Skip to main content
own2pwn

Pentest. Build the tools that were missing.

own2pwn is THE HIVE: the tools I'd have wanted as a pentester.

On the services side: black-box and white-box web pentests, which I run myself. On the product side: an EASM platform for external attack surface, and an AppSec suite that extends a human-led audit between engagements.

Continuous, contextual, actionable pentesting.

In most organisations, pentesting is still a one-shot event: an annual audit, a report that gathers dust in a drawer, and a six-to-twelve-month gap between two offensive perspectives. That gap is exactly where regressions creep in.

My goal: make offensive testing reproducible between two engagements, without rerunning a full audit at every release.

That's what both own2pwn products aim to do. EASM keeps your exposed-asset inventory up to date. SecAI analyses your code continuously, on every commit, and flags regressions between audits. Human engagements stay where they're worth their cost: exploitation, architecture review, contextual judgement.

AI is used to reduce noise (false positives, non-exploitable findings) and to draft reports. The final call, qualifying, prioritising, writing the client-ready version, always goes through a human operator.

The principles behind every product.

Offensive rigor

My personal commitment: test like an attacker, document like an auditor. No cosmetic checklists, no unreproducible findings.

Transparency

Detailed reports with proofs of exploitation, justified CVSS scores, concrete remediation plans. No black boxes, you understand every finding.

Sovereignty

Code, data, and hosting in the EU. Native GDPR compliance. Your pentest results stay strictly confidential.

Useful automation

AI isn't a marketing gimmick: I use it to cut false positives, prioritise by real exploitability, and focus my time on what requires human judgement.

Three pillars, one offensive approach.

EASM

Continuous mapping of your external attack surface. Forgotten-asset discovery, CVE detection, real-time alerts.

AI-Native AppSec

Contextual taint-based SAST, SCA, IaC and secrets, automated reports. A continuous static-analysis platform for application security.

Web Pentesting

Black-box and white-box audits delivered by an OSWE-certified pentester. Actionable reports, retest included.

What exists, and since when.

Q1
2025

Genesis

A field-driven realisation: too many false positives, too many non-actionable findings, too much overlooked attack surface. own2pwn starts here, with the first lines of the site and tooling written for my own use.

Q1
2026

The pentest offering

Black-box and white-box web pentesting becomes a formalised offering: scope agreed in writing, methodology, two-level report with PoC and CVSS, retest included, and published day rates on a market where nobody shows a figure.

Q2
2026

Building EASM

Writing the EASM engine: multi-source discovery from a single root domain, detection catalogue, CVE correlation and CISA KEV / EPSS prioritisation.

Q3
2026

EASM in production, SecAI in pre-launch

EASM runs in production on easm.own2pwn.fr. SecAI, the AppSec suite (taint-tracking SAST, SCA, IaC, secrets), is in pre-launch: static analysis only, no DAST and no replay against a live target.

Author

THE HIVE, one offensive operator, founder of own2pwn.

Pentester by trade, OSWE-certified. I founded own2pwn to bring defensive tooling closer to real-world offensive practice: you don't build a strong security product without having broken systems yourself.

own2pwn is published by THE HIVE, a French single-shareholder company. A deliberately minimal structure, and that is the point of the offering: every engagement, every line of code, every report goes through the same person, the one who signs it.

CertificationOSWE

Test your defences, continuously.

Discover EASM or talk to us directly about your pentest needs.