About Obexum

Built by auditors who got tired of false positives.

Obexum is named after obex — the latin root for "barrier". We build the barrier between a fresh AD install and the attacker who shows up six months later. No more, no less.

The story

Obexum started in 2026 as an internal tool. We were running pericial AD audits for clients and noticed the same pattern over and over: every commercial scanner emitted dozens of "informational" findings on a clean forest, every report was a 200-page wall of CVE noise, and the actual adversary primitives (ESC1-15, ACL backdoors, Kerberos abuse) lived in separate playbooks, separate tools, separate vendors.

We wrote a Go binary that codified the checks we ran by hand, with one hard rule: zero false positives in a clean state, or the check does not ship. Every probe had to pass a pericial round-trip — inject the misconfiguration, detect it, remediate it, re-scan clean — before it earned its rule_id.

Five months and 569 checks later, we shipped Obexum publicly. The lab DC at obxlab.local still runs every release. Every commit references the engagement evidence. Every check has a story.

What "pericial-grade" means

Pericial is what Spanish-speaking auditors call expert-witness forensic work — the kind that holds up in a courtroom. For us it translates to:

What we believe

Want to talk?

We are a small team. We answer email personally. Get in touch.