Overview
Crimson7 offers offensive security and continuous threat validation services, translating adversary research into operational defense. The company provides offensive engineering, defensive engineering, and managed security services, with specialty products including HackerFlow and 7Hunter.
Key people
In the news
- Nobody broke into Revolut. A compliance team answered an email from a real police mailbox. The mailbox was compromised. The fraudulent emergency data request passed SPF, DKIM and DMARC because the infrastructure was legitimate. Revolut's compliance workflow released the customer data. Our investigation followed what happened next: two actors claiming the breach, two leak domains placed on hold and a public GitHub trail that showed the backup was prepared before the primary domain disappeared. The actor kept committing after the
- Threat intelligence earns its place when it changes what defenders do next. Nick Maeckelberghe and Jeff Schiemann joined this panel at teissLondon2026 to discuss how high-confidence context can reduce false positives and drive active threat hunting. This was not a product session. But the problem sits at the centre of what we build at Crimson7. 7Hunter helps SOC teams turn threat intelligence into structured, repeatable hunts, with the queries, investigation context and runbooks needed to act. HackerFlow takes that same
- Masterclass Theater 2 filled up for our session yesterday, and stayed full to the last slide. The same sentence came up all afternoon, at the session and at the stand: we run an exercise twice a year and have no idea what changed in between. Today is the other end of that loop. Atilla B. and Adriaan Neijzen present "Never Hunt Alone: A Threat Hunting Companion for the SOC" at 12:30 in Masterclass Theater 2. Find us at Hall 11, Stand 11.C015 for the rest of the day. It is the last day of the show. The presentation material goes out
- We’re at Cybersec Netherlands in Jaarbeurs Utrecht tomorrow and Thursday. Find us in Hall 11, Stand 11.C015, or join one of our two live sessions. Wednesday 9 September, 12:30 · Masterclass Theater 2 Always Under Attack: Turning Purple Teaming into Continuous Security Validation. Joey Verleg demonstrates HackerFlow live and shows how to move from periodic exercises to continuous, threat-informed validation against real attacks. Thursday 10 September, 12:30 · Masterclass Theater 2 Never Hunt Alone: A Threat Hunting Companion for
- Ph1shy v2.0.0 went up on BreachForums in June at $500, described as a phishing panel with five features. WebSocket updates, custom templates, multi-server, multi-user, JavaScript execution in the victim's browser. An ordinary PhaaS listing. We cloned the frontend from a live instance and read the JavaScript. No access needed, the panel served its static assets to anyone who asked. The API client carries over 100 endpoint methods across fifteen modules, and ten of those modules appear in no public advertisement. There's a
- When a new attack technique goes public, our clock starts. Within 72 hours we have it running end to end in our system, twice. HackerFlow builds the offensive side: the technique executed against live defenses, chained the way an attacker would chain it, using open-source C2 frameworks and the private tradecraft commodity PowerShell tests never touch. Fileless, in-memory, the parts a vendor demo skips. The output is a gap report: did detection fire, and where. 7Hunter builds the other side on the same clock: MITRE-mapped hunt
- Come meet the Crimson7 team during Cybersec Europe in jaarbeurs Utrecht next month (09 & 10 September). One booth, two talks. More info below
- Cybersec Netherlands · Jaarbeurs Utrecht · 9 & 10 September · Hall 11, Stand 11.C015. Two theatre sessions from our team, working the same loop from opposite ends. Wednesday runs real adversary behaviour against live defences. Thursday hunts for whatever none of it caught. Wed 9 Sep, 12:30 · Masterclass Theater 2 Always Under Attack: Turning Purple Teaming into Continuous Security Validation. Joey shows how HackerFlow turns the annual purple team exercise into something that runs continuously. Threat intelligence in, threat-informed
Related profiles
Something wrong or missing? Send an update. Fixed within 24 hours.






