Volkis @volkis.au · 19hCurious about what our pentest reports actually look like? 📄 Thanks to some awesome clients, we've published real, sanitised sample reports so you can see exactly how we document findings and remediation.👇 100
Volkis @volkis.au · 30/09/2026When "just one quick exploit before bed" turns into a 1 AM drink-tasting panel. 001
Volkis @volkis.au · 27/09/2026Solid prep up front prevents accidental downtime, avoids scope surprises, and extracts maximum value from your engagement. Read our full pre-engagement guide 👇 100
Volkis @volkis.au · 27/09/2026Next, system prep on your end before testing starts: • Back up all systems prior to the test starting • Tell us about any known issues or planned fixes so we can scope around them properly • Ensure you have permission from any affected third parties for our testing. 100
Volkis @volkis.au · 27/09/2026What do the consultants need? • Scope Confirmation: We re-verify scope 1 week prior so we test strictly what you own • Contacts: A Business lead for progress updates + a Tech lead on standby for system context • On-site setup: If in person, just a desk, chair, and ethernet 100
Volkis @volkis.au · 27/09/2026A successful pentest relies on clear communication and solid environment prep before the first packet hits the wire. Here’s the pre-flight checklist we walk through with clients before hitting "Go"👇 110
Volkis @volkis.au · 24/09/2026volkis.com.auIndependent Australian offensive cyber securityWe are a bunch of hackers that can help you find out where you're vulnerable, how to improve, and how to protect your customers and your systems, helping you concentrate on running your organisation without interruption. 000
Volkis @volkis.au · 24/09/2026Fresh updates are live on our site, and we couldn't wait to share them with you! We’ve polished up a few things to make finding what you need even easier. Many more changes to come! Check them out 👇 100
Volkis @volkis.au · 16/09/20267 years ago, Alexei set out to build a security consultancy grounded in empathy, transparency, and doing things the right way. Thank you for leading us with genuine kindness, passion, and curiosity, and for everything you do for the team. Happy Volkisversary, boss! 🐺 010
Volkis @volkis.au · 11/09/2026imperva.comCopyEscape: Taking Over Docker Hosts with docker cp | ImpervaImperva Red Team uncovered CVE-2026-17106, a container-to-host arbitrary file-write vulnerability in Docker’s docker cp command. Docker later confirmed that the same CVE also affected sbx cp when copying files out of Docker Sandboxes. A malicious container or sandbox could exploit the copy process to create or overwrite files outside the destination selected by the user, […] 000
Volkis @volkis.au · 11/09/2026A vulnerability in docker cp (and sbx cp in Docker Sandboxes) that allows a malicious container to escape its filesystem boundary and overwrite arbitrary files on your host machine. Check out the full Imperva write-up below👇 110
Volkis @volkis.au · 11/09/2026Ever run docker cp to pull logs, build artifacts, or test results out of a container? You might want to double-check your Docker version. Imperva published details on CopyEscape (CVE-2026-17106). 110
Volkis @volkis.au · 10/09/20263. Training and mentoring: A pentest shouldn't end the moment we deliver a PDF. We sit down with your team, walk through remediation, and help close the gap so vulnerabilities don't come back. 110
Volkis @volkis.au · 10/09/20262. Context over templates: Your business isn't a copy-paste of the next one. We tailor findings and risk ratings to how your operations actually run, instead of dropping a generic report template on your desk. 100
Volkis @volkis.au · 10/09/20261. Support from the team: Nobody knows every tech stack or niche tool. Work with us and you don't just get one tester, you get our whole team backing them up, sharing context, and double-checking findings in real time. 100
Volkis @volkis.au · 10/09/2026When you book a pentest, the obvious value comes from the consultant digging into your systems. But what does the company behind them bring to the table? Is it just scheduling and an invoice, or does it make the test better? Here's where we reckon a consultancy earns its keep👇 110
Volkis @volkis.au · 08/09/2026Most of the time, a misconfiguration lets us request a certificate for a privileged account. Pass-the-Cert authenticates as them for Domain Admin, and Pass-the-Hash gets us everywhere after that. 100
Volkis @volkis.au · 08/09/2026In an engagement, we phished creds, snuck into a public bathroom below their office and hid a device. From that first foothold to complete network control took less effort than the phishing and the sneaking. 101
Volkis @volkis.au · 02/09/2026Volk the Siberian Husky bypasses firewalls differently. He just runs straight through it 🐺 000
Volkis @volkis.au · 02/09/2026Firewalls don't get "broken through." Attackers just make malicious traffic look legit using protocols the firewall already trusts, or slipping through blind spots where it only sees part of the network path. 100
Volkis @volkis.au · 30/08/2026Happy Birthday to our Senior Security Consultant, Nathan! 🥳 Whether he’s performing network and web app pentests or running security reviews, Nathan brings incredible skill and genuine kindness to everything he does at Volkis. 000
Volkis @volkis.au · 26/08/2026handbook.volkis.com.auVolkis goodies · Volkis HandbookThe Volkis Handbook. 000
Volkis @volkis.au · 26/08/2026Wallpapers, T-shirt designs, and other bits with the Volkis wolf on them. We put it all in one spot. 🐺👇 100
Volkis @volkis.au · 24/08/2026volkis.com.auWe’re here to help. Let’s chat!A dedicated cyber security consultancy that provides penetration testing, security strategy, GRC, training, social engineering, and red team services. 000
Volkis @volkis.au · 24/08/2026We reckon most orgs are weaker than they think. Book a call and find out where you stand 👇 100
Volkis @volkis.au · 24/08/2026This chart is from a real engagement: it's how one of our clients scored across all eight controls, sector by sector, maturity level by maturity level. 100
Volkis @volkis.au · 24/08/2026How mature is your Essential 8 actually? Not what the checklist says but what an attacker would find. 100
Volkis @volkis.au · 13/08/2026On a late night flight to Greece, Alexei kept playing with it. "Volk Security"? No. "Volk IS" (Information Security)? No. Volk + IS. Volkis. Unique, and the domain was available! 🐺 Bonus: "Volk" means wolf in Russian. Fitting for an offensive security firm 000
Volkis @volkis.au · 13/08/2026Where does "Volkis" come from? True story. Matt and Alexei were brainstorming names while Alexei was in Europe. Matt suggested "Volk," after Alexei's dog. Close, but not quite. 100
Volkis @volkis.au · 10/08/2026We are honest and transparent with ourselves, our clients, and the wider community. A philosophy at Volkis is to be "open but secure". We make information public by default unless its under NDA, or could be damaging. 000
Volkis @volkis.au · 06/08/2026We're hearing a lot about how AI-generated pentest reports and hallucinated findings are plaguing our industry. What do we bring? Trust! The words in our reports are our own. Putting our name on it means we stand by every word and present something you can trust. 000
Volkis @volkis.au · 05/08/2026Happy Birthday to the big boss, Alexei! 🐺 As one of the two founders who made Volkis possible, thank you for inspiring and leading us with kindness and genuine curiosity to give the best of ourselves 000
Volkis @volkis.au · 03/08/2026We are open and transparent about how we work and what you'll get working with us. We prioritise communication because it's the key to success. The goal is improving your security and helping you protect your customers and yourself, not just a long report. 100
Volkis @volkis.au · 03/08/2026We're a "what you see is what you get" organisation. You can see our methodologies, sample reports, hiring criteria, even our internal policies and processes on our handbook. 100
Volkis @volkis.au · 03/08/2026We started Volkis because we wanted to raise the bar for security consulting. Find more, do better, and get our clients real outcomes. 100
Volkis @volkis.au · 03/08/2026We are Volkis. A group of hackers, Australian, independent from the big players, all local. We are dedicated to offensive security. We love it and we do it well. 110
Volkis @volkis.au · 30/07/2026Meet the operator, Nathan Jarvie, our Senior Security Consultant. He's a hacker with deep hands-on experience, and he's chasing every certification he can get his hands on. 13 certifications in cybersecurity so far, with more on the way. 000
Volkis @volkis.au · 24/07/2026volkis.com.auWhat we doA dedicated cyber security consultancy that provides penetration testing, security strategy, GRC, training, social engineering, and red team services. 000
Volkis @volkis.au · 20/07/2026To support this goal, we aim to follow six values: - Empathy - Learn and grow - Supporting each other - Giving back to the community - Transparency - Independence We don't hide who we are or how we operate. 010
Volkis @volkis.au · 20/07/2026Our goal is simple: to keep the people around us safe, whether they are our staff, friends, family, or clients. 100
Volkis @volkis.au · 20/07/2026When everything is moving fast, you need to know that the professionals handling your security actually have a compass, ethics and principles that don’t shift depending on who is paying the bill. 120
Volkis @volkis.au · 20/07/2026With the threat landscape feeling a bit chaotic lately, we reckon it's time to bring that back. 100