Skip to main content

Estonian Security Consultancy

Think your web apps are secure? Let's find out. Real offense builds real defense.

ProksiAbel OÜ runs highly specialized offensive security assessments. I don't just hand you a PDF of automated scanner results. We build realistic defense strategies because, frankly, we know exactly how to break in.

AiTM attack vectorsimulated
Client → AiTM Proxy → Target AppClientAiTM ProxySessionTarget App
Interceptedsession token
Set-Cookie: sid=a3f…9c1; HttpOnly

Select a node to trace the attack

Offensive web security
6+ years
Tooling
Written in Go
Company
Estonian OÜ, registry 17017826
Disclosure
Findings reported upstream and to CERT-EE

Our Services

Forget automated slop. We do actual, hands-on penetration testing. We figure out where your architecture is weak and help you fix it before someone else exploits it.

Penetration Testing & Vulnerability Management

Real-world web application penetration testing. We map out your authentication flows, simulate session hijacking, and show you exactly what an attacker sees. Because automated tools? They miss the logic flaws every single time.

  • Manual Web Application Penetration Testing
  • Authentication Flow Threat Modeling
  • Session Hijacking & AiTM Simulations
Sample findingCritical, CVSS 9.8
Auth bypass / race condition
Custom Go tooling

Security Research & Tool Development

Sometimes the tool we need doesn't exist yet. So we build it. Digging into the code lets us bypass modern JavaScript bot detection systems and map out how organised fraud networks operate.

Secure Development Practices

“We build systems that are mathematically and logically hard to break.”

Select a control

Phishing-resistant auth: credentials are bound to the origin and never leave the device.

How an engagement works

A fixed sequence, so you know what you get before we start and what you hold when we finish.

  1. 01

    Scope

    We agree in writing on targets, test accounts, time windows and rules of engagement. Nothing outside the written scope is touched.

  2. 02

    Test

    Manual testing along the OWASP Web Security Testing Guide, focused on authentication, session handling and business logic, where scanners go blind. Tools support the work; they do not replace it.

  3. 03

    Report

    Every finding comes with reproduction steps, evidence, a CVSS score and a concrete fix for your stack. Critical findings are raised as soon as they are confirmed, not held for the final report.

  4. 04

    Retest

    After you fix, we re-run each finding with the same reproduction steps and record its status in the report.

What you receive

  • An executive summary of risk and priorities for management
  • A technical report with reproduction steps, evidence and CVSS scores
  • Fix guidance for your language and framework
  • Retest results showing which findings are closed
  • All reports and evidence delivered PGP-encrypted

Read our technical guides. The same depth goes into every report.

Frequently asked questions

What does a web application penetration test cover?
Authentication and session handling, access control between users and roles, injection flaws, business logic, and the configuration the application depends on, within the scope agreed in writing. Most of the time goes to logic and authorization flaws, because scanners do not find them.
How is a penetration test different from a vulnerability scan?
A scanner matches known patterns and reports what might be wrong. A manual test proves what is exploitable, chains findings into attack paths, and finds logic and authorization flaws that have no signature. That is usually where the serious findings are.
Do you test production systems?
Only when the written scope says so. A staging environment that mirrors production is preferred; when production is in scope, we first agree on time windows, request-rate limits and a contact who can stop the test.
How are findings rated and reported?
Each finding gets a CVSS score, a plain-language description of the business impact, reproduction steps, evidence and a fix. Reports are delivered encrypted, and critical findings are raised as soon as they are confirmed.
Tom Kristian Abel, Offensive Security Specialist, ProksiAbel OÜ
Tallinn, Estonia
0x0C2A0C6F110AABC5

Tom Kristian Abel

Offensive Security Specialist

“An attacker doesn't read your requirements doc. They look for the single logic flaw.”

My background is deeply rooted in offensive security. I write custom tooling in Go and take complex web applications apart to understand exactly how they work. That is what gives my defensive recommendations their edge.

I have spent over 6 years doing this. I have also authored a proof-of-concept that fully bypassed a major platform's client-side bot detection system. That kind of hands-on evidence is what separates a real assessment from a scanner report.

Technical arsenal & focus

GolangReverse EngineeringAiTM / MitMFull-Stack Web
Recognition

RedSWAT: AI/GovTech Hackathon 2026

Award-winning team with AMEDIA (Kyiv): AI-driven automated penetration testing of government code.

Read the announcement

Coordinated disclosure

Independent AI-assisted review of Estonia's open-source eID stack. Reported to CERT-EE and since fixed upstream; findings later corroborated by AMEDIA.

  • digidoc4jCWE-502 · v6.2.0

    Deserialization RCE in the CLI signing-data path and a certificate-revocation-bypass chain.

  • SiGaCWE-863 · v2.13.1

    Proxy source-address authorization bypass.

  • open-eidSiVa v3.10.3

    Further findings across GovSSO, TARA, and X-Road components.

Reported to CERT-EE. No CVE assigned.

Get In Touch

Ready to test your systems?

Direct line to the specialist. No sales layer in between.

0x0C2A0C6F110AABC5

03DA4E96 931BB2DC 095A2109 0C2A0C6F 110AABC5

Reply within 24h. NDA guaranteed.