In conjunction with

Offensive Security and Continuous Threat Exposure Management

Cenobe is a Greek offensive security firm operating from Athens since 2020, serving public sector bodies, logistics and maritime operators, and digital transformation providers across several countries. It sells penetration testing, red teaming, and continuous threat exposure management rather than compliance-driven scanning, and it holds ISO 27001 certification. In July 2025 the Qualco Group acquired a majority stake of just over 50 percent, folding the firm into a larger technology group while keeping its offensive security practice intact.

The work runs on Cenobe's own platform, sold in three tiers named after Greek mythology. Morpheus performs zero-input external attack surface discovery: subdomain and DNS enumeration, shadow IT detection, and a per-asset exposure score. Nyx tests AWS, Azure, and GCP from both outside and inside, chaining misconfigurations into validated attack paths and covering CI/CD pipelines, containers, and infrastructure as code. Erevos adds manual pentesting and red teaming by human researchers on top of both engines.

Service lines include application, network, and SAP penetration testing, red team and assume-breach exercises, external attack surface management, threat intelligence, GRC consulting, and incident response. Findings are written up as ATT&CK-mapped attack narratives with proof, and reporting maps to DORA, NIS2, and ISO 27001 so security leaders can hand board-level summaries to executives. The platform also ingests third-party scanner output, consolidating results that would otherwise sit across separate point tools. The company also publishes its own vulnerability research, including CVE write-ups covering Black Duck Coverity, GraphQL-Ruby, SAP Crystal Reports, and Apache Tomcat.

Market Segment:

Penetration Testing

Categories:

OP - Penetration Testing