Odysec
Self-service checks & free config review · Available now

Most organizations cannot tell
whether their servers
have been compromised.

Odysec examines Linux hosts for traces of intrusion: replaced system binaries, hidden boot-time persistence, anomalous processes, and privilege-escalation paths.

You run the collector on your own hosts — we never have any access to your machines, at any point.

View a full sample report → (in Chinese)

baseline ⟷ currentdiff
628 items collected  →  1 differs from the baseline
15+
persistence locations
~20s
collection per host
0
access to your hosts
0
third-party dependencies
What we do — 01

From free tools
to consulting engagements.

Every service follows the same set of principles: you run it yourself, the source is readable, nothing is installed and nothing is left behind. There is no quality gap between the free tools and the paid services — only scope and depth differ.

Free tools
Paid services

All prices are public on the pricing page — no sales call required →

Who we are — 02

Operations and offense,
one team.

Odysec is made up of security practitioners with backgrounds in both operations and offensive security.

We have run production servers and handled real intrusion incidents. The situation we see most often in practice: an environment has several protection products deployed, yet nobody can clearly answer whether a given host is compromised right now. Odysec focuses on answering that question — compromise assessment for Linux servers and container environments.

We do not aim for a long list of services; each one is offered only after it has been thoroughly validated. Our assessment tooling is built in-house and its design principles are fully documented — because for a security service, whether customers can verify it themselves matters more than a feature list.

who we areodysec
$ ops $ offense $ tooling ODYSEC
ops × offense × in-house tooling  →  one team

Operations background

Our checks come from real operational experience. They focus on the configurations that actually cause incidents — including settings that look complete but are silently ineffective — rather than items ported line-by-line from a compliance checklist.

Attacker's perspective

We understand how intruders hide: a backdoor that must survive a reboot has to live in a limited number of persistence locations. The entire assessment method is designed around this fact.

Tools built in-house

The collector is developed by us: a single file, readable source code, zero dependencies. A tool that asks for root must withstand line-by-line review.

Why Linux — 03

Budgets on Windows,
attackers on Linux.

Most enterprise security budgets go to Windows endpoints. Yet the public websites, APIs, databases and container hosts — the machines that actually run the business and sit directly on the internet — mostly run Linux, and usually with no endpoint protection at all.

This gap has existed for years, and attackers understand it well.

Windows endpoints

Antivirus, EDR, asset inventory and alerting pipelines: this is where budgets and tooling concentrate.

Covered
Internet-facing Linux servers

Directly exposed to the internet and carrying the business, yet largely outside any endpoint protection coverage.

Blind spot

We do not match signatures of known malware

Maintaining our own signature set without a threat-intelligence pipeline would only ever match samples that are already public — the result is a false sense of security with no real substance.

What we compare is the state your host is supposed to be in. A backdoor that must survive a reboot necessarily lands in a limited set of locations: systemd units, cron, shell startup files, SSH authorized keys, and so on. We enumerate these locations exhaustively, fingerprint them, and verify each item against the package manager's records. This method depends on no threat intelligence, and it is most effective against the "you ran poisoned code" class of compromise.

Principles — 04

Four principles,
no exceptions.

The following principles apply to every service, from the free tools to consulting engagements, without exception.

You run it yourself

Compromise assessment requires root. Handing root on a production host to a web service is not acceptable, so we reversed the direction of execution: you run the collector on your own hosts. We never have any access to your machines, at any point.

Readable source code

No minification, no obfuscation, no dependencies. Any security tool that asks you to run it as root but won't show you its source does not deserve your trust.

Nothing installed, nothing left behind

No resident service, no changes to system configuration, no files left on disk. The collector exits when it finishes, so it does not contaminate the very evidence it is collecting.

The report answers one question

Is this host compromised? Configuration weaknesses are listed separately. Merging both into a single risk score makes every report read "high risk" — and therefore worthless.

See how these principles apply to each service →

How it works — 05

From order to report,
a straight line.

The whole flow is online and self-service — no meetings to schedule, no access to grant. If anything is unclear, mail is answered by the people who actually perform the assessments.

01

Get an order code

Order online or write to us. The free tools need no code at all — just open the page.

02

Download & review the tool

The collector is a single file of readable source with a SHA-256 checksum. We recommend reviewing it before running.

03

Run it yourself

Runs on your host in about 20 seconds, fully offline, nothing installed and nothing left behind. You upload the result file yourself.

04

Receive the report

The report answers "were traces of compromise found", lists configuration weaknesses separately, and itemizes the coverage gaps of the assessment.

Limits — 06

What we cannot do,
on the front page.

The security industry has no shortage of inflated marketing claims. Here is what this service cannot do, stated on the front page rather than in a report appendix:

"No findings" means no anomalies were observed within the scope and methods above — it is not proof that the host was never compromised. We never use claims like "guaranteed to find every threat", and every report itemizes the coverage gaps of that particular assessment. This one will not change.
Direct line — 07

Your mail is answered by
the person doing the work.

Odysec has no sales team and no support tiers. Your mail is read and answered by the people who wrote the assessment tooling and review the reports — every word of a quote comes from someone accountable for the result.

contact@odysec.org →

Contact — 08

Tell us what
you need to confirm.

For quotes, consulting engagements, or anything not covered on this site, write to us. Mail is answered by the people who actually perform the assessments — not routed through sales.

General inquiries

contact@odysec.org

Quotes, consulting engagements, personal-data access and deletion requests.

Security reports

security@odysec.org

Vulnerability reports and security issues. See our disclosure policy before reporting.

The self-service interface and generated reports are currently available in Traditional Chinese only. If you need service in English, contact us before ordering.