Covenant Cyber

Securing the World
Melbourne, Australia — Offensive Security

Adversarial Security.
Intelligence-Led.

Covenant Cyber delivers elite offensive security, governance and AI-augmented assurance. Every engagement is executed by senior certified operators — never juniors learning on your environment.

OSCE3-certified operators
Continuous, not point-in-time
100% Australian owned & operated
OSCE³
Expert-Level Certified
500+
Engagements Delivered
100%
Human-Validated Findings
24/7
Continuous Attack Surface
Why Test

Outcomes, Not Output

A test that hands you a scanner dump has told you nothing. Every Covenant Cyber engagement is built to answer four questions your board actually cares about.

Verify Posture

Prove your existing controls actually work under real attack conditions — not just on paper or in a vendor datasheet.

Identify Exposure

Pinpoint the specific, exploitable weaknesses a motivated threat actor would use to reach your crown-jewel data.

Unlock Remediation

Receive prioritised, engineer-ready guidance ranked by genuine business risk — so your team fixes what matters first.

Uplift Security

Measurably improve your posture engagement over engagement, with retest validation confirming every fix landed.

Our Expertise

Cyber Security Services

Designed to dissolve ambiguity and manage real risk — from adversary simulation and continuous AI-driven testing through to governance, compliance and physical security.

AI Continuous Penetration Testing

Always-On Assurance

An annual pentest tells you how secure you were on one week of one year. Modern environments do not hold still — code ships daily, cloud resources appear hourly, and your attack surface drifts constantly. Our AI-augmented platform tests continuously against that moving target, while senior operators direct where it goes deep and validate every finding before it reaches you.

  • Continuous discovery and monitoring of your external attack surface
  • Automated exploitation chains re-run on every material change
  • Real-time alerting when new exposure appears — not next quarter
  • Every finding human-validated by a certified operator, zero false-positive dumps

Penetration Testing

Manual Depth, AI-Supplemented

Deep, hands-on manual testing across networks, web applications, APIs, mobile and cloud — the kind of work that finds broken authorisation logic, chained privilege escalation and business-logic abuse that no scanner will ever surface. We supplement that human tradecraft with AI for breadth, so coverage is never limited by the arithmetic of billable hours.

  • External and internal network infrastructure, including assumed-breach scenarios
  • Web applications, APIs and thick clients — black, grey or white box
  • iOS and Android mobile applications, including backend API and storage review
  • Authenticated multi-role testing to expose IDOR and privilege-boundary flaws

Red Teaming

Full-Scope Adversary Simulation

A penetration test asks “what is vulnerable?”. A red team asks “can a determined adversary achieve their objective — and would you even notice?”. We emulate the tradecraft of real threat actors against agreed objectives, operating covertly across your people, process and technology to test detection and response as much as prevention.

  • Objective-based engagements mapped to MITRE ATT&CK adversary TTPs
  • Initial access via phishing, social engineering or exposed perimeter services
  • Covert C2, evasion, lateral movement and domain privilege escalation
  • Purple team collaboration and detection-gap analysis with your SOC

AI Cloud Configuration Review

AWS · Azure · GCP

Most cloud breaches are not exotic exploits — they are a permission that was too broad, a storage bucket that was never meant to be public, or an identity role nobody has reviewed since it was created. We combine AI-driven analysis across your entire tenancy with expert validation and controlled exploitation, so you learn which misconfigurations are genuinely reachable and which are noise.

  • IAM, identity and privilege-escalation path analysis across the full tenancy
  • Storage, network, secrets and key-management exposure review
  • Kubernetes, container and serverless workload hardening assessment
  • Benchmarked against CIS, Essential Eight and cloud provider baselines

GRC & Risk Assessments

Governance, Risk & Compliance

Technical testing tells you where you are broken. Governance tells you why it happened and what stops it recurring. We assess your control environment against the frameworks your regulators, insurers and enterprise customers actually ask about, then translate technical risk into the commercial language your executive and board need to make funding decisions.

  • Cyber risk assessments and security maturity benchmarking
  • ISO 27001 ISMS implementation and audit readiness
  • Essential Eight, NIST CSF 2.0, SOC 2 and APRA CPS 234 alignment
  • Policy and framework development, third-party risk, vCISO advisory

Physical Security Audits

On-Site Assessment

Every digital control you own can be undone by someone who simply walks through the door behind a helpful employee. We test your physical perimeter the way an intruder would: discreetly, opportunistically, and with a clear objective. Findings are evidenced with photographs and access logs so there is no argument about what was possible.

  • Tailgating, social pretexting and reception bypass attempts
  • RFID and access-badge cloning, lock bypass and door-control weaknesses
  • Rogue device placement, network drop testing and clean-desk review
  • Server room, comms cabinet and secure area access validation

CI/CD & Pipeline Security

DevSecOps & Supply Chain

Your build pipeline holds the credentials to production, and it is frequently the least-tested system in the business. Compromise it once and an attacker owns every future deployment. We audit the whole chain — source control, runners, secrets, registries and deployment identity — to find the path from a pull request to production compromise.

  • Pipeline and runner privilege review across GitHub Actions, GitLab CI, Azure DevOps
  • Secrets management, credential sprawl and hardcoded key discovery
  • Container image, registry and dependency supply-chain analysis
  • Infrastructure-as-Code review and secure SDLC gate integration

Security Strategy & Advisory

Architecture & Consulting

Testing without a strategy produces a treadmill of findings you never get ahead of. We work alongside your leadership to build a security roadmap grounded in your actual threat model, budget and risk appetite — then help you execute it, from architecture decisions through to incident response readiness.

  • Security architecture and design review for new or migrating platforms
  • Threat modelling workshops and multi-year uplift roadmapping
  • Incident response planning and tabletop exercises
  • Security awareness training and phishing simulation programmes
Areas of Expertise

Full-Spectrum Coverage

Whatever your environment is built on, we have tested it before — and we scope to the risk that actually applies to you.

External Network
Internal Network
Web Applications
Mobile Applications
APIs & Web Services
Wireless Networks
Cloud Infrastructure
Source Code Review
Social Engineering
Active Directory
Build & SOE Review
Physical Premises
AI-Augmented Delivery

Offensive AI, Under Command

Most penetration tests sample. Not by choice, but by arithmetic — there are only so many hours in a scope, and a tester must choose which of your two hundred endpoints to examine properly. The client assumes coverage. The tester knows it was sampled.

We close that gap. Our AI tooling covers the ground exhaustively — every role, every workflow, every host in scope — while a senior operator decides what matters, steers the engagement throughout, and validates every single finding before it reaches your report. Fully autonomous tools plateau into volume without insight. Ours does not run unattended.

  • Coverage that isn't limited by available hours. Breadth is handled by machine; depth is directed by an expert.
  • 100% human-validated findings. A named operator stands behind every issue — you never receive a triage queue.
  • Australian data handling. Engagement data stays onshore and is never used to train third-party models.

“The machine covers the ground. The operator decides what matters.”

— Covenant Cyber delivery principle

Built, Not Bought

Our tooling is developed and tuned in-house by the same operators who run your engagement — not a resold vendor scanner.

Expert-Piloted

A senior operator directs the engagement end to end. Not scoping at the front and reviewing at the back — steering throughout.

Live Reporting

Findings appear as they are validated, throughout the engagement — not in a PDF three weeks after we finish.

Sovereign by Design

Isolated engagement environments, controlled egress, full action logging, and all data processed in Australia.

How We Work

A Transparent Engagement

No black boxes and no radio silence. You know what we are doing, what we have found, and what it means — while the engagement is still running.

01

Scoping & Threat Modelling

A senior operator — not a salesperson — runs a working session to map your attack surface, understand what would genuinely hurt your business, and tailor scope to real-world risk rather than a template.

02

Testing & Live Reporting

Findings land on a live dashboard as they are validated. You can raise questions, request clarification and start remediating critical issues immediately — directly with your tester.

03

1-on-1 Debrief

A personal walkthrough of every finding, framed against your environment, your business impact and your compensating controls — for engineers and executives alike.

04

Reporting & Retest

A report with full technical detail, steps to reproduce, risk ratings and prioritised remediation. Complimentary retesting confirms your fixes actually closed the gap.

Leadership

Senior Operators.
Proven Credentials.

Covenant Cyber was founded on a straightforward premise: the person testing your environment should be the most capable person we have, every single time. There is no delivery pyramid here, no junior consultant learning the trade on your production systems, and no offshore handoff.

The practice is led by Tim Lepp, who holds OffSec's OSCE³ — the combined achievement of the OSWE, OSEP and OSED certifications, three of the most demanding expert-level exams in offensive security, covering advanced web exploitation, evasion and adversary simulation, and exploit development respectively — built on the OSCP foundation.

That depth is backed by advanced red team, wireless and exploit-development credentials, and by more than 500 engagements delivered across finance, healthcare, government-adjacent and critical infrastructure environments. When we tell you something is exploitable, we have exploited it.

Certifications Held
OSCE³ OSWE OSEP OSED OSCP OSWP CRTO PNPT CORELAN
TL
Tim Lepp
Founder & Principal Operator

Offensive security specialist with deep expertise in exploit development, advanced web application exploitation, red team operations and adversary simulation.

Holder of the OSCE³ — OffSec's expert-level trifecta — alongside CRTO for red team operations and Corelan for advanced exploit development. Focused on building an Australian consultancy where clients deal directly with the operator who did the work, and where AI extends coverage without ever replacing expert judgement.

Specialisations
  • Exploit development and binary exploitation
  • Advanced web and API exploitation
  • Red team operations, C2 and evasion
  • Cloud and identity attack paths
  • AI-augmented offensive tooling
Our Strength, Your Advantage

Why Covenant Cyber

We are deliberately not the largest consultancy in the market. We are built to be the one you actually want holding your findings.

Senior-Only Delivery

Every engagement is run by an operator holding expert-level certification and years of real offensive experience. No graduates, no outsourcing, no delivery pyramid absorbing your budget.

AI-Augmented Depth

We use AI to eliminate the sampling problem, not to cut corners. Machine breadth plus operator judgement means broader coverage and deeper findings in the same window.

Direct Access

You talk to the person testing your systems, not an account manager relaying messages. Questions get answered by someone who has their hands on your environment.

Locally Resourced

Australian owned and operated from Melbourne. No timezone friction, no offshore data handling, and full alignment with local regulatory and privacy obligations.

Reports People Read

Findings written for both engineers and executives — reproducible technical detail, honest severity ratings, and remediation advice that makes sense in your context.

Integrity First

We will tell you when a control is working, when a finding is low risk, and when you do not need the engagement you asked for. Trust is the product.

Frameworks & Standards

Aligned to What You're Audited Against

Assessments mapped to the frameworks your regulators, insurers and enterprise customers require.

ISO/IEC 27001
ASD Essential Eight
NIST CSF 2.0
SOC 2 Type I & II
APRA CPS 234
APRA CPS 230
SOCI Act
PCI DSS 4.0
OWASP ASVS
OWASP MASVS
MITRE ATT&CK
CIS Benchmarks
Privacy Act / APPs
Consumer Data Right
PTES / OSSTMM
NIST SP 800-115
Common Questions

Before You Engage

Straight answers to what clients ask us most.

What is penetration testing, and why do we need it?

A penetration test is a controlled simulation of a real-world attack against your systems, applications and infrastructure. Rather than listing theoretical weaknesses, we attempt to exploit them — proving which issues genuinely put your business at risk. The result validates that your existing controls work, and gives you prioritised, actionable guidance to close the gaps that matter before a real attacker finds them.

How is AI continuous testing different from a traditional pentest?

A traditional pentest is a deep, point-in-time assessment: it tells you your security posture during the week it was performed. Continuous testing runs against your environment permanently, re-testing as code ships and infrastructure changes, so new exposure is caught in days rather than at your next annual engagement. They are complementary — continuous testing maintains baseline assurance and catches drift; a manual engagement provides the depth that finds complex logic and privilege-boundary flaws. Most mature clients run both.

What's the difference between a penetration test and a red team engagement?

A penetration test aims for breadth of coverage within a defined scope, answering “what is vulnerable and how badly?”. A red team engagement is objective-based and covert: we pick a goal a real adversary would pursue — domain compromise, access to a specific dataset, fraudulent transaction — and pursue it using realistic tradecraft while your team attempts to detect us. Pentesting tests your prevention; red teaming tests your detection and response. If you do not yet have a functioning SOC or monitoring capability, a pentest almost always delivers better value first.

Will testing disrupt our production systems?

No. Engagements are safe, controlled and coordinated closely with your team. Rules of engagement, testing windows, out-of-scope systems and escalation contacts are agreed in writing before we begin. Any potentially disruptive technique — denial-of-service testing, destructive exploitation, aggressive fuzzing — is excluded by default and only performed with explicit written authorisation, typically against non-production environments.

Does a GRC assessment replace technical testing?

No — they answer different questions. GRC assesses your governance, policies, processes and control frameworks: whether you have the right structures in place and can demonstrate them to an auditor. Technical testing proves whether those controls actually hold up against an attacker. Governance complements technical assurance but never replaces it; plenty of ISO 27001-certified organisations have exploitable perimeters.

How often should we test?

At minimum annually, and additionally after any significant infrastructure change, major application release, merger or security incident. High-risk environments, regulated entities and organisations shipping frequently should test more often — which is precisely the gap continuous testing is designed to fill.

What do we receive at the end of an engagement?

A comprehensive report covering every finding with clear severity ratings, full steps to reproduce, supporting evidence and specific remediation guidance — written to be useful to your engineers and intelligible to your executive. That is accompanied by an executive summary suitable for board reporting, a one-on-one debrief session, and complimentary retesting to verify your remediation succeeded.

Is our data kept in Australia?

Yes. Covenant Cyber is Australian owned and operated, and engagement data is processed and stored onshore in isolated environments with controlled egress and full action logging. Client data is never used to train third-party AI models — not anonymised, not aggregated.

No Cost, No Obligation

Free External Asset Check

Let us show you what an attacker sees. We will map your internet-facing attack surface, identify exposed services and highlight any critical risks — then walk you through the results. No engagement required, no sales pressure.

Request Your Free Scan
External attack surface mapping
Exposed service & misconfiguration review
Walkthrough with a senior operator

Prefer email? Reach us directly at info@covenantcyber.com.au