Skip to content

Vulnerability research

Deep review of software and protocols, down to the primitives, to surface the bug classes an automated scanner has no way to model.

Deliverable
Advisory · coordinated disclosure
Stages
4
Pricing
Fixed, agreed before start

Where an assessment asks "is this deployment secure", research asks "is this design sound". Source review, reverse engineering, protocol analysis and targeted fuzzing applied to a product, a library, or a piece of firmware — with the goal of finding the class of bug rather than a single instance of it. Where a finding affects a third party, we run coordinated disclosure on your behalf under a published policy.

How the engagement runs

  1. 01

    Target modelling

    Establish the trust boundaries, the attacker-reachable surface, and the invariants the code believes it holds. Research without a threat model finds noise.

  2. 02

    Analysis

    Static review and reverse engineering to locate candidate bug classes, then harness construction to reach them reliably.

  3. 03

    Triage and proof

    Crashes are deduplicated, root-caused and driven to a demonstration of impact. A crash without a reachable path is reported as exactly that.

  4. 04

    Disclosure

    Advisories, vendor coordination, and an agreed embargo. We do not publish before a fix or an agreed deadline.

Typical scope

  • Source-assisted and black-box binary review
  • Reverse engineering of native and managed binaries
  • Protocol and file-format analysis
  • Coverage-guided fuzzing with custom harnesses
  • Cryptographic implementation review
  • Firmware and embedded targets

Other engagements