# Elementrica > Penetration testing, attack simulations, security audits, and training in one place. A certified team, rated 5.0 on Clutch, a reply within 24 hours. - Contact: contact@elementrica.com - Phone: +48 12 400 4777 - Full index: https://elementrica.com/llms-full.txt - Sitemap: https://elementrica.com/sitemap-index.xml ## Languages - [English](https://elementrica.com/) - [Polski](https://elementrica.com/pl/) - [Deutsch](https://elementrica.com/de/) ## Pages - [About Elementrica | Team, certifications and approach](https://elementrica.com/company/) - [Client References | Elementrica](https://elementrica.com/references/) - [Contact | Elementrica](https://elementrica.com/contact/) ## Services — categories - [Attack Simulations | Elementrica](https://elementrica.com/services/attack-simulations/) - [IT Security Audits | Elementrica](https://elementrica.com/services/security-audits/) - [Penetration Testing | Elementrica](https://elementrica.com/services/penetration-testing/) - [Training | Elementrica](https://elementrica.com/services/training/) ## Services - [Attack Simulations: APT Simulations | Elementrica](https://elementrica.com/services/apt-simulation/) - [Attack Simulations: Phishing Campaigns | Elementrica](https://elementrica.com/services/phishing-campaigns/) - [Attack Simulations: Physical Security Testing | Elementrica](https://elementrica.com/services/physical-security-testing/) - [Attack Simulations: Purple Team | Elementrica](https://elementrica.com/services/purple-teaming/) - [Attack Simulations: Ransomware Attack Simulations](https://elementrica.com/services/ransomware-simulation/) - [Attack Simulations: Red Team | Elementrica](https://elementrica.com/services/red-teaming/) - [Attack Simulations: Social Engineering | Elementrica](https://elementrica.com/services/social-engineering/) - [Attack Simulations: TLPT | Elementrica](https://elementrica.com/services/tlpt/) - [IT Security Audits: Active Directory Audit | Elementrica](https://elementrica.com/services/active-directory-audit/) - [IT Security Audits: Cloud Security Audit | Elementrica](https://elementrica.com/services/cloud-audit/) - [IT Security Audits: DORA Audit | Elementrica](https://elementrica.com/services/dora-audit/) - [IT Security Audits: Entra ID Audit | Elementrica](https://elementrica.com/services/entra-id-audit/) - [IT Security Audits: ISO 27001 Audit | Elementrica](https://elementrica.com/services/iso-27001-audit/) - [IT Security Audits: IT Security Audit | Elementrica](https://elementrica.com/services/it-audit/) - [IT Security Audits: NCSA (KSC) Audit | Elementrica](https://elementrica.com/services/ksc-audit/) - [IT Security Audits: NIS2 Audit | Elementrica](https://elementrica.com/services/nis2-audit/) - [Penetration Testing: API | Elementrica](https://elementrica.com/services/api-pentest/) - [Penetration Testing: Desktop Applications | Elementrica](https://elementrica.com/services/desktop-app-pentest/) - [Penetration Testing: External Network | Elementrica](https://elementrica.com/services/external-network-pentest/) - [Penetration Testing: ICS / SCADA / OT / IoT | Elementrica](https://elementrica.com/services/ot-ics-pentest/) - [Penetration Testing: Internal Network | Elementrica](https://elementrica.com/services/internal-network-pentest/) - [Penetration Testing: LLM Applications | Elementrica](https://elementrica.com/services/llm-pentest/) - [Penetration Testing: Mobile Applications | Elementrica](https://elementrica.com/services/mobile-app-pentest/) - [Penetration Testing: SAST | Elementrica](https://elementrica.com/services/source-code-review/) - [Penetration Testing: Web Applications | Elementrica](https://elementrica.com/services/web-app-pentest/) - [Penetration Testing: Web3 Applications | Elementrica](https://elementrica.com/services/web3-pentest/) - [Penetration Testing: Wireless Networks | Elementrica](https://elementrica.com/services/wifi-pentest/) - [Training: OWASP Training | Elementrica](https://elementrica.com/services/owasp-training/) - [Training: Penetration Testing Workshop | Elementrica](https://elementrica.com/services/pentest-workshop/) - [Training: Red Team Workshop | Elementrica](https://elementrica.com/services/red-team-workshop/) - [Training: Secure Coding Training | Elementrica](https://elementrica.com/services/secure-coding/) - [Training: Security Awareness Training | Elementrica](https://elementrica.com/services/security-awareness/) - [Training: Spotting AI-Driven Attacks | Elementrica](https://elementrica.com/services/ai-security-training/) ## Products - [E-One: see who clicks before a real attacker does](https://elementrica.com/products/e-one/) - [E-Two: make your weakest link your first defense](https://elementrica.com/products/e-two/) - [E-Zero: Your whole pentest project in one place](https://elementrica.com/products/e-zero/) - [Pulse: continuous threat exposure management (CTEM)](https://elementrica.com/products/pulse/) - [Security products | Elementrica](https://elementrica.com/products/) ## News - [A short introduction to ICS and OT security | Elementrica](https://elementrica.com/news/intro-to-ics-and-ot-security/) - [An introduction to the NIST Cybersecurity Framework](https://elementrica.com/news/introduction-to-the-nist-cybersecurity-framework/) - [Certighost (CVE-2026-54121) | Elementrica](https://elementrica.com/de/aktuelles/certighost-cve-2026-54121/) - [Certighost (CVE-2026-54121): an AD CS authorization bug](https://elementrica.com/news/certighost-cve-2026-54121/) - [Certighost (CVE-2026-54121): błąd autoryzacji w AD CS](https://elementrica.com/pl/aktualnosci/certighost-cve-2026-54121/) - [Cyberbezpieczeństwo to inwestycja, nie koszt | Elementrica](https://elementrica.com/pl/aktualnosci/cyberbezpieczenstwo-to-inwestycja-nie-koszt-jak-obliczyc-roi-ochrony-firmy/) - [Cyberbezpieczeństwo: od kosztu do przewagi strategicznej](https://elementrica.com/pl/aktualnosci/cyberbezpieczenstwo-od-kosztu-operacyjnego-do-strategicznej-dzwigni-biznesu/) - [Cybersecurity is an investment, not a cost | Elementrica](https://elementrica.com/news/cybersecurity-is-an-investment-not-a-cost-how-to-calculate-roi/) - [Cybersecurity: from operating cost to strategic advantage](https://elementrica.com/news/cybersecurity-from-operating-cost-to-strategic-advantage/) - [Cybersicherheit ist eine Investition, kein Kostenfaktor](https://elementrica.com/de/aktuelles/cybersicherheit-ist-investition-kein-kostenfaktor-roi-berechnen/) - [Cybersicherheit: vom Kostenfaktor zum strategischen Vorteil](https://elementrica.com/de/aktuelles/cybersicherheit-vom-kostenfaktor-zum-strategischen-vorteil/) - [Dlaczego CVSS często nie oddaje realnego zagrożenia](https://elementrica.com/pl/aktualnosci/dlaczego-wyniki-cvss-czesto-nie-odzwierciedlaja-rzeczywistych-zagrozen/) - [DoS and fail-open: when a crash opens the door | Elementrica](https://elementrica.com/news/dos-fail-open/) - [DoS i fail-open: gdy awaria otwiera drzwi atakującemu](https://elementrica.com/pl/aktualnosci/dos-fail-open/) - [DoS und Fail-Open: wenn ein Ausfall die Tür öffnet](https://elementrica.com/de/aktuelles/dos-fail-open/) - [E-Zero: eine Plattform für das ganze Sicherheitsprojekt](https://elementrica.com/de/aktuelles/e-zero-plattform-fuer-sicherheitsprojekte/) - [E-Zero: jedna platforma do projektów bezpieczeństwa](https://elementrica.com/pl/aktualnosci/rozwijamy-e-zero-platforme-ktora-porzadkuje-chaos-w-projektach-cyberbezpieczenstwa/) - [Ein Link, und Ihr Copilot arbeitet für jemand anderen](https://elementrica.com/de/aktuelles/searchleak-microsoft-365-copilot-cve-2026-42824/) - [Eine kurze Einführung in die ICS- und OT-Sicherheit](https://elementrica.com/de/aktuelles/einfuehrung-in-ics-und-ot-sicherheit/) - [Einführung in das NIST Cybersecurity Framework | Elementrica](https://elementrica.com/de/aktuelles/einfuehrung-in-das-nist-cybersecurity-framework/) - [FrostyGoop and the cyber cold war | Elementrica](https://elementrica.com/news/frostygoop-cyber-cold-war-how-malware-cut-heat-in-lviv/) - [FrostyGoop i cyberzimna wojna | Elementrica](https://elementrica.com/pl/aktualnosci/frostygoop-i-cyberzimna-wojna-jak-zlosliwe-oprogramowanie-zaklocilo-lwowska-infrastrukture-krytyczna/) - [FrostyGoop und der kalte Cyberkrieg | Elementrica](https://elementrica.com/de/aktuelles/frostygoop-kalter-cyberkrieg-heizungsangriff-lwiw/) - [Ile kosztuje test penetracyjny? | Elementrica](https://elementrica.com/pl/aktualnosci/ile-naprawde-kosztuje-test-penetracyjny/) - [Jeden link i Twój Copilot pracuje dla kogoś innego](https://elementrica.com/pl/aktualnosci/searchleak-microsoft-365-copilot-cve-2026-42824/) - [Krótkie wprowadzenie do cyberbezpieczeństwa ICS i OT](https://elementrica.com/pl/aktualnosci/krotkie-wprowadzenie-do-cyberbezpieczenstwa-ics-i-ot/) - [LegacyHive: LPE w Windows bez łatki (ProfSvc) | Elementrica](https://elementrica.com/pl/aktualnosci/legacyhive-lpe-windows-profsvc/) - [LegacyHive: ungepatchte Windows-LPE über ProfSvc](https://elementrica.com/de/aktuelles/legacyhive-lpe-windows-profsvc/) - [LegacyHive: unpatched Windows LPE via ProfSvc | Elementrica](https://elementrica.com/news/legacyhive-lpe-windows-profsvc/) - [Mehr Cybersicherheit im Finanzsektor | Elementrica](https://elementrica.com/de/aktuelles/dora-leitfaden-cybersicherheit-finanzsektor/) - [NIS2 and penetration testing: what changes for your company](https://elementrica.com/news/nis2-directive-and-penetration-testing/) - [NIS2 i testy penetracyjne: co musisz wiedzieć | Elementrica](https://elementrica.com/pl/aktualnosci/wszystko-co-musisz-wiedziec-o-dyrektywie-nis2-i-testach-penetracyjnych/) - [NIS2 und Penetrationstests | Elementrica](https://elementrica.com/de/aktuelles/nis2-richtlinie-und-penetrationstests/) - [NTLM reflection na Windows Server 2025 (CVE-2026-24294)](https://elementrica.com/pl/aktualnosci/ntlm-reflection-server-2025-cve-2026-24294/) - [NTLM reflection on Windows Server 2025 (CVE-2026-24294)](https://elementrica.com/news/ntlm-reflection-server-2025-cve-2026-24294/) - [NTLM-Reflection auf Windows Server 2025 (CVE-2026-24294)](https://elementrica.com/de/aktuelles/ntlm-reflection-server-2025-cve-2026-24294/) - [One link and your Copilot works for someone else](https://elementrica.com/news/searchleak-microsoft-365-copilot-cve-2026-42824/) - [Penetration test scope | Elementrica](https://elementrica.com/news/sample-penetration-test-scope/) - [Penetration test scope: the one page that matters most](https://elementrica.com/news/penetration-test-scope/) - [Penetration testing vs. vulnerability assessment](https://elementrica.com/news/penetration-testing-vs-vulnerability-assessment-key-differences/) - [Penetrationstest oder Schwachstellenanalyse | Elementrica](https://elementrica.com/de/aktuelles/penetrationstest-vs-schwachstellenanalyse-die-unterschiede/) - [regreSSHion (CVE-2024-6387) | Elementrica](https://elementrica.com/de/aktuelles/regresshion-openssh-cve-2024-6387/) - [regreSSHion (CVE-2024-6387) | Elementrica](https://elementrica.com/news/regresshion-openssh-cve-2024-6387/) - [regreSSHion (CVE-2024-6387) | Elementrica](https://elementrica.com/pl/aktualnosci/regresshion-cve-2024-6387/) - [Stronger cybersecurity in financial services | Elementrica](https://elementrica.com/news/dora-financial-sector-cybersecurity-guide/) - [Testy penetracyjne a ocena podatności | Elementrica](https://elementrica.com/pl/aktualnosci/testy-penetracyjne-a-ocena-podatnosci-rozplatywanie-roznic/) - [Umfang eines Penetrationstests | Elementrica](https://elementrica.com/de/aktuelles/beispiel-umfang-penetrationstest/) - [Umfang eines Penetrationstests: die entscheidende Seite](https://elementrica.com/de/aktuelles/umfang-eines-penetrationstests/) - [Warum CVSS-Werte oft die tatsächliche Bedrohung verfehlen](https://elementrica.com/de/aktuelles/warum-cvss-werte-oft-die-echte-bedrohung-verfehlen/) - [Was kostet ein Penetrationstest? | Elementrica](https://elementrica.com/de/aktuelles/was-kostet-ein-penetrationstest/) - [We're building E-Zero: one platform for security work](https://elementrica.com/news/building-e-zero-one-platform-for-security-projects/) - [What does a penetration test cost? | Elementrica](https://elementrica.com/news/what-does-a-penetration-test-cost/) - [Why CVSS scores often miss the real threat | Elementrica](https://elementrica.com/news/why-cvss-scores-often-miss-the-real-threat/) - [Windows LPE: MiniPlasma and an unpatched CVE-2020-17103](https://elementrica.com/news/windows-lpe-miniplasma-cve-2020-17103/) - [Windows LPE: MiniPlasma i powrót (nie)załatanej luki](https://elementrica.com/pl/aktualnosci/windows-lpe-miniplasma-cve-2020-17103/) - [Windows LPE: MiniPlasma und eine ungepatchte Lücke](https://elementrica.com/de/aktuelles/windows-lpe-miniplasma-cve-2020-17103/) - [wp2shell: pre-auth RCE in WordPress (CVE-2026-63030)](https://elementrica.com/news/wp2shell-rce-wordpress-cve-2026-63030/) - [wp2shell: pre-auth RCE w WordPress (CVE-2026-63030)](https://elementrica.com/pl/aktualnosci/wp2shell-rce-wordpress-cve-2026-63030/) - [wp2shell: Pre-Auth-RCE in WordPress (CVE-2026-63030)](https://elementrica.com/de/aktuelles/wp2shell-rce-wordpress-cve-2026-63030/) - [Wprowadzenie do NIST Cybersecurity Framework | Elementrica](https://elementrica.com/pl/aktualnosci/wprowadzenie-do-nist-cybersecurity-framework/) - [Wzmocnienie cyberbezpieczeństwa w sektorze finansowym](https://elementrica.com/pl/aktualnosci/wzmocnienie-cyberbezpieczenstwa-w-sektorze-finansowym-kompletny-przewodnik-po-ustawie-o-cyfrowej-odpornosci-operacyjnej-dora/) - [Zakres testu penetracyjnego | Elementrica](https://elementrica.com/pl/aktualnosci/przykladowy-zakres-testu-penetracyjnego/) - [Zakres testu penetracyjnego: co decyduje o wyniku](https://elementrica.com/pl/aktualnosci/zakres-testu-penetracyjnego/) ## Case studies - [An invoice, a gift card, and 22 sets of credentials](https://elementrica.com/case-studies/an-invoice-a-gift-card-and-22-sets-of-credentials/) - [Case Studies | Elementrica](https://elementrica.com/case-studies/) - [Five High findings, zero way in | Elementrica](https://elementrica.com/case-studies/five-high-findings-zero-way-in/) - [One operator account, full platform takeover | Elementrica](https://elementrica.com/case-studies/one-operator-account-full-platform-takeover/) - [Passive listening, one account, and the whole domain](https://elementrica.com/case-studies/passive-listening-one-account-and-the-whole-domain/) - [Request smuggling on a server that shouldn't be online](https://elementrica.com/case-studies/request-smuggling-on-a-server-that-was-not-supposed-to-be-on/) - [SAST review: 159 CVEs, real risk in one line | Elementrica](https://elementrica.com/case-studies/159-cves-in-libraries/) - [The whole company had access to the secrets vault](https://elementrica.com/case-studies/the-whole-company-had-access-to-the-secrets-vault-one-group-/) - [We uploaded a package. We got root. | Elementrica](https://elementrica.com/case-studies/we-uploaded-a-package-we-got-root/)