We break in.
So no one else does.

Realistic attack simulations for SAP landscapes — from on-prem through RISE with SAP to the factory floor. No theoretical audit. No scanner report. Real attacks by real hackers.

Example: real SAP kill chain (anonymized)
01 Initial Access: Fiori Launchpad with default credentials RECON
02 Privilege Escalation: ICF Service Misconfiguration EXPLOIT
03 Lateral Movement: Trusted RFC to ERP Prod PIVOT
04 OT Bridge: RFC to MES system in production CROSS-LAYER
05 Data Exfiltration: BTP Cloud Destination Hijack IMPACT

5 hops: Fiori login → production control + cloud exfiltration

What we attack — so no one else does

Our red team covers the entire SAP attack surface: from the ABAP layer through cloud integrations to the factory floor.

🎯

SAP Application Layer

Attacks on the SAP application layer — where the business data lives.

  • ABAP Code Injection & Transport Exploits
  • RFC/ICF Service Exploitation
  • SAP GUI & Fiori/UI5 attacks
  • Privilege escalation (SU01, PFCG)
  • SAP Router & Message Server Attacks
  • Transaction Code Abuse & Backdoors

Cloud & Integration

Attacks on cloud services, APIs and the bridges between on-prem and cloud.

  • BTP Destination Hijacking
  • Integration Suite Flow Manipulation
  • OAuth Token Theft & Replay
  • Cloud Connector Breakout
  • OData/REST API Exploitation
  • Cross-System Identity Abuse
🏭

OT & Production

Where SAP meets the physical world: MES, SCADA, PLCs and the bridges in between.

  • SAP MES/MII to SCADA pivoting
  • RFC connections to OT gateways
  • Hardware hacking: PLCs & IoT devices
  • Plant Connectivity (PCo) Exploitation
  • Production data manipulation
  • Safety system bypass scenarios

Every SAP architecture. Every attack surface.

Whether on-prem, hybrid or full cloud — every SAP variant has its own weaknesses. We know them all.

🖥

SAP On-Premise (ECC & S/4HANA)

Classic on-prem installations with full control — and full responsibility. Often grown over 15+ years, carrying historical legacy.

Typical attack vectors:
RFC-Exploitation · ABAP Backdoors · Transport System Abuse · Gateway Security · Message Server Attacks · Kernel-Level Exploits
🔄

Hybrid (On-Prem + BTP)

The most dangerous constellation: on-prem systems with cloud connectivity. The Cloud Connector becomes the bridge for attackers.

Typical attack vectors:
Cloud Connector Breakout · Destination Confusion · Certificate Pinning Bypass · Hybrid-Identity-Attacks · Trust Chain Exploitation

RISE with SAP

SAP as a managed service. Infrastructure at SAP/hyperscaler, but the application layer remains the customer's responsibility — and is often overlooked.

Typical attack vectors:
Shared Responsibility Confusion · Custom Code Vulnerabilities · API management gaps · Identity Federation Weakness · Misconfigured tenant isolation
🚀

SAP BTP (Business Technology Platform)

Cloud-native services, custom apps, AI integrations. New attack surfaces that classic SAP security tools don't see.

Typical attack vectors:
Service Binding Leaks · XSUAA Misconfiguration · CAP/RAP Code Injection · SAP HANA Cloud SQL Injection · MTA Deployment Hijacking
🔗

SAP Integration Suite

The nervous system of the SAP landscape. CPI, API Management, Event Mesh — every connection is a potential attack vector.

Typical attack vectors:
iFlow Manipulation · Credential Store Extraction · Message Routing Abuse · API Proxy Bypass · Event Mesh Spoofing · SOAP/REST Injection
🏭

SAP + OT/production environments

Where SAP ERP meets MES, SCADA and PLCs. The bridge between office IT and the factory floor is often the weakest point.

Typical attack vectors:
SAP MII/MES Pivoting · Plant Connectivity Exploitation · OPC UA Manipulation · Historian database attacks · Safety-System-Bypass · Hardware hacking

Our red team process

Structured, reproducible, documented. From reconnaissance to executive report.

01

Scoping

Joint definition of objectives, systems, rules of engagement and escalation paths.

02

Reconnaissance

Passive and active reconnaissance: system versions, interfaces, exposed services, OSINT.

03

Exploitation

Active attacks: exploit vulnerabilities, escalate privileges, perform lateral movement.

04

Post-Exploitation

Validate business impact: data access, production control, exfiltration — how far do we get?

05

Reporting

Executive summary + technical deep dive + prioritized remediation roadmap.

Where SAP meets the factory floor

Most red teams stop at IT. We go further: from SAP ERP through MES to the PLC on the production line.

The Purdue model as an attack path

In automotive, pharma and manufacturing, SAP systems are connected directly or indirectly to production systems: via MES (SAP MII/ME), Plant Connectivity (PCo), OPC UA gateways or historically grown RFC connections.

An attacker who compromises SAP ERP can move through these bridges into the OT world — all the way to production control. This isn't a theoretical scenario: it's the reality we find at every third automotive client.

Our OT expertise is not an add-on — it's part of our DNA. Hardware hacking, PLC analysis and SCADA pen testing have been part of our portfolio for years.

Request an OT red team →
Level 4/5 — Enterprise IT
SAP S/4HANA · SAP BW · SAP BTP · Active Directory · Email · VPN
Level 3 — MES / Manufacturing Operations
SAP MII · SAP ME · SAP Plant Connectivity · Historian DBs · Quality Management
Level 2 — SCADA / process control system
SCADA Server · HMI Stations · OPC UA Gateway · Engineering Workstations
Level 0/1 — Production / PLC
Siemens S7 · Allen-Bradley · Sensors · Actuators · Safety controllers · Robots
⚠ log(2) red team tests the entire path: SAP ERP → MES → SCADA → PLC

What sets us apart from every other red team

🔫

Bug Bounty Hunter

Active bug bounty hunters on Synack and at hacker conferences. We find vulnerabilities no scanner knows — because we discover them ourselves.

🧠

30+ years of SAP from the inside

Founded by a former SAP employee. We don't know ABAP, RFC, BTP and the SAP architecture from books — we know them because we built them.

🌐

Cross-Layer: SAP + OT + Hardware

Most pen testers stop at the application. We go further: through network pivoting into the OT world, including hardware hacking on PLCs and IoT.

🔒

Independent & discreet

Owner-operated, no investors, no disclosure obligations. Ideal for public authorities, KRITIS and organizations with the highest confidentiality requirements.

Three packages. Fixed scope. Clear results.

No blank-cheque contract with open-ended effort. Each package has a defined scope, a fixed duration and a concrete deliverable.

Focused

SAP Pen Test

Targeted pen test on a single SAP system or a defined attack surface. Fast, focused, with concrete findings.

  • 1 SAP system (e.g. S/4HANA Prod, BTP subaccount)
  • Defined attack vectors (e.g. API, RFC, Fiori)
  • Technical report + executive summary
  • Remediation recommendations with priorities
  • 30-min results walk-through
Maximum

Enterprise + OT

The full programme: SAP + IT + OT + hardware. From Fiori login to production control. For automotive, pharma and KRITIS.

  • Entire SAP landscape + OT environment
  • Hardware hacking & physical tests
  • Social engineering (on request)
  • SAP ↔ OT Bridge Exploitation
  • Full report + live demo for the board
  • Remediation workshop (full day)

Ready to have your SAP landscape attacked?

In a 30-minute call we clarify scope, variant, timeline and expectations.
No sales pitch — straight to the red team lead.

Get in touch →

Or just call us. Discretion goes without saying.