bytepatch://secure-shell — bash
$ ssh root@bytepatch.tech
↳ establishing encrypted tunnel… [ OK ]
↳ bypassing firewall layers… [ OK ]
↳ decrypting payload 0x8F3A… [ OK ]
↳ mounting secure assets… [ OK ]
[░░░░░░░░░░░░░░░░░░░░] 0%
ACCESS GRANTED
Home Services Work About Research Contact Cyber Range
Services/Cyber Security/Ethical Hacking

Ethical Hacking

Authorised white-hat hackers who attack your business the way a real threat actor would — red team operations, phishing simulations and adversary emulation, run from Delhi NCR for clients across India and worldwide. Same techniques as the criminals. Opposite outcome.

MITRE ATT&CK TIBER-EU aligned Signed authorisation NDA first
Ethical hacking and red team services by BytePatch Technologies — authorised white hat hackers in India
Overview

The only difference is permission.

An ethical hacker and a criminal use the same tools, the same techniques and the same creativity. What separates them is a signed authorisation letter, an agreed scope, and where the report ends up — on your desk, or on a dark web marketplace.

That distinction is legal, not moral. Under Sections 43 and 66 of India's IT Act, 2000, unauthorised access is an offence regardless of intent. So every BytePatch engagement starts with paperwork before it starts with tooling.

Once that's in place, we stop being polite. We phish your staff, pivot through your network, escalate privileges and go for the crown jewels — then show you exactly how we did it and how to make it impossible next time.

Engagement types

Nine ways we come at you.

Pick the threat model that actually matches your risk. Most clients start grey box and escalate to red team once their detection is worth testing.

Black box

Outside-in attack

We start with nothing but your company name — exactly what a real attacker has. Asset discovery, perimeter mapping and exploitation of whatever we find exposed.

Grey box

Compromised-account simulation

We hold valid low-privilege credentials and see how far we get. This models the most common real breach: a phished employee account. Best value for most clients.

White box

Full-knowledge review

Source code, architecture diagrams and admin access. Finds the most issues per rupee spent, and catches the flaws that only reveal themselves in the code.

Red team

Goal-oriented operation

Pick an objective — reach the customer database, move money, take over an admin account — then achieve it by any authorised route while your team tries to catch us.

Purple team

Attack with your defenders

We attack in the open, alongside your blue team, tuning detections in real time. The fastest way to turn a red-team failure into working alerts.

Phishing simulation

Human attack surface

Authorised phishing, smishing and pretext calling that measures click, credential-submission and report rates — reported as team statistics, never as a list of people to punish.

Assumed breach

Start from inside

We skip the perimeter and start with a foothold, then measure lateral movement, privilege escalation and how much of your estate is reachable before anyone notices.

Physical & social

On-site intrusion

Tailgating, badge cloning, drop devices and pretext visits against your office footprint, run strictly within the authorised premises and hours.

AI & LLM red team

Prompt and agent abuse

Prompt injection, jailbreaks, tool abuse and training-data extraction against your LLM features and autonomous agents, aligned to the OWASP Top 10 for LLM Applications.

Targets

What we hack.

If it has an attack surface and you own it, we can test it. Anything not on this list, ask — the answer is usually yes.

Web applications Mobile apps (iOS & Android) REST & GraphQL APIs Cloud (AWS / Azure / GCP) Internal networks & Active Directory Wi-Fi & wireless Thick clients & desktop apps IoT & embedded devices CI/CD & supply chain Payment & fintech flows SaaS multi-tenant isolation LLM features & AI agents
Skill set
Web exploitation Binary exploitation Active Directory attacks Cloud privilege escalation Mobile reverse engineering Network pivoting Social engineering Malware analysis OSINT & recon Password cracking Wireless attacks LLM prompt injection
Rules of engagement

Paperwork before payloads.

Six documents exist before we run a single tool. This is what makes it ethical hacking rather than a criminal offence.

Mutual NDA
Signed before a single technical detail is exchanged — in both directions.
Authorisation-to-test letter
A signed document naming the in-scope assets and confirming you hold authority over them. Without it, we do not start.
Rules of engagement
Testing windows, escalation contacts, explicitly out-of-scope systems, and a stop-work phrase that halts everything within minutes.
Third-party notice
Where your host, CDN or payment provider requires notification before testing, we help you file it.
Evidence handling
All evidence encrypted at rest, restricted to the named testers, and destroyed 30 days after sign-off with written confirmation.
Safe-harbour clause
A written commitment on both sides covering what we may test, what we will never touch, and how findings are disclosed.
Pricing

Ethical hacking cost in India.

Starting prices in INR, exclusive of GST. Fixed-price after a free scoping call — see the full sample quotation format for exactly how the line items break down.

Targeted Ethical Hack
₹22,000
starting from · one target, outside-in
  • Black-box assessment, single application or perimeter
  • Asset discovery & exposure mapping
  • Exploitation of confirmed weaknesses
  • CVSS v3.1 rated findings with proof of concept
  • Remediation guidance + read-out call
  • Turnaround: 4–7 working days
Scope this engagement →
Adversary EmulationMost chosen
₹48,000
starting from · multi-vector, most chosen
  • Everything in Targeted, plus:
  • Grey-box + assumed-breach testing
  • Authorised phishing simulation
  • Lateral movement & privilege escalation
  • Detection & response gap analysis
  • Free retest + attestation letter
Scope this engagement
Full Red Team
₹95,000
starting from · goal-oriented operation
  • Everything in Adversary Emulation, plus:
  • Objective-driven, stealth-aware operation
  • Custom tooling & C2 infrastructure
  • Physical / social engineering (optional)
  • Full attack narrative & MITRE ATT&CK mapping
  • Purple-team debrief with your blue team
Scope this engagement →
FAQ

Ethical hacking, answered.

What exactly is ethical hacking?

The authorised use of real attacker techniques against systems you own, to find and fix weaknesses before a criminal does. The techniques are identical to a malicious hacker's. The difference is written permission, an agreed scope, and a report that goes to you rather than a dark web marketplace.

Is ethical hacking legal in India?

Yes — when authorised. Sections 43 and 66 of the IT Act, 2000 make unauthorised access an offence with no exception for good intentions. Authorisation is the whole difference, which is why every engagement starts with a signed authorisation-to-test letter, written rules of engagement and a mutual NDA.

Ethical hacking vs penetration testing?

A penetration test is time-boxed and coverage-driven — find as many exploitable issues as possible in a defined scope. A red team engagement is goal-driven and stealth-aware — reach a specific objective while testing whether anyone notices. Most organisations need the pen test first.

How much does it cost?

Targeted black-box assessments start at ₹22,000. Multi-vector adversary emulation with a phishing simulation starts at ₹48,000. A full goal-oriented red team operation starts at ₹95,000. All fixed-price after a free scoping call.

Black box, grey box or white box?

Black box starts with nothing but your name. Grey box gives us valid low-privilege credentials — modelling the far more common phished-account scenario. White box adds source code and finds the most per rupee. Grey box is the best value for most engagements.

Do you phish our staff?

Yes, with written leadership authorisation and in line with your HR policy. We measure click, credential-submission and report rates, and deliver anonymised team-level statistics — never a list of individuals to punish. Results feed straight into targeted training.

What certifications do your testers hold?

Our team works to OSCP-style manual methodology and CEH-aligned engagement structure, and we publish original security research on our research page. We are happy to share tester profiles and redacted sample reports under NDA before you commit.

Can you hack a specific person or account for us?

No. We test only systems you demonstrably own or control and have signed an authorisation letter for. We do not accept work targeting individuals, competitors, ex-partners, or any device or account the requester does not own. Those requests are declined without exception.

Keep reading

Related services & guides.

Ready when you are

Let us break in first.

Free 30-minute scoping call, NDA signed before any detail is shared, and a fixed-price proposal within 24 hours.

Start an engagement Try the Cyber Range