, defensible, minimal.

Every artifact accounted for, with the smallest footprint the objective allows.

Start with a scoped conversation.

Tell us the decision you're trying to make. We'll tell you whether it's an engagement we can take, and how we'd scope it.

Discuss an engagement