
EnableSecurity
- Founded
- 2008-01-01
- Headquarters
- 02, Moloko, Humol Street, Mriehel, Malta
- Phone
- +44 20-8133-7269
Enable Security is a boutique cybersecurity consultancy founded in 2008 by Sandro Gauci, dedicated exclusively to the security of real-time communications (RTC) systems, including VoIP and WebRTC. The firm offers penetration testing, vulnerability assessments, and denial-of-service simulation tailored to RTC infrastructure, serving telecommunications providers and unified-communications vendors. Enable Security is best known for creating SIPVicious, the most widely used open-source VoIP security testing toolkit, and for maintaining a steady stream of RTC-focused research through its RTCSec newsletter and Communication Breakdown blog. Despite its small size, the company has an outsized influence, regularly uncovering critical vulnerabilities in products from major vendors like Cisco and AudioCodes. The company is privately held and operates as a high-end consulting practice, with its two publicly named principals being founder/CEO Gauci and lead researcher Alfred Farrugia. Enable Security does not disclose revenue or headcount but is estimated to have fewer than ten employees.
Detailed Review
History and Founding
Enable Security was founded in 2008 by Sandro Gauci, a well-known researcher in real-time communications security. Gauci's early work on the SIPVicious toolkit established the company's reputation as a specialist in VoIP and WebRTC security. The firm has remained privately held, with Gauci actively involved in hands-on engagements and tool development.
Services and Offerings
Enable Security's core services include manual and semi-automated penetration testing of SIP and WebRTC systems, denial-of-service simulation using custom fuzzers, reverse engineering of proprietary protocols, and security training via the internally developed DVRTC (Damn Vulnerable Real-Time Communications) lab. Engagements typically last weeks and command premium rates due to the firm's deep expertise.
Open Source Contributions
The flagship open-source project is SIPVicious OSS, the de facto standard toolkit for auditing SIP-based systems, providing utilities for user enumeration, extension scanning, and password cracking. Enable Security also maintains WAFW00F, a Web Application Firewall fingerprinting tool, and curates the Awesome VoIP/WebRTC Security list on GitHub. The advanced SIPVicious PRO toolset is used internally for client work and is not commercially available.
Thought Leadership
Enable Security disseminates research through the free RTCSec newsletter (bi-weekly commentary on VoIP/WebRTC vulnerabilities) and the Communication Breakdown blog, which publishes technical deep-dives and vulnerability disclosures. The team has credited-disclosed critical issues in products from Cisco, AudioCodes, Asterisk, FreeSwitch, and many others, reinforcing its influence in the niche.
Business Model and Market Position
The company operates as a high-end consultancy, not a software vendor. It competes indirectly with generalist cybersecurity firms but occupies a unique position as the only dedicated RTC security specialist with over 15 years of history. Enable Security does not pursue venture funding or broad commercialisation, limiting scalability but allowing deep focus on evolving threats.
Team and Ownership
Enable Security is a very small team, likely fewer than 10 people, with two named principals: Sandro Gauci (CEO, Founder, and Chief Mischief Officer) and Alfred Farrugia (R&D Lead and Chief Demolition Officer). The firm does not publicly disclose revenue, headcount, or a physical headquarters address, though Gauci is based in Malta.
Key Products
SIPVicious OSS
Open-source VoIP security testing toolkit; includes tools for SIP user enumeration (svmap, svwar, svcrack) and is the most widely used open-source RTC audit suite.
SIPVicious PRO
Internal advanced toolset used by Enable Security during engagements, including fuzzing and DoS capabilities; not sold or licensed.
DVRTC (Damn Vulnerable Real-Time Communications)
Intentionally vulnerable VoIP/WebRTC platform designed for security training and research, providing isolated lab scenarios.
RTCSec Newsletter
Free periodic newsletter covering VoIP and WebRTC security news, vulnerabilities, and commentary.
Communication Breakdown
Company blog dedicated to technical analysis of RTC vulnerabilities and attacks.
WAFW00F
Open-source Web Application Firewall fingerprinting tool maintained by Enable Security.
Awesome VoIP/WebRTC Security
Curated list of resources on GitHub covering RTC security tools, research, and references.