Odysec examines Linux hosts for traces of intrusion: replaced system binaries, hidden boot-time persistence, anomalous processes, and privilege-escalation paths.
You run the collector on your own hosts — we never have any access to your machines, at any point.
View a full sample report → (in Chinese)
Every service follows the same set of principles: you run it yourself, the source is readable, nothing is installed and nothing is left behind. There is no quality gap between the free tools and the paid services — only scope and depth differ.
Upload a config file and get hardening advice instantly. Rules come from real operational incidents, not compliance checklists. Files are never stored.
Enter a domain to check its anti-spoofing posture — especially the ways these records silently stop working.
You export your tenant settings yourself with read-only permissions; we review them against attack paths that are actually exploited.
Download the readable-source collector, run it yourself, upload the result and receive a full assessment report.
Detects configuration drift and anomalous change against a baseline — and the baseline stays on your host.
Watches your domain's DNS, certificates, open ports and subdomains — and notifies you only when something changes.
A human-performed compromise assessment with expert interpretation, for concrete suspicions or complex environments.
All prices are public on the pricing page — no sales call required →
Odysec is made up of security practitioners with backgrounds in both operations and offensive security.
We have run production servers and handled real intrusion incidents. The situation we see most often in practice: an environment has several protection products deployed, yet nobody can clearly answer whether a given host is compromised right now. Odysec focuses on answering that question — compromise assessment for Linux servers and container environments.
We do not aim for a long list of services; each one is offered only after it has been thoroughly validated. Our assessment tooling is built in-house and its design principles are fully documented — because for a security service, whether customers can verify it themselves matters more than a feature list.
Our checks come from real operational experience. They focus on the configurations that actually cause incidents — including settings that look complete but are silently ineffective — rather than items ported line-by-line from a compliance checklist.
We understand how intruders hide: a backdoor that must survive a reboot has to live in a limited number of persistence locations. The entire assessment method is designed around this fact.
The collector is developed by us: a single file, readable source code, zero dependencies. A tool that asks for root must withstand line-by-line review.
Most enterprise security budgets go to Windows endpoints. Yet the public websites, APIs, databases and container hosts — the machines that actually run the business and sit directly on the internet — mostly run Linux, and usually with no endpoint protection at all.
This gap has existed for years, and attackers understand it well.
Antivirus, EDR, asset inventory and alerting pipelines: this is where budgets and tooling concentrate.
CoveredDirectly exposed to the internet and carrying the business, yet largely outside any endpoint protection coverage.
Blind spotMaintaining our own signature set without a threat-intelligence pipeline would only ever match samples that are already public — the result is a false sense of security with no real substance.
What we compare is the state your host is supposed to be in. A backdoor that must survive a reboot necessarily lands in a limited set of locations: systemd units, cron, shell startup files, SSH authorized keys, and so on. We enumerate these locations exhaustively, fingerprint them, and verify each item against the package manager's records. This method depends on no threat intelligence, and it is most effective against the "you ran poisoned code" class of compromise.
The following principles apply to every service, from the free tools to consulting engagements, without exception.
Compromise assessment requires root. Handing root on a production host to a web service is not acceptable, so we reversed the direction of execution: you run the collector on your own hosts. We never have any access to your machines, at any point.
No minification, no obfuscation, no dependencies. Any security tool that asks you to run it as root but won't show you its source does not deserve your trust.
No resident service, no changes to system configuration, no files left on disk. The collector exits when it finishes, so it does not contaminate the very evidence it is collecting.
Is this host compromised? Configuration weaknesses are listed separately. Merging both into a single risk score makes every report read "high risk" — and therefore worthless.
The whole flow is online and self-service — no meetings to schedule, no access to grant. If anything is unclear, mail is answered by the people who actually perform the assessments.
Order online or write to us. The free tools need no code at all — just open the page.
The collector is a single file of readable source with a SHA-256 checksum. We recommend reviewing it before running.
Runs on your host in about 20 seconds, fully offline, nothing installed and nothing left behind. You upload the result file yourself.
The report answers "were traces of compromise found", lists configuration weaknesses separately, and itemizes the coverage gaps of the assessment.
The security industry has no shortage of inflated marketing claims. Here is what this service cannot do, stated on the front page rather than in a report appendix:
Odysec has no sales team and no support tiers. Your mail is read and answered by the people who wrote the assessment tooling and review the reports — every word of a quote comes from someone accountable for the result.
For quotes, consulting engagements, or anything not covered on this site, write to us. Mail is answered by the people who actually perform the assessments — not routed through sales.
Quotes, consulting engagements, personal-data access and deletion requests.
Vulnerability reports and security issues. See our disclosure policy before reporting.