Skip to content
OPS-LIVE
// OPERATOR LED — VERIFIED CREDENTIALS — CLEARED FACILITY

Operators, not consultants.

Phantom X is staffed by people who spent their careers inside offensive intelligence and product-security teams — NSA Tailored Access Operations, Unit 8200, GCHQ, and the red-team benches of CrowdStrike Services. You are buying years of operator judgment, not a junior analyst following a runbook.

  • U.S. SECRET Facility
  • CJIS Compliant
  • SOC 2 Type II
  • ISO 27001
  • FedRAMP Moderate
// ROSTER — 38 OPERATORS ACROSS 7 COUNTRIES

Named, vetted, and verifiable.

Every Phantom X engagement is staffed by named operators you can vet before signing. No black-box staff-augmentation, no anonymous "senior consultants" — the people who scope your engagement are the people who run it.

Black-and-white portrait of Keren Lahav, Lead Consultant at Phantom X US

Keren Lahav

Lead Consultant
  • U.S. SECRET
  • ex–NSA TAO
  • Operator of the Year · 2023

11 years on offensive engagements across financial services and federal verticals. Leads Phantom X's continuous red-team program design and adversary-emulation playbooks.

Engagements led
94
CVE credits
7
Vertical focus
Fintech · Federal
Black-and-white portrait of Avi Mor, Principal Operator at Phantom X IL

Avi Mor

Principal Operator
  • U.S. SECRET
  • ex–Unit 8200
  • ex–CrowdStrike Services

Specialist in cloud-identity attack paths and SaaS post-exploitation. Built the ATT&CK-mapped playbook library that underpins every Phantom X engagement.

Engagements led
71
CVE credits
9
Vertical focus
SaaS · Critical Infra
Black-and-white portrait of James Holloway, Senior Operator at Phantom X UK

James Holloway

Senior Operator
  • DBS Enhanced
  • ex–GCHQ
  • ex–CrowdStrike Services

Leads Phantom X's purple-team exercise design and detection-evasion tradecraft. Frequent contributor to MITRE ATT&CK technique submissions.

Engagements led
58
CVE credits
5
Vertical focus
Healthcare · FinServ
Black-and-white portrait of Priya Iyer, Adversary-Emulation Lead at Phantom X US

Priya Iyer

Adversary-Emulation Lead
  • U.S. SECRET
  • ex–NSA TAO
  • Bug-Bounty Triage

Runs the bug-bounty triage partnership with two of the top-five U.S. banks. Designed the outcome-based pricing model now standard on Phantom X Tier-3 engagements.

Engagements led
62
CVE credits
6
Vertical focus
FinServ · Healthcare

The four profiles above are representative. Phantom X's full roster of 38 operators across the U.S., Israel, the U.K., Germany, Singapore, Canada, and Australia is provided to prospects during scoping under NDA.

// CUMULATIVE OUTPUT — AUDITABLE FIGURES

By the numbers.

These are not marketing ranges. They are the totals our delivery team reports against at quarterly review — and the figures an enterprise CISO can validate against CVEs, awards, and named publications.

612 Engagements completed through 2024 across financial services, SaaS, healthcare, and federal verticals.
41 Published CVE credits since 2019, including three vendor-acknowledged critical-severity findings.
72h Median time-to-first-critical-finding across 600+ engagements — documented in post-engagement reports.
38/7 Offensive-security consultants operating across seven countries, with 70% from named intelligence or product-security roles.
  • CSO Online · Top 10 Boutique Red-Team Firms, 2023 & 2024
  • Global Cyber Awards · Red-Team Operator of the Year, 2023
  • SOC 2 Type II · ISO 27001 · FedRAMP Moderate
  • 4.9 / 5.0 · Post-engagement satisfaction across 200+ verified client reviews
// BOOK A SCOPING CALL

Validate your defenses against named operators.

Tell us your environment, your threat model, and the questions your board is asking. We'll come back with a scoped engagement plan, a named operator team, and a fixed-fee proposal — typically within five business days.

// VETTED OPERATORS — APPLY

Cleared, offensive-minded, tired of staff-aug?

Phantom X hires from NSA TAO, Unit 8200, GCHQ, and Fortune 100 red teams. If you have an active clearance and a portfolio of post-exploitation work, we want to hear from you. Submissions are reviewed by an operator, not a recruiter.

Send CV + writeup PGP fingerprint: 0x9F4E 2A81 7C3D 6B05 · [email protected]