OffSeq — short for Offensive Sequence — was founded in 2022 on a simple principle: you cannot reliably defend a system that has never been tested from an attacker’s perspective. Every engagement begins by identifying the paths an adversary could actually use.
We combine deep offensive-security expertise with the regulatory requirements European organizations face. NIS2, DORA and GDPR shape how we test, report and advise.
In 2026, OffSeq became a PECB training partner, expanding our work into internationally recognized ISO and cybersecurity training and certification across Latvia and the EU.
| Founded | 2022 |
|---|---|
| Core services | 28 |
| In-house platforms | 6 |
Principles we operate by
- 01
Attacker-led
We start with the attack paths most relevant to your environment, not a generic checklist.
- 02
Clear communication
Clear findings and candid advice, without fear-based selling or unnecessary jargon.
- 03
Evidence over opinion
Every conclusion is supported by evidence, a severity rating and an assessment of business impact.
- 04
Built for Europe
Our work reflects the regulatory and operational context of European organizations.
On the ground
Certified to international standards
-
OSCP OffSec
-
Lead Pen Test Professional PECB -
ISO/IEC 27001 Senior Lead Auditor PECB -
Certified Information Systems Auditor ISACA -
Red Team Operations Clarified Security
-
Critical Information Infrastructure Protection NATO CCDCOE
-
Web Applications Attack & Defence NATO CCDCOE
-
IT Systems Attack & Defense CybExer
-
Cybercrime CEPOL -
Cyber Bite: Darkweb CEPOL -
OSINT – Cryptocurrencies CEPOL -
Security Awareness: Privileged Accounts SANS
Organizations and networks
Selected clients
We build the tools we use.
Selected offensive-security tools used in our engagements are available to the community as open-source projects on GitHub.
- 01
threat-finder (View on GitHub)
Runtime CVE scanner — finds vulnerabilities in the services actually running on a host, ranked by network exposure.
Rust - 02
threadsrecon (View on GitHub)
OSINT tooling for Threads (threads.net) — profiles, posts and connections.
Python - 03
rockyou-lv (View on GitHub)
Latvian-language password wordlist for cracking and credential audits.
Python - 04
servicediscovery (View on GitHub)
CIDR-aware Nmap scanner — one process per IP, per-host XML output.
Python - 05
xcompare (View on GitHub)
Find mutual followers between two X accounts without the official API.
Python - 06
homebrew-tap (View on GitHub)
Homebrew tap distributing the OffSeq toolset.
Ruby
Strengthening cybersecurity awareness and resilience in Europe
OffSeq participates in EU-funded initiatives that strengthen cybersecurity awareness and resilience by identifying vulnerabilities from an attacker’s perspective and developing proactive monitoring solutions.
Agreement ID: KD/1/24/A/004
Work with a team that tests from an attacker’s perspective
Tell us what you need to protect. We will explain how we would test it and how to strengthen its defenses.