Cybersecurity Division

WE BREAK
THINGS SO
HACKERS CAN'T.

侵入テスト・脆弱性診断・防御アーキテクチャ

Offensive security, defensive architecture, and secure web development for Raleigh, NC and the Research Triangle, from a 20-year enterprise IT shop. We test like adversaries, harden like operators, and build like engineers — because the difference between a breach and a near-miss is whoever got there first.

root@gotroot ~ engagement.sh
20+
Years Enterprise IT
975+
Projects Delivered
7,500+
Companies Protected
99.9%
Uptime Guarantee
// cat /etc/services

What We Do

[ 01 ]

Penetration Testing

Real-world attack simulation against your infrastructure, web apps, and networks. We find what scanners miss — chained vulnerabilities, business-logic flaws, and the soft spots adversaries actually exploit.

Offensive Security
[ 02 ]

Vulnerability Assessment

Comprehensive scanning and analysis with industry-leading tools, then triaged by humans who know your environment. Prioritized findings with actionable remediation — not 400-page noise reports.

Risk Management
[ 03 ]

Security Hardening

Firewall tuning, SIEM deployment (Security Onion, Elastic), endpoint detection, and zero-trust architecture. We lock the perimeter, instrument the interior, and make sure you'll see the breach — if it ever happens.

Defensive Security
[ 04 ]

Secure Web Development

Custom websites and applications built security-first from line one. WordPress hardening, headers, CSP, secrets handling, dependency hygiene, and code that won't show up in a CVE next year.

Development
[ 05 ]

Managed IT & Cloud

Proactive infrastructure monitoring, encrypted cloud backup with hourly snapshots, disaster recovery, and ongoing patch management. Your IT department, outsourced — without the help-desk runaround.

Managed Services
[ 06 ]

Compliance & Auditing

HIPAA, PCI-DSS, and NIST framework navigation with thorough documentation. We come from healthcare IT — we know what auditors want to see, and we've helped clients pass on the first try.

Compliance
// ./engagement.sh

How We Operate

01

Recon

Scoping call, asset inventory, threat model, and rules of engagement. We don't touch a packet until we both agree on what's in scope and what's off-limits.

02

Engage

Active testing — automated scanning paired with manual exploitation, chained findings, and adversary-emulation techniques drawn from current threat intel.

03

Report

Executive summary plus technical findings, severity-ranked, with proof-of-concept where appropriate and remediation guidance you can hand straight to your team.

04

Remediate

We don't just hand you a PDF and disappear. Retest after fixes, quarterly reviews, and standing access to the engineer who knows your environment.

// ./lab/run --interactive

The Lab

Most security firms hand you a screenshot of an old project. We embedded a working simulation of one of our visualizations directly on this page — rendered live in your browser, no external services, no heavy frameworks. If you can imagine the dashboard, we can build it — and we mean that as a turnkey service offering, not a tagline.

▸ network_attack_visualizer.js real-time canvas2d ~340 LOC
NODES: PACKETS: BLOCKED: BREACHED:

What you're looking at: a simulated network mesh where green packets are legitimate traffic and pink packets are attempted intrusions. The firewall (center node) blocks most attacks — but a small fraction get through, just like in the real world. Click Launch Attack to see a coordinated burst. What this is really for: showing you that "we built a custom dashboard for your SOC" isn't a slide — it's a deliverable we ship.

// whoami

Who We Are

gotroot.sh is the cybersecurity division of Pendergrass Consulting, a full-service IT firm built on two decades of enterprise healthcare experience — hospital networks, mission-critical infrastructure, and the kind of environments where downtime isn't an inconvenience, it's a patient outcome.

We bring that operational rigor to small businesses that can't afford a breach. No ticket systems. No junior account managers. When you call, you reach the engineer who already knows your stack — and we'd rather tell you the uncomfortable truth than the comfortable lie.

Based in Selma, NC — about 30 miles east of downtown Raleigh — we serve clients across the Research Triangle: Raleigh, Durham, Cary, Chapel Hill, Apex, Garner, Clayton, and Smithfield. On-site engagements throughout Wake and Johnston Counties; remote assessments and managed services nationally.

// CAPABILITIES_STACK

  • OffensiveBurp Suite Pro · Metasploit · Cobalt Strike-class TTPs · custom tooling
  • DefensiveSecurity Onion · Elastic SIEM · Suricata · Wazuh · Palo Alto · Cisco ASA
  • FrameworksMITRE ATT&CK · NIST CSF · OWASP ASVS · CIS Benchmarks
  • ComplianceHIPAA · PCI-DSS · NIST 800-53 · SOC 2 readiness support
  • BuildWebGL · Three.js · D3 · Canvas2D · custom dashboards · the page you're on
// initiate_handshake

Get In Touch

Free initial consultation.
No obligations — just answers.

Twenty minutes is usually enough to figure out whether we're a fit. Tell us what's keeping you up at night and we'll tell you whether it should be — and what we'd do about it.