Authorised white-hat hackers who attack your business the way a real threat actor would — red team operations, phishing simulations and adversary emulation, run from Delhi NCR for clients across India and worldwide. Same techniques as the criminals. Opposite outcome.

An ethical hacker and a criminal use the same tools, the same techniques and the same creativity. What separates them is a signed authorisation letter, an agreed scope, and where the report ends up — on your desk, or on a dark web marketplace.
That distinction is legal, not moral. Under Sections 43 and 66 of India's IT Act, 2000, unauthorised access is an offence regardless of intent. So every BytePatch engagement starts with paperwork before it starts with tooling.
Once that's in place, we stop being polite. We phish your staff, pivot through your network, escalate privileges and go for the crown jewels — then show you exactly how we did it and how to make it impossible next time.
Pick the threat model that actually matches your risk. Most clients start grey box and escalate to red team once their detection is worth testing.
We start with nothing but your company name — exactly what a real attacker has. Asset discovery, perimeter mapping and exploitation of whatever we find exposed.
We hold valid low-privilege credentials and see how far we get. This models the most common real breach: a phished employee account. Best value for most clients.
Source code, architecture diagrams and admin access. Finds the most issues per rupee spent, and catches the flaws that only reveal themselves in the code.
Pick an objective — reach the customer database, move money, take over an admin account — then achieve it by any authorised route while your team tries to catch us.
We attack in the open, alongside your blue team, tuning detections in real time. The fastest way to turn a red-team failure into working alerts.
Authorised phishing, smishing and pretext calling that measures click, credential-submission and report rates — reported as team statistics, never as a list of people to punish.
We skip the perimeter and start with a foothold, then measure lateral movement, privilege escalation and how much of your estate is reachable before anyone notices.
Tailgating, badge cloning, drop devices and pretext visits against your office footprint, run strictly within the authorised premises and hours.
Prompt injection, jailbreaks, tool abuse and training-data extraction against your LLM features and autonomous agents, aligned to the OWASP Top 10 for LLM Applications.
If it has an attack surface and you own it, we can test it. Anything not on this list, ask — the answer is usually yes.
Six documents exist before we run a single tool. This is what makes it ethical hacking rather than a criminal offence.
Starting prices in INR, exclusive of GST. Fixed-price after a free scoping call — see the full sample quotation format for exactly how the line items break down.
The authorised use of real attacker techniques against systems you own, to find and fix weaknesses before a criminal does. The techniques are identical to a malicious hacker's. The difference is written permission, an agreed scope, and a report that goes to you rather than a dark web marketplace.
Yes — when authorised. Sections 43 and 66 of the IT Act, 2000 make unauthorised access an offence with no exception for good intentions. Authorisation is the whole difference, which is why every engagement starts with a signed authorisation-to-test letter, written rules of engagement and a mutual NDA.
A penetration test is time-boxed and coverage-driven — find as many exploitable issues as possible in a defined scope. A red team engagement is goal-driven and stealth-aware — reach a specific objective while testing whether anyone notices. Most organisations need the pen test first.
Targeted black-box assessments start at ₹22,000. Multi-vector adversary emulation with a phishing simulation starts at ₹48,000. A full goal-oriented red team operation starts at ₹95,000. All fixed-price after a free scoping call.
Black box starts with nothing but your name. Grey box gives us valid low-privilege credentials — modelling the far more common phished-account scenario. White box adds source code and finds the most per rupee. Grey box is the best value for most engagements.
Yes, with written leadership authorisation and in line with your HR policy. We measure click, credential-submission and report rates, and deliver anonymised team-level statistics — never a list of individuals to punish. Results feed straight into targeted training.
Our team works to OSCP-style manual methodology and CEH-aligned engagement structure, and we publish original security research on our research page. We are happy to share tester profiles and redacted sample reports under NDA before you commit.
No. We test only systems you demonstrably own or control and have signed an authorisation letter for. We do not accept work targeting individuals, competitors, ex-partners, or any device or account the requester does not own. Those requests are declined without exception.
Sample quotation, exact pricing, seven-phase methodology and a real finding from a live report.
Read more →The full programme — audits, threat modelling, zero-trust design, compliance and incident response.
Read more →Same skills, two very different paths. An honest look at where ethical hacking careers actually go.
Read more →Free 30-minute scoping call, NDA signed before any detail is shared, and a fixed-price proposal within 24 hours.