Why the physical vector matters
Much of the investment in cybersecurity concentrates on the network and on email. But a determined attacker rarely comes in where they are most expected: they take advantage of the cable someone plugs in without thinking, the radio fob nobody has changed in ten years, or the operator workstation someone reaches physically for a minute.
Assessing that plane calls for real tools, not slides. Titanium designs and prepares that hardware, and above all knows what each finding means in a plant or an office, and how to turn it into a recommendation you can actually act on.
What the Evil Crow family is
Evil Crow is a line of hardware-hacking devices in discreet form factors —cables, adapters, small boards— built for security testing. Each model covers a different vector: keyboard emulation (BadUSB), keystroke logging, radio-frequency analysis or video-signal interception. Titanium folds them into its assessments and adapts them to each client's scenario.
Devices fitted with implants
When the engagement calls for it, we start from an everyday object —a charger, a mouse, a keyboard, a monitor, a power strip— and add an implant that gives it remote-control capabilities over Wi-Fi, Bluetooth or 4G. It lets us measure, with a realistic and controlled case, how far a seemingly harmless device can reach inside a trusted zone.
Bespoke device development
Not every scenario fits a catalogue. When needed, we develop the specific device and firmware for the test: the form factor, the connectivity and the capabilities that engagement requires, no more and no less. The target is never the gadget, but the response the organisation gives when it appears.
Responsible use
This is offensive hardware, and we treat it as such. It is only used inside contracted assessments, with the express authorisation of the systems' owner, a bounded scope and rules of engagement agreed beforehand. The purpose is always defensive: to find the gap before someone else does and close it.