CRTO Certified Red Team Operator

CRTO Certification

The CRTO (Certified Red Team Operator) is a hands-on certification in the field of red teaming and offensive security. It emphasizes the execution of realistic attack scenarios within Active Directory environments. Participants are required to practically apply various techniques related to post-exploitation and command-and-control (C2) infrastructure. Due to its technical depth and relevance, the CRTO certification is gaining increasing recognition in the industry. Several of our employees hold this certification.

Your advantages with
binsec GmbH

As an owner-managed pentest boutique – staffed by a high-performing team of around 10 experienced senior experts – binsec GmbH has specialized in sophisticated penetration testing for over a decade. We demonstrate our deep roots in the community every day through our own platforms like binsec.tools, binsec.wiki, and binsec.academy. Relevant academic degrees, high-caliber industry certifications, and years of hands-on project experience are what truly matter to us – and how we guarantee a precise, manual analysis for every assessment.

Contact us

More than 10 years of practical experience in penetration testing

No subcontractors or external freelancers

Direct communication with the responsible senior penetration tester

Structured, documented, and reproducible testing methodology based on PTDoc®

Fully controlled in-house pentesting infrastructure, no cloud services used

Local LLMs on own hardware in German data centers

Professional offensive security certifications: OSCP, OSCE, CRTO, BACPP

Identification of technical and business-relevant security risks

Risk-weighted vulnerability assessment or CVSS based scoring

Report including executive summary and detailed technical section

Retesting of identified vulnerabilities included

Your advantages with
binsec GmbH

As an owner-managed pentest boutique – staffed by a high-performing team of around 10 experienced senior experts – binsec GmbH has specialized in sophisticated penetration testing for over a decade. We demonstrate our deep roots in the community every day through our own platforms like binsec.tools, binsec.wiki, and binsec.academy. Relevant academic degrees, high-caliber industry certifications, and years of hands-on project experience are what truly matter to us – and how we guarantee a precise, manual analysis for every assessment.

More than 10 years of practical experience in penetration testing

No subcontractors or external freelancers

Direct communication with the responsible senior penetration tester

Structured, documented, and reproducible testing methodology based on PTDoc®

Fully controlled in-house pentesting infrastructure, no cloud services used

Local LLMs on own hardware in German data centers

Professional offensive security certifications: OSCP, OSCE, CRTO, BACPP

Identification of technical and business-relevant security risks

Risk-weighted vulnerability assessment or CVSS based scoring

Report including executive summary and detailed technical section

Retesting of identified vulnerabilities included

Approach: Standard-Compliant & Reproducible

A penetration test is a structured attack on IT systems or applications to identify potential vulnerabilities. It uses the same tools and techniques that real attackers would use to break into a system. Thus, a penetration test is not an automated vulnerability scan. On the contrary, a penetration test as a service is always a combination of using security tools and conducting manual tests to uncover vulnerabilities. While a real attacker only needs to find and exploit a single vulnerability, a penetration tester checks all relevant attack vectors.

Having a structured approach is one of the most important factors. For this purpose, we use our own platform PTDoc®, a specialized pentest documentation tool that logs all manual testing steps in full compliance with all relevant security standards and translates them into a clear, reproducible report for you. Since this tool significantly reduces the overhead of report generation, it allows us to focus entirely on our core mission as pentesters: identifying and analyzing critical security flaws. That is also true for CRTO certified penetration tester. Our approach is based on all relevant standards and publications.

How We Work
From Planning to Re-Testing

 
 
 
 

Preparations

We coordinate the technical and organisational framework for the penetration test, communication channels, points of contact and testing windows. Depending on the project, this is done through a kick-off meeting or a brief exchange via e-mail. Where required, the client provides relevant technical documentation and access to the systems within scope.

 
 
 
 

Conducting

The penetration test is performed using a structured and risk-oriented assessment approach that combines automated analysis techniques with extensive manual testing. The specific test cases and assessment procedures depend on the actual conditions, technologies and attack surface encountered within the target environment.

 
 
 
 

Reporting

After the assessment, we prepare a detailed report including an executive summary, risk ratings, technical details and remediation recommendations. Findings are documented in a clear and reproducible manner and critical issues are communicated immediately during the engagement if required.

 
 
 
 

Debriefing

We are happy to review the findings and recommendations together with your team. During the debriefing, we explain technical details, potential impacts and remediation priorities, while answering questions and discussing next steps.

 
 
 
 

Re-Testing

After remediation, we verify whether the identified findings have been successfully resolved and update the report accordingly. Re-testing is generally included for remote assessments and provides assurance that the implemented measures are effective.

Getting an Offer for a pentest

Planning a penetration test always requires a careful balance between the time invested in testing and the financial framework to achieve a reasonable price-performance ratio. Successful pentests are characterized by a precise balance between these factors, as this is the only way to guarantee a reliable review of all relevant attack vectors. The time required depends on the size and complexity of the scope. While analyzing a small web application without complex permission structures often takes just a few days, auditing extensive corporate networks can take several weeks.

To provide a tailored pentest offer, we require initial information regarding the systems and applications to be examined, allowing us to accurately assess the target environment. For web applications, providing test credentials is highly beneficial. Any additional technical details, such as the frameworks and technologies utilized, help us design the ideal testing scenario for you. If you require an infrastructure penetration test, we will need the relevant network addresses in advance. In this case, we will first perform a non-invasive network scan to conduct an initial scoping analysis, which forms the basis for your detailed quote.

binsec GmbH is a German pentest company for professional penetration testing. Please get in touch with us if you would like to get a formal quote or if you have any questions. The company binsec GmbH is your pentesting vendor. Get your pentest today!

Contact us
Pentest Offer

Penetration Testing at binsec GmbH

The key questions for anyone commissioning a penetration test – from cost and execution to data protection.

Most companies that regularly perform penetration tests opt for an annual cycle. On one hand, various standards require annual testing; on the other hand, an annual penetration test can be easily integrated into budget planning. Conducting a penetration test every nine months, for example, would be difficult to align with financial planning. A semi-annual schedule — meaning two tests per year — is often too expensive for most.

However, there are companies that conduct penetration tests twice a year, focusing on different aspects each time. From a security and risk management perspective, it would be ideal to perform a penetration test after every significant system change. In practice, however, this often fails due to limited personnel and financial resources.

One possible solution is to establish a framework agreement for penetration testing, often referred to by the buzzword Pentesting as a Service. In this model, recurring tests are performed at defined intervals – for example, quarterly or semi-annually – with the scope adjusted each time to reflect current changes or specific focus areas. This makes it possible to review security-relevant developments on a regular basis without having to initiate a new individual engagement for a full penetration test each time.

The cost of a penetration test depends on scope, complexity, and manual effort – for example the number and type of target systems, the depth of the analysis, and the scope of the report. Because a genuine, manual pentest is individual, we replace blanket hourly rates with a transparent fixed-price quote for your specific target environment.

A detailed, transparent breakdown by scope, method, and effort is available in our article on pentest costs.

Pentest costs in detail →

A penetration test provides more than just technical details. It establishes a reliable basis for understanding and developing IT security as part of overall corporate governance. Organizations benefit on several levels.

  • Transparency: Clear visibility into existing vulnerabilities, the attack surface, and the actual security posture.
  • Prioritization: Structured assessment by risk and impact, enabling targeted allocation of resources.
  • Effectiveness check: Verification of whether existing security controls such as firewalls, WAFs, or endpoint security function as intended.
  • Strategic planning: A solid basis for investment decisions and for further developing the security strategy.
  • Compliance and assurance: Support in meeting regulatory requirements (e.g., ISO 27001, TISAX, NIS2, PCI DSS) and providing objective evidence to customers, partners, or auditors.
  • Response capability: Insights into how quickly and effectively internal teams react to simulated attacks.

The essential benefit is that organizations can assess their security posture not only in theory, but in practice and in a verifiable manner. This enables realistic risk evaluation and well-founded prioritization of mitigation measures.

A common question from clients is: Why does binsec GmbH consistently uncover vulnerabilities in penetration tests that other providers have missed?

The answer is PTDoc – our internal tool for the structured execution and documentation of penetration tests. Developed by binsec systems GmbH and maintained within the binsec group, it was created to address a central challenge: How can quality remain consistently high as the team grows and individual testers have different personal focus areas? And how can we ensure that results are always identical and reproducible, regardless of which senior penetration tester performs the assessment?

PTDoc provides the solution: standardized methodologies for different targets – from Active Directory to mobile applications to networks. Established standards such as the OWASP Testing Guide, MASVS, and OSSTMM are continuously integrated. At the same time, the experience of our testers is embedded in the test steps: new checks are regularly added and made immediately available to the entire team.

In practice, this means:

  • binsec uncovers vulnerabilities that others miss. Over the past years, we have repeatedly identified findings that were overlooked in previous tests.
  • PTDoc relieves binsec’s testers: They can fully focus on executing the test, while documentation, evidence management, and report generation are handled efficiently in the background.
  • Reports are fast and multilingual: PTDoc supports both German and English reporting – and can deliver results in both languages if required.

This is the secret behind binsec pentesting: a systematic approach that combines standards and experience, ensures quality and repeatability – and delivers the decisive difference for clients. One client summarized it this way: “Since working with binsec, I don’t even consider the previous tests from other providers to have been real penetration tests.”

Before a penetration test is conducted, it may be necessary to establish contractual agreements addressing data protection requirements. This ensures compliance with legal regulations (e.g., GDPR) and clearly defines the responsibilities and obligations between the client and the penetration tester. The scope of personal data processing during a penetration test largely depends on the specific objectives of the engagement. The following types of personal data may be processed during a penetration test:

  • Personal Data of One or More Client Contacts

    This typically includes the first name, last name, business email address, business phone number, and position within the company. These personal details are usually stored and processed in email clients, on mail servers, within phone systems, in calendar entries, and in the final penetration test report. It may sound trivial – and in this case, it is – but this information is necessary for communication between client and tester. Such data is always processed and is often publicly available anyway.

  • Personal Data of Other Employees

    When the objective of the penetration test targets the corporate network, contact with employee personal data is often unavoidable. For external penetration tests, this is less common, but for internal tests, especially those involving Active Directory, it is almost inevitable. At a minimum, tester may obtain the names of employees. A common part of internal testing involves attempting to escalate privileges or gain access to additional accounts and systems. If successful – which becomes more likely as the number of employees increases – the tester may obtain valid passwords or at least password hashes. To conduct the test, at least this data must be processed locally on the tester's device. Further escalation, such as account compromise or bypassing access controls, may expose even more information. In the worst-case scenario, such as a full compromise of Active Directory, a large volume of personal data could become accessible. However, it is not necessary to copy this data to the penetration tester's systems – quite the opposite: it should be avoided wherever possible. There is no operational need to do so.

  • Personal Data of the Client’s Customers

    Personal customer data may be encountered when production systems are tested. A straightforward example is an online store. Securing customer data in such systems is a primary goal of penetration testing. Part of the test is to determine whether it is possible to gain unauthorized access to customer records. If successful, individual customer data entries may be temporarily displayed and thus processed locally on the tester’s device.

In the latter two cases, it may be advisable to conclude a data processing agreement (DPA). The focus should always be on the principle of data minimization. A penetration tester is – obviously – not a malicious attacker, and there is no need to process significant volumes of personal data. Only for reporting purposes is it necessary to find a reasonable compromise between anonymization and pseudonymization. For example, if login credentials are successfully obtained during the penetration test, they must be included in the report to provide the client with the relevant information. However, these credentials should not be linked to specific individuals.

Penetration tests generate sensitive information: technical details about systems, configurations, vulnerabilities, user accounts, and internal structures. It is therefore essential to define not only where but also how this data is processed.

All processing takes place within a controlled, self operated infrastructure in Germany. Operations run from a data center in Frankfurt am Main and are complemented by a physically separate hot standby location to ensure redundancy and high availability. Project data is not processed in public cloud environments and is not transferred to unspecified third countries.

Own IPv4 and IPv6 address space is operated. As a Local Internet Registry, an independent network and routing infrastructure is maintained using enterprise hardware including Juniper networking components. Hypervisor and storage systems are fully operated under direct technical control.

Project data is handled exclusively within dedicated, segmented systems. Access is strictly role based and limited to the senior penetration testers involved in the respective engagement. Collected data typically includes:

  • technical test notes and analyses
  • screenshots and evidences
  • draft and final reports

All laptops used are fully encrypted. Project data is deleted locally from tester systems after completion. Central documentation and management of all findings takes place exclusively within PTDoc as the controlled core system. This combination of self operated infrastructure, strict access separation, encrypted endpoints and structured documentation processes ensures that data processing remains controlled and traceable.

binsec GmbH: Professional Penetration Testing
Your pentest experts!

binsec GmbH is your owner-operated boutique firm for professional penetration testing.

Talk directly to the executing experts instead of sales consultants. Better pentesting. No nonsense. As a dedicated penetration testing firm, we do things differently: We do not sell automated vulnerability scans as a true pentest, focusing instead on manual analysis of complex business logic flaws. Looking for a professionally conducted penetration test? Let's discuss your project.

Contact us

Frequently Asked Questions

Of course. Please contact us for a pentest example report.

It is difficult to give an generalized answer to this question, since the toolset used basically depends on the respective test object. Of course, we use tools such as nmap to check IT infrastructures or the Burp Suite Professional in the case of web applications.

However, we believe that publishing a tool list is mere window dressing, as each target system should be tested individually. However, you are welcome to ask us about the tools we used after the pentest.

If you fix the vulnerabilities within a reasonable amount of time, we would be glad to retest at no additional cost.

Hosting critical business applications on a cloud provider such as Amazon AWS, Microsoft Azure, Google Cloud Hetzner Cloud or STACKIT Cloud is becoming increasingly common.

Of course we perform penetration tests for applications hosted in the cloud. This also applies to penetration testing of cloud-based IT infrastructures, provided that the virtual machines are not managed directly by the cloud provider.

There are three approaches based on the information a penetration tester gets before starting: Black-Box-Pentest, Grey-Box-Pentest and White-Box-Pentest. We always recommend going for grey box pentesting. It has the best cost-benefit ratio if you like to get your complete attack surface tested.
Of course, we also offer Red Teaming. Basically Red Teaming is a subcategory of pentesting with a very strong focus on unstructured Ethical Hacking.

We perform penetration tests for almost any IT environment, system, application or network – right down to protocol fuzzing. Only the analysis of hardware chips under a microscope is something we leave to others.

Typical targets of our penetration tests include:

Web Applications and APIs

Mobile Applications

Servers, Platforms and Infrastructure

Containers and DevOps

Identity and Authentication

Pentest Knowledge and Tools

Free pentest tools for your security analysis.

Pentest Tools

Take a look at our wiki page about pentesting.

Pentest WIKI

Straight answers to common pentesting questions.

Pentest FAQ

News about pentesting and the binsec universe.

Pentest News

Company

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorised Officer: Florian Zavatzki, Dominik Sauer
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808

© 2026 binsec GmbH. The operative core enterprise of the binsec group. Your specialized penetration testing service provider.

© 2026 All rights reserved by binsec GmbH.