ARMOR

מבדקי חדירות ורד טים

Penetration Testing & Red Team
בדיקות מורשות בלבד · כללי התקשרות חתומים · בהתאם לתורת ההגנה 2.0 של מערך הסייבר הלאומי

Penetration Testing & Red Team

Authorized offensive security services
Authorized testing only · Signed Rules of Engagement · Aligned with INCD Cyber Defense Doctrine 2.0
ARMOR IT & SECURITY LTD.

על השירות

ארמור אי.טי. אנד סקיוריטי בע"מ מבצעת מבדקי חדירות מורשים, סימולציות תקיפה ותגובה לאירועי סייבר עבור ארגונים בישראל ובעולם. כל פרויקט מתבצע אך ורק תחת כללי התקשרות (Rules of Engagement) חתומים ואישור בכתב מהלקוח, על מערכות הלקוח בלבד, ובהתאם לתורת ההגנה בסייבר 2.0 של מערך הסייבר הלאומי ולתקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017.

2019שנת ייסוד
515959765ח"פ
CISSPמוביל הצוות · אימות ב-Credly
ROEחתום לפני כל בדיקה
ARMOR IT & SECURITY LTD.

About the service

Armor IT & Security Ltd. delivers authorized penetration testing, adversarial simulation and incident response for Israeli and international organizations. Every engagement is performed under a signed Rules of Engagement and written client authorization, on the client's own systems only, and in line with the Israel National Cyber Directorate's Cyber Defense Doctrine 2.0 and the Israeli Privacy Protection Regulations (Data Security), 2017.

2019Founded
515959765Israeli company no.
CISSPLead tester · verify on Credly
ROESigned before every test
SERVICES

מפרט שירות

אפליקציות ווב ו-API

בדיקות קופסה שחורה, אפורה ולבנה של אפליקציות ווב, ממשקי REST ו-GraphQL, הזדהות וניהול סשן, לוגיקה עסקית ואינטגרציות.

OWASP WSTG · API Top 10

רשת חיצונית ופנימית

משטח התקיפה החשוף לאינטרנט, ציוד היקפי ו-VPN, ולאחר מכן Active Directory, הסלמת הרשאות, תנועה רוחבית וסגמנטציה.

PTES · NIST SP 800-115

Microsoft 365 וענן

סקירת תצורה ומסלולי תקיפה ב-Microsoft 365 ו-Entra ID, Azure, AWS ו-Google Cloud: זהויות, גישה מותנית, כיסוי MFA, חשיפת מידע, לוגים והתראות.

CIS Benchmarks · MITRE ATT&CK

רד טים וסימולציית תוקף

פרויקטים מבוססי יעד שמדמים תוקף אמיתי מול האנשים, התהליכים והטכנולוגיה, למדידת יכולת הזיהוי והתגובה של הארגון. יעדים ומנגנוני בטיחות נקבעים מראש בכללי ההתקשרות.

MITRE ATT&CK · TIBER-style

סימולציות פישינג

קמפיינים מדודים מול עובדי הארגון עצמו, כולל תרחישי גניבת סיסמאות ועקיפת MFA (תוקף באמצע), עם מדדים לכל קמפיין והמלצות המשך.

Social Engineering · AiTM

סקירת קוד ותגובה לאירועים

סקירת קוד מקור, תלויות ו-CI/CD עם ממצאים ממופים לקוד; וליווי בבלימה, חקירה והתאוששות מאירועי סייבר, כולל השתלטות על דואר עסקי וכופרה, עם דיווח לפי חוק הגנת הפרטיות.

Secure Code Review · IR
SERVICES

What we test

Web applications & APIs

Black-box, grey-box and white-box testing of web applications, REST and GraphQL APIs, authentication and session management, business logic and integrations.

OWASP WSTG · API Top 10

External & internal network

Internet-facing attack surface, perimeter devices and VPN, followed by Active Directory, privilege escalation, lateral movement and segmentation testing.

PTES · NIST SP 800-115

Microsoft 365 & cloud

Configuration and attack-path review of Microsoft 365 and Entra ID, Azure, AWS and Google Cloud: identity, conditional access, MFA coverage, data exposure, logging and alerting.

CIS Benchmarks · MITRE ATT&CK

Red team & adversary simulation

Objective-driven engagements emulating a realistic attacker across people, process and technology, to measure detection and response. Objectives and safety controls are fixed in the Rules of Engagement.

MITRE ATT&CK · TIBER-style

Phishing simulation

Measured campaigns against the organization's own workforce, including credential harvesting and MFA-bypass (adversary-in-the-middle) scenarios, with per-campaign metrics and follow-up recommendations.

Social Engineering · AiTM

Code review & incident response

Review of source code, dependencies and CI/CD with findings mapped to code; containment, investigation and recovery support for incidents such as business email compromise and ransomware, with reporting under the Israeli Privacy Protection Law.

Secure Code Review · IR
METHOD

איך אנחנו עובדים

שום בדיקה לא מתחילה לפני שההיקף, ההרשאות ותנאי העצירה חתומים.

1

כללי התקשרות

ROE חתום: היקף, יעדים, חלונות זמן, מערכות מוחרגות, אנשי קשר לחירום ותנאי עצירה.

2

אישור בכתב

הרשאה חתומה של בעל המערכת. צד שלישי נבדק רק באישורו בכתב.

3

ביצוע מבוקר

בדיקה בתוך ההיקף בלבד. בלי מניעת שירות, פעולות הרסניות או שינוי מידע בייצור, אלא אם סוכם מראש.

4

דיווח

תמצית מנהלים, דוח טכני עם CVSS, ראיות, שחזור והנחיות תיקון, ותוכנית תיקון לפי סיכון.

5

מבדק חוזר

אימות התיקונים, מכתב סגירה ומפגש סיכום עם ההנהלה והצוות הטכני.

METHOD

How we work

No testing starts before scope, authorization and stop conditions are signed.

1

Rules of Engagement

Signed ROE: scope, objectives, time windows, excluded systems, emergency contacts and stop conditions.

2

Written authorization

Signed authorization from the system owner. Third-party systems are tested only with their written consent.

3

Controlled testing

Strictly within scope. No denial of service, destructive actions or production data changes unless agreed in advance.

4

Reporting

Executive summary, technical report with CVSS scoring, evidence, reproduction steps and remediation, plus a risk-ranked fix plan.

5

Re-test

Verification of fixes, closure letter and a debrief with management and the technical team.

STANDARDS

תקנים ורגולציה

תורת ההגנה בסייבר 2.0 · מערך הסייבר הלאומי תקנות הגנת הפרטיות (אבטחת מידע) 2017 OWASP WSTGOWASP API Top 10OWASP MASVS PTESNIST SP 800-115MITRE ATT&CKCVSS v3.1 / v4.0

תוצרים

  • תמצית מנהלים להנהלה ולדירקטוריון
  • דוח ממצאים טכני עם דירוג חומרה (CVSS), ראיות, שלבי שחזור והנחיות תיקון
  • תוכנית תיקון מתועדפת לפי סיכון
  • מבדק חוזר לממצאים שתוקנו ומכתב סגירה
  • מפגש סיכום עם הצוות הטכני וההנהלה

התחייבויות

  • הרשאה לפני הכול. בדיקה רק על נכסים שבבעלות הלקוח או שהוא מורשה חוזית לבדוק.
  • בטיחות. מניעת שירות, פעולות הרסניות ושינוי מידע בייצור מוחרגים כברירת מחדל.
  • סודיות. ממצאים, ראיות ומידע של הלקוח תחת הסכם סודיות; נמחקים או מוחזרים בסיום לפי תנאי השמירה שסוכמו.
  • שקיפות. ממצא קריטי מדווח מיד, לא בסוף הפרויקט.
STANDARDS

Standards & regulation

INCD Cyber Defense Doctrine 2.0 Privacy Protection Regulations (Data Security) 2017 OWASP WSTGOWASP API Top 10OWASP MASVS PTESNIST SP 800-115MITRE ATT&CKCVSS v3.1 / v4.0

Deliverables

  • Executive summary for management and the board
  • Technical findings report with CVSS severity, evidence, reproduction steps and remediation guidance
  • Remediation plan prioritized by risk
  • Re-test of fixed findings and a closure letter
  • Debrief with the technical and management teams

Our commitments

  • Authorization first. Testing only on assets the client owns or is contractually authorized to have tested.
  • Safety. Denial of service, destructive actions and production data changes are excluded by default.
  • Confidentiality. Findings, evidence and client data are handled under NDA and deleted or returned at the end of the engagement per the agreed retention terms.
  • Transparency. Critical findings are reported immediately, not at the end of the engagement.
TEAM

הצוות

צוות קטן וקבוע. אותם אנשים שמגדירים את ההיקף הם אלה שמבצעים את הבדיקה וכותבים את הדוח.

RW

רפאל וייצמן

מייסד ומנכ"ל · מוביל מבדקים

מוביל את כל הפרויקטים של ארמור מאז הקמתה ב-2019, עם ניסיון רב שנים באבטחת מידע, הגנת פרטיות וביקורת סייבר, כולל הערכת מכרזי סייבר ממשלתיים. אחראי על כללי ההתקשרות, על הבדיקה עצמה ועל הדיווח להנהלת הלקוח.

CISSP · ISC2 CISO LinkedIn
תג CISSP של ISC2מאומת ב-Credly · ISC2
YR

יוסי רובין

מוביל GRC ולקוחות · תשתיות רשת

בארמור מאז 2018. מוביל סקרי סיכונים, מיפוי מערכות ונכסים קריטיים, ליווי להסמכת ISO 27001 ועמידה ב-GDPR, ואחראי על צד התשתיות במבדקים: רשתות, Firewall, סגמנטציה וסביבות ענן. בוגר הכשרות Certified Network Defender, Check Point CCSA/CCSE ו-Fortinet NSE 4.

TEAM

Team

A small, permanent team. The people who scope the engagement are the ones who run the test and write the report.

RW

Rafael Waizman

Founder & CEO · Lead tester

Leads every Armor engagement since founding the company in 2019, with many years in information security, privacy and cyber audit, including evaluation of government cyber tenders. Owns the Rules of Engagement, the testing itself and the debrief to client management.

CISSP · ISC2 CISO LinkedIn
CISSP badge, ISC2Verified on Credly · ISC2
YR

Yossi Rubin

GRC & Client Lead · Network infrastructure

With Armor since 2018. Leads risk assessments, system and critical-asset mapping, ISO 27001 and GDPR implementation, and owns the infrastructure side of engagements: networks, firewalls, segmentation and cloud environments. Trained in Certified Network Defender, Check Point CCSA/CCSE and Fortinet NSE 4.

מתחילים ממבדק אחד

נשמח לתאם שיחת היכרות ולהגדיר יחד היקף, יעדים ולוחות זמנים.

לחץ כאן ליצירת קשר
ארמור אי.טי. אנד סקיוריטי בע"מ · רחוב תוצרת הארץ 3, פתח תקווה · info@armor.co.il

Start with one test

Let's set up an intro call and define scope, objectives and timeline together.

Contact us
Armor IT & Security Ltd. · 3 Totzeret HaAretz St., Petah Tikva, Israel · info@armor.co.il
כל הזכויות שמורות לחברת ארמור בע"מ © 2026 · מדיניות פרטיות · הצהרת נגישות© 2026 Armor IT & Security Ltd. All rights reserved. · Privacy policy · Accessibility