
ארמור אי.טי. אנד סקיוריטי בע"מ מבצעת מבדקי חדירות מורשים, סימולציות תקיפה ותגובה לאירועי סייבר עבור ארגונים בישראל ובעולם. כל פרויקט מתבצע אך ורק תחת כללי התקשרות (Rules of Engagement) חתומים ואישור בכתב מהלקוח, על מערכות הלקוח בלבד, ובהתאם לתורת ההגנה בסייבר 2.0 של מערך הסייבר הלאומי ולתקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017.
Armor IT & Security Ltd. delivers authorized penetration testing, adversarial simulation and incident response for Israeli and international organizations. Every engagement is performed under a signed Rules of Engagement and written client authorization, on the client's own systems only, and in line with the Israel National Cyber Directorate's Cyber Defense Doctrine 2.0 and the Israeli Privacy Protection Regulations (Data Security), 2017.

בדיקות קופסה שחורה, אפורה ולבנה של אפליקציות ווב, ממשקי REST ו-GraphQL, הזדהות וניהול סשן, לוגיקה עסקית ואינטגרציות.
OWASP WSTG · API Top 10משטח התקיפה החשוף לאינטרנט, ציוד היקפי ו-VPN, ולאחר מכן Active Directory, הסלמת הרשאות, תנועה רוחבית וסגמנטציה.
PTES · NIST SP 800-115סקירת תצורה ומסלולי תקיפה ב-Microsoft 365 ו-Entra ID, Azure, AWS ו-Google Cloud: זהויות, גישה מותנית, כיסוי MFA, חשיפת מידע, לוגים והתראות.
CIS Benchmarks · MITRE ATT&CKפרויקטים מבוססי יעד שמדמים תוקף אמיתי מול האנשים, התהליכים והטכנולוגיה, למדידת יכולת הזיהוי והתגובה של הארגון. יעדים ומנגנוני בטיחות נקבעים מראש בכללי ההתקשרות.
MITRE ATT&CK · TIBER-styleקמפיינים מדודים מול עובדי הארגון עצמו, כולל תרחישי גניבת סיסמאות ועקיפת MFA (תוקף באמצע), עם מדדים לכל קמפיין והמלצות המשך.
Social Engineering · AiTMסקירת קוד מקור, תלויות ו-CI/CD עם ממצאים ממופים לקוד; וליווי בבלימה, חקירה והתאוששות מאירועי סייבר, כולל השתלטות על דואר עסקי וכופרה, עם דיווח לפי חוק הגנת הפרטיות.
Secure Code Review · IRBlack-box, grey-box and white-box testing of web applications, REST and GraphQL APIs, authentication and session management, business logic and integrations.
OWASP WSTG · API Top 10Internet-facing attack surface, perimeter devices and VPN, followed by Active Directory, privilege escalation, lateral movement and segmentation testing.
PTES · NIST SP 800-115Configuration and attack-path review of Microsoft 365 and Entra ID, Azure, AWS and Google Cloud: identity, conditional access, MFA coverage, data exposure, logging and alerting.
CIS Benchmarks · MITRE ATT&CKObjective-driven engagements emulating a realistic attacker across people, process and technology, to measure detection and response. Objectives and safety controls are fixed in the Rules of Engagement.
MITRE ATT&CK · TIBER-styleMeasured campaigns against the organization's own workforce, including credential harvesting and MFA-bypass (adversary-in-the-middle) scenarios, with per-campaign metrics and follow-up recommendations.
Social Engineering · AiTMReview of source code, dependencies and CI/CD with findings mapped to code; containment, investigation and recovery support for incidents such as business email compromise and ransomware, with reporting under the Israeli Privacy Protection Law.
Secure Code Review · IRשום בדיקה לא מתחילה לפני שההיקף, ההרשאות ותנאי העצירה חתומים.
ROE חתום: היקף, יעדים, חלונות זמן, מערכות מוחרגות, אנשי קשר לחירום ותנאי עצירה.
הרשאה חתומה של בעל המערכת. צד שלישי נבדק רק באישורו בכתב.
בדיקה בתוך ההיקף בלבד. בלי מניעת שירות, פעולות הרסניות או שינוי מידע בייצור, אלא אם סוכם מראש.
תמצית מנהלים, דוח טכני עם CVSS, ראיות, שחזור והנחיות תיקון, ותוכנית תיקון לפי סיכון.
אימות התיקונים, מכתב סגירה ומפגש סיכום עם ההנהלה והצוות הטכני.
No testing starts before scope, authorization and stop conditions are signed.
Signed ROE: scope, objectives, time windows, excluded systems, emergency contacts and stop conditions.
Signed authorization from the system owner. Third-party systems are tested only with their written consent.
Strictly within scope. No denial of service, destructive actions or production data changes unless agreed in advance.
Executive summary, technical report with CVSS scoring, evidence, reproduction steps and remediation, plus a risk-ranked fix plan.
Verification of fixes, closure letter and a debrief with management and the technical team.
צוות קטן וקבוע. אותם אנשים שמגדירים את ההיקף הם אלה שמבצעים את הבדיקה וכותבים את הדוח.
מוביל את כל הפרויקטים של ארמור מאז הקמתה ב-2019, עם ניסיון רב שנים באבטחת מידע, הגנת פרטיות וביקורת סייבר, כולל הערכת מכרזי סייבר ממשלתיים. אחראי על כללי ההתקשרות, על הבדיקה עצמה ועל הדיווח להנהלת הלקוח.
מאומת ב-Credly · ISC2
בארמור מאז 2018. מוביל סקרי סיכונים, מיפוי מערכות ונכסים קריטיים, ליווי להסמכת ISO 27001 ועמידה ב-GDPR, ואחראי על צד התשתיות במבדקים: רשתות, Firewall, סגמנטציה וסביבות ענן. בוגר הכשרות Certified Network Defender, Check Point CCSA/CCSE ו-Fortinet NSE 4.
A small, permanent team. The people who scope the engagement are the ones who run the test and write the report.
Leads every Armor engagement since founding the company in 2019, with many years in information security, privacy and cyber audit, including evaluation of government cyber tenders. Owns the Rules of Engagement, the testing itself and the debrief to client management.
Verified on Credly · ISC2
With Armor since 2018. Leads risk assessments, system and critical-asset mapping, ISO 27001 and GDPR implementation, and owns the infrastructure side of engagements: networks, firewalls, segmentation and cloud environments. Trained in Certified Network Defender, Check Point CCSA/CCSE and Fortinet NSE 4.
נשמח לתאם שיחת היכרות ולהגדיר יחד היקף, יעדים ולוחות זמנים.
לחץ כאן ליצירת קשרLet's set up an intro call and define scope, objectives and timeline together.
Contact us