We will hack you,before attackers do.
AwareXone detects and stops social engineering, scams and human-targeted attacks.
We find them by running them first.
We build in the open, so defence moves faster than fraud
A fixed share of our engineering time goes into security tooling anyone can clone today. No licence, no paid tier, no upgrade path. Attackers have shared their tools for twenty years. Defenders are only now catching up.
Generates agent skill files for eighteen vulnerability classes from public disclosures.
223Pythonweb3-bug-bounty-hunting-ai-skillsEighteen smart contract security skill files for agent-assisted review.
129MarkdownFraud does not check whether you have a security budget before it starts. Publishing the tooling is how the clinics, schools and small businesses we will never invoice get to defend themselves too.
4,768 stars across three public repositories.
The open source programSocial engineering already worked.
AI made it industrial.
Attackers stopped bothering with your firewall a long time ago. They call someone instead, and the tools that make it convincing now cost almost nothing.

VoiceA familiar voice is no longer identity
Three seconds from a webinar or a voicemail greeting produces a real-time clone. Your staff have spent their careers treating a recognised voice as proof.
VideoSeeing someone is no longer proof
Live face replacement survives a compressed webcam stream and an eight-minute meeting, which is exactly how approvals happen.
LanguageBad grammar is no longer the tell
Models write flawless, context-aware messages in any language and any register, personalised per recipient, at unlimited volume.
ReconnaissanceResearch costs nothing now
Mapping an org chart, matching it against breach data and writing a tailored pretext per employee took an analyst a week. It is now an overnight script.


Which leaves one control that still scales: a workforce that verifies through a second channel, and is never punished for doing so.
One team for the whole human attack path
From the reconnaissance an attacker starts with, to the person they eventually call, to the systems behind them. Engaged individually or as a single program.
Every path ends at a person.
- Recon
- Contact
- Access
Assess. Simulate. Train. Measure. Repeat.
A loop, not the annual module.
- Exposure
- Memory
- Proof
Run the attack before somebody else does
Pretexts built from live reconnaissance of your own organisation, delivered across every channel an attacker would use.
- Spear phishing, vishing, smishing, quishing, chat and deepfake video
- Weighted by role, privilege and payment authority
- Measured on reporting speed and escalation, not just click rate
Train the mind, not the checklist
Surface cues are dead, so we teach the psychological lever instead. The lure will always be new; the feeling it creates never is.
- The seven levers every social engineer uses, and how each feels from inside
- Ninety-second coaching the moment somebody fails, not months later
- Verification made procedural, so declining is never a confrontation

Report human risk like any other risk
A number your board can act on, built from behaviour rather than attendance, weighted by the privilege each person holds.
- Scored by department, role and access level
- Repeat susceptibility surfaced for coaching, never for discipline
- Evidence mapped to ISO 27001, SOC 2, NIST CSF and GDPR expectations
Delivered as a rolling program or as a one-off assessment if you need a baseline first.
Scope a programWhat we show on stage
Figures from our talks, workshops and engagement debriefs. Every loss number here comes from a named source: UNODC, the FTC, the FBI, Singapore Police.
















We publish the research rather than gate it. If a figure here is useful to your board, take it.
Read the write-upsThe field notes behind the figures
Anonymised breakdowns of the pretexts we meet in engagements and the procedures that defeat them. No gating, nothing to hand over first.
Why social engineering beats your security stack
You can buy every control on the market and still lose to a polite phone call. Here is why the human layer keeps deciding breaches, and what actually changes the outcome.AI voice cloning attacks: how they work and how to stop them
Cloning a voice now takes seconds of audio and costs nothing. A practical breakdown of how these calls are built and the verification habits that defeat them.Someone joined your video call as your CFO. Now what?
Live face replacement is good enough to survive a short meeting. A verification protocol your finance and leadership teams can actually run under pressure.You are handing us permission to manipulate your staff
That deserves more than a statement of work. Four constraints, in writing, on every engagement.
The boundary is drawn before we start.
- Scope
- Authorisation
- Stop authority
Authorised, scoped, documented
Signed rules of engagement naming targets, channels, timing and limits, plus a named contact who can stop an engagement instantly.
No blame, no names
Individual results go to the individual. Leadership sees aggregates. Programs that shame people stop receiving reports.
Evidence over theatre
Findings reproduced by hand and rated on real impact. If a control already works, we say so.
Independent by design
We resell nothing and take no vendor commission. Often the recommendation is a procedure rather than a purchase.
Three ways to start,
and no price list
What it costs depends on headcount, channels, depth and cadence, so the number comes out of a thirty-minute call rather than a table. No pitch deck, and no proposal unless there is something worth doing.
- A real conversation, not a sales script
- You talk to the person who would run the work
- No proposal unless there is something worth doing
