Now offering free 30-minute scoping calls
C2Recon

See what the hacker sees — before they do.

Red Team Recon looks at your company the way an attacker would — what's visible from the outside, the ways in — and hands you the fix list before someone else uses it.

Book a free scoping call

See exactly what you get — a real 11-page sample with real findings and a ranked fix plan.

$1,500 fixed · Full report in 10 business days

01 / WHAT ATTACKERS CAN ALREADY SEE

Common findings from an outside-in assessment:

Anyone can send email as you

Missing email protections let scammers send invoices and payment requests that look like they came from your domain.

A lookalike domain is already registered

A domain one letter off from yours can be used to impersonate you to customers, vendors, and your own staff.

A forgotten system is still online

Old staging sites and remote-access logins stay visible long after everyone forgets them — and attackers scan for them daily.

Typical examples.

02 / WHO THIS IS FOR

Startups (10–50 people) at a moment where security suddenly matters:

An enterprise customer’s security review holding up a deal

Cyber-insurance application or renewal

Fundraising due diligence or an early SOC 2 push

03 / WHY NOT JUST A SCANNER?

Automated scanners check boxes. I think like the person trying to get in.

  • An adversary’s perspective, backed by 5 years in cyber threat intelligence.
  • Human-reviewed findings — no 200-page PDF of false positives.
  • A fix plan ranked by risk, not alphabetically.
04 / SERVICES

Two tiers, one standard of work.

Tier 1 · Available now

Tier 1 — Recon: the looking, not the breaking in

If I were an attacker targeting your company, this is what I’d see — and this is how I’d get in.

  1. 01

    Passive recon — OSINT, external asset discovery, exposed credentials, lookalike/typosquat domains — drawn from public sources, so it needs no permission.

  2. 02

    Active recon — Port scans, service enumeration, vulnerability identification on your public-facing infrastructure. Looking, never breaking in. Runs under a simple one-page written authorization you sign before we start.

  3. 03

    Human-reviewed — Findings are reviewed by a human analyst (me) and ranked by actual risk to your business. Not an automated scan dump.

  • Fixed price
  • Full recon report in 10 business days
  • Ranked fix plan — what to fix first and why
  • 45-minute walkthrough of the findings
  • 90-day re-check
Book a free scoping call
Tier 2 · Coming soon

Tier 2 — Full red team operations: coming soon

Authorized, scoped operations that go beyond recon — exploitation, tested end to end, with formal rules of engagement.

05 / HOW IT WORKS

Four steps, one fixed price.

STEP 1

Free scoping call

STEP 2

Assessment

STEP 3

Report + walkthrough

STEP 4

90-day re-check (included)

06 / PRICING

Red Team Recon — $1,500, fixed.

Introductory pricing for our first clients.

Includes report, walkthrough, and 90-day re-check. Report within 10 business days of kickoff.

Looking, never breaking in · Written authorization · Findings go only to you · Working data deleted within 30 days

Alex Stafstrom
07 / ABOUT

Hi, I’m Alex.

I’m Alex Stafstrom, a cybersecurity professional with 10+ years in the field, including threat intelligence and reconnaissance work.

08 / GET IN TOUCH

What’s driving your timeline? Tell me and I’ll reply within one business day.

Prefer to talk? Call or text (978) 300-2085