UBT CERT — Kosovo's First Academic Computer Emergency Response Team · Est. 2017
Services

Enterprise-Grade Capabilities

Advanced cybersecurity services delivered by academic experts and industry professionals using proven international methodologies.

International methodologies (PTES, OWASP, NIST, MITRE ATT&CK)
Full technical and executive reporting after every engagement
Certified team: OSCP, CEH, CISA, ISO 27001 Lead Auditor

// Services

01
Advanced Penetration Testing

Sophisticated simulation of cyber attacks to uncover hidden vulnerabilities before real attackers exploit them. Covers network, web application, API, and critical infrastructure testing.

Network Web App API PTES OWASP
02
Red Team Operations

Advanced tactical operations emulating sophisticated threat actors (APT) to test your end-to-end defenses — from social engineering and phishing to full technical exploitation of systems.

APT Simulation Social Engineering Physical MITRE ATT&CK
03
SIEM/EDR Engineering

Design, deployment, and optimization of SIEM and EDR systems for real-time threat monitoring and detection. Includes custom correlation rules, playbooks, and operational dashboards.

Splunk Microsoft Sentinel CrowdStrike Elastic SIEM
04
Digital Forensics & Incident Response

Swift and professional investigation of cybersecurity incidents. Digital evidence analysis, memory forensics, network analysis, system recovery, and comprehensive technical and legal reporting (e-Discovery).

Memory Analysis Disk Forensics eDiscovery Volatility Autopsy
05
Infrastructure Hardening

Systematic hardening of your IT infrastructure — servers, networks, operating systems, cloud — by eliminating configuration weaknesses and applying CIS, NIST, and ISO 27001 baselines.

CIS Benchmarks NIST Cloud Security AWS Azure
06
Security Automation & Orchestration (SOAR)

Automation of security processes and orchestration of multiple tools (SIEM, EDR, Ticketing) for faster, more effective incident response. Playbook development and API integration.

Playbooks API Integration Threat Intel TheHive Shuffle
07
GRC — Governance, Risk & Compliance

Strategic guidance for information security governance, risk management, and compliance with international standards: ISO 27001, GDPR, NIS2, as well as Kosovo's local legal framework.

ISO 27001 GDPR NIS2 Risk Assessment Gap Analysis
Process

How We Work

Every engagement follows a structured and transparent process.

01
Scoping
Clearly define the objectives, scope, and terms of engagement together with the client.
02
Reconnaissance
Passive and active information gathering to understand the attack surface.
03
Exploitation
Controlled and documented testing of discovered vulnerabilities within the agreed scope.
04
Reporting
Detailed technical and executive report with findings, risks, and prioritized recommendations.
05
Remediation & Retest
Support during vulnerability remediation and a free retest to confirm effectiveness.

Need help with your security posture?

Discuss your organization's specific needs with our technical team.

Contact Our Team