Skip to main content
Back to Solution Providers

Neonix Security Pty Ltd trading as trustee for Neonix Unit Trust

Research-led offensive security. Penetration testing. Red team. Vulnerability research. We test applications, infrastructure and connected devices, with findings your team can verify and fix.

We’re a focused offensive security team based in Australia. Our clients work directly with the senior practitioners responsible for scoping, testing, reporting and debriefing every engagement.

We specialise in research-led offensive security for high-trust infrastructure and platforms, systems where a breach can affect not only one organisation, but thousands or millions of end users. Our engagements go beyond compliance checklists to identify, validate and explain the vulnerabilities that matter most before adversaries exploit them.

Our technical practice is grounded in original vulnerability research, not simply the application of commercial tools. The Neonix team conducts sustained zero-day research programmes, targeted bug-class investigations and coordinated disclosure. 

Adversarial Emulation: Objective-led campaigns that test whether your people, processes and technology can prevent, detect and respond to realistic attacks.

Application Security Testing: Security testing of web applications, APIs, mobile and endpoint software, and AI- and LLM-enabled systems.

IoT and OT Security Testing: End-to-end assessment of the device, application, cloud services, identity controls, communications and update mechanisms, because material vulnerabilities often emerge between components.

Network and Infrastructure Testing: Assessment of external and internal infrastructure, Active Directory and Microsoft Entra ID, cloud environments, wireless networks, physical controls and internet-facing exposure.

Vulnerability Research: Our flagship capability. We investigate a selected product, codebase, bug class, firmware component or supply-chain dependency to discover original vulnerabilities, demonstrate impact, determine root-cause, and support coordinated disclosure.

Security Advisory Services: ISO 27001 readiness and preparedness support; Essential Eight, NIST CSF 2.0, APRA CPS 234 and AESCSF maturity/current state assessments; risk assessments; virtual-CISO, security program leadership.