Estonian Security Consultancy
Think your web apps are secure? Let's find out. Real offense builds real defense.
ProksiAbel OÜ runs highly specialized offensive security assessments. I don't just hand you a PDF of automated scanner results. We build realistic defense strategies because, frankly, we know exactly how to break in.
- Offensive web security
- 6+ years
- Tooling
- Written in Go
- Company
- Estonian OÜ, registry 17017826
- Disclosure
- Findings reported upstream and to CERT-EE
Our Services
Forget automated slop. We do actual, hands-on penetration testing. We figure out where your architecture is weak and help you fix it before someone else exploits it.
Penetration Testing & Vulnerability Management
Real-world web application penetration testing. We map out your authentication flows, simulate session hijacking, and show you exactly what an attacker sees. Because automated tools? They miss the logic flaws every single time.
- Manual Web Application Penetration Testing
- Authentication Flow Threat Modeling
- Session Hijacking & AiTM Simulations
Auth bypass / race conditionSecurity Research & Tool Development
Sometimes the tool we need doesn't exist yet. So we build it. Digging into the code lets us bypass modern JavaScript bot detection systems and map out how organised fraud networks operate.
Secure Development Practices
“We build systems that are mathematically and logically hard to break.”
Phishing-resistant auth: credentials are bound to the origin and never leave the device.
How an engagement works
A fixed sequence, so you know what you get before we start and what you hold when we finish.
- 01
Scope
We agree in writing on targets, test accounts, time windows and rules of engagement. Nothing outside the written scope is touched.
- 02
Test
Manual testing along the OWASP Web Security Testing Guide, focused on authentication, session handling and business logic, where scanners go blind. Tools support the work; they do not replace it.
- 03
Report
Every finding comes with reproduction steps, evidence, a CVSS score and a concrete fix for your stack. Critical findings are raised as soon as they are confirmed, not held for the final report.
- 04
Retest
After you fix, we re-run each finding with the same reproduction steps and record its status in the report.
What you receive
- An executive summary of risk and priorities for management
- A technical report with reproduction steps, evidence and CVSS scores
- Fix guidance for your language and framework
- Retest results showing which findings are closed
- All reports and evidence delivered PGP-encrypted
Read our technical guides. The same depth goes into every report.
Frequently asked questions
- What does a web application penetration test cover?
- Authentication and session handling, access control between users and roles, injection flaws, business logic, and the configuration the application depends on, within the scope agreed in writing. Most of the time goes to logic and authorization flaws, because scanners do not find them.
- How is a penetration test different from a vulnerability scan?
- A scanner matches known patterns and reports what might be wrong. A manual test proves what is exploitable, chains findings into attack paths, and finds logic and authorization flaws that have no signature. That is usually where the serious findings are.
- Do you test production systems?
- Only when the written scope says so. A staging environment that mirrors production is preferred; when production is in scope, we first agree on time windows, request-rate limits and a contact who can stop the test.
- How are findings rated and reported?
- Each finding gets a CVSS score, a plain-language description of the business impact, reproduction steps, evidence and a fix. Reports are delivered encrypted, and critical findings are raised as soon as they are confirmed.

Tom Kristian Abel
Offensive Security Specialist“An attacker doesn't read your requirements doc. They look for the single logic flaw.”
My background is deeply rooted in offensive security. I write custom tooling in Go and take complex web applications apart to understand exactly how they work. That is what gives my defensive recommendations their edge.
I have spent over 6 years doing this. I have also authored a proof-of-concept that fully bypassed a major platform's client-side bot detection system. That kind of hands-on evidence is what separates a real assessment from a scanner report.
Technical arsenal & focus
RedSWAT: AI/GovTech Hackathon 2026
Award-winning team with AMEDIA (Kyiv): AI-driven automated penetration testing of government code.
Read the announcementCoordinated disclosure
Independent AI-assisted review of Estonia's open-source eID stack. Reported to CERT-EE and since fixed upstream; findings later corroborated by AMEDIA.
- digidoc4jCWE-502 · v6.2.0
Deserialization RCE in the CLI signing-data path and a certificate-revocation-bypass chain.
- SiGaCWE-863 · v2.13.1
Proxy source-address authorization bypass.
- open-eidSiVa v3.10.3
Further findings across GovSSO, TARA, and X-Road components.
Reported to CERT-EE. No CVE assigned.
Get In Touch
Ready to test your systems?
Direct line to the specialist. No sales layer in between.
Reply within 24h. NDA guaranteed.