Adversarial Security Testing + Advisory

Know where you stand before an attacker decides for you.

See how attackers get in, how they move, and what your controls actually stop. Senior operators apply manual tradecraft across your entire attack surface, then turn the evidence into decisions your team can act on.

See what holds.
Find what fails.
Fix what matters.
Lares, a Damovo company is a team of senior engineers and security experts who helped define what modern adversarial testing should be. We co-created the Penetration Testing Execution Standard (PTES) and have led thousands of high-impact engagements for teams that care more about outcomes than optics.

Since 2008, Lares has helped organizations protect digital, physical, intellectual, and financial assets through assessment, testing, and coaching.
EVIDENCE OVER ASSUMPTIONS
Solutions What We Test Methods How we Operate Experience Who we are 2008 date_range Company
Established
600+ work_outline Customers
worldwide
4,500+ Adversarial
Engagements

01 / Choose the Outcome

Start with the decision you need to make.

Find the gaps. Test the defenses. Secure AI systems. Strengthen the program. Start with the outcome, then scope only what supports it.

Assess / 01

Know where you stand.

Find exploitable paths and understand their business impact before you commit resources.


External and internal penetration testing


Application security


Cloud security


AI security testing

Explore assessment services →

Validate / 02

Prove your defenses work.

Exercise people, process, and technology against realistic tradecraft. Validate coverage while the evidence is fresh.


Red team testing


Purple team testing


Social engineering


Physical security

See adversarial testing →

Advance / 03

Get stronger every engagement.

Turn findings into a repeatable program, with practical guidance from advisors who work alongside your team.


Advisory and vCISO


IT risk assessment


Continuous testing


AI Governance

Explore advisory services →

02 / AI Security

Secure the systems making decisions on your behalf.

Assess AI risk, define governance, and test the models, agents, infrastructure, endpoints, and SaaS your organization depends on.

01 - AI risk assessment and governance

Translate AI adoption into clear ownership, data boundaries, human approval points, and testable controls.


02 - Chatbot and AI system testing

Move beyond simple prompt injection with hands-on testing across chatbots, agents, and LLM ecosystems.


03 - AI-enabled SaaS application assessment

Evaluate how AI changes application behavior, exposure, and the trust boundaries around enterprise data.


04 - Cloud and endpoint review

Review the AI environment in the cloud and the endpoints where agents run.

Securing ALL Industries

Lares has partnered with the leading organizations in Agriculture, Construction, Education, Financial Services, Government, Healthcare, Hospitality, Legal, Manufacturing, Oil & Gas, Retail, Software, Technology, Telecommunications, Transportation, Utilities, and more.

60+

Financial Institutions

45+

Manufacturing Companies

55+

Software Companies

30+

Insurance Companies

15+

Energy & Utilities

15+

City, State, & Local Government

22+

Law Firms

20+

Retail Companies

Some of Our Delighted Customers

"The expertise and professionalism that Lares' Purple Team brings to the table are unmatched. We will definitely be bringing them back for future engagements."
Benjamin Vaughn
SVP & CISO, Hyatt
"They wanted to see us succeed as much as we wanted to see us succeed. This is why, 10 years later, we are still having this conversation."
Jeffrey Hecht
(Former) Chief Compliance & Security Officer, The Word & Brown Companies
"The biggest benefit of having a Lares vCISO is getting guidance on how to tackle security issues and determining a realistic approach on how to address them."
Andrew Casceillo
Corporate Director of Technical Services, Ulbrich Stainless Steel and Speciality Metals Inc.

CASE STUDY: Word & Brown

Using a culture of security as a baseline, Word & Brown achieved compliance because of its security journey — not in spite of it.

CASE STUDY: Ulbrich Stainless Steels and Speciality Metals

Ulbrich Stainless Steel and Specialty Metals were able to benefit greatly from the services provided by Lares. By engaging with Lares for penetration testing and vCISO services, Ulbrich continues to identify and address vulnerabilities, improve its security posture, and protect their business from cyber threats.

Minnesota Water Attacks and the Predictable Reality

August 12, 2026 by Andrew Heller How possible Iran-linked actors exploited exposed PLCs in the 2026 Minnesota water attacks. MITRE ATT&CK mapping, risk matrix, and OT security lessons from Lares. Read More Blog, Penetration Testing, Purple Teaming, Red Teaming

Part 3: The Collapse of the Testing Boundary: Why Purple Teaming is Mission-Critical

August 7, 2026 by Andrew Heller Point-in-time pen tests can't catch AI agents that fail in minutes. See why continuous purple teaming is the only defense — and how to build the budget case. Read More Artificial Intelligence, Blog, Purple Teaming

Part 2: The Collapse of the Testing Boundary: Anthropic and the Behavioral Threat

August 7, 2026 by Andrew Heller Claude models attacked real infrastructure while believing they were in a simulation. Anthropic's retrospective reveals a new AI risk class beyond alignment. Read More Artificial Intelligence, Blog, Purple Teaming

Part 1: The Collapse of the Testing Boundary: Deconstructing the OpenAI Agent Breakout

August 7, 2026 by Andrew Heller OpenAI's frontier model escaped its sandbox and breached Hugging Face's cluster in under 13 hours. See the full kill chain mapped to MITRE ATT&CK and ATLAS. Read More Artificial Intelligence, Blog, Purple Teaming

Social Profiling – OSINT for Red/Blue

July 27, 2026 by Lares Labs Read More Blog, Penetration Testing, Red Teaming

The Phantom Menace: Exposing hidden risks through ACLs in Active Directory

June 18, 2026 by Raúl Redondo Discover how attackers exploit hidden risks in Active Directory ACLs. Explore techniques like GenericAll, GenericWrite, and WriteDACL abuse in our latest post. Read More Blog, Insider Threat, Penetration Testing, Red Teaming

Kerberos IV - Delegations

June 17, 2026 by Raúl Redondo Discover how to abuse Kerberos for lateral movement. Learn User Impersonation techniques like Pass the Ticket, Shadow Credentials, and forging tickets. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Kerberos III - User Impersonation

June 17, 2026 by Raúl Redondo Discover how to abuse Kerberos for lateral movement. Learn User Impersonation techniques like Pass the Ticket, Shadow Credentials, and forging tickets. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Kerberos II - Credential Access

June 16, 2026 by Raúl Redondo Dive into the fundamentals of the Kerberos authentication protocol. Explore its history, core concepts, authentication flow, and PKINIT in part one of our series. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Kerberos I - Overview

June 16, 2026 by Raúl Redondo Dive into the fundamentals of the Kerberos authentication protocol. Explore its history, core concepts, authentication flow, and PKINIT in part one of our series. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Bring us a question.
Leave with a clear scope. 

Compare notes with a Lares operator on the environment, objectives, and evidence your team needs.

Where There is Unity, There is Victory

[Ubi concordia, ibi victoria]

– Publius Syrus

Contact Lares Consulting logo (image)

Continuous defensive improvement through adversarial simulation and collaboration.

Email Us

©2025 Lares, a Damovo Company | All rights reserved.