Vulnerability research
Deep review of software and protocols, down to the primitives, to surface the bug classes an automated scanner has no way to model.
- Deliverable
- Advisory · coordinated disclosure
- Stages
- 4
- Pricing
- Fixed, agreed before start
Where an assessment asks "is this deployment secure", research asks "is this design sound". Source review, reverse engineering, protocol analysis and targeted fuzzing applied to a product, a library, or a piece of firmware — with the goal of finding the class of bug rather than a single instance of it. Where a finding affects a third party, we run coordinated disclosure on your behalf under a published policy.
How the engagement runs
- 01
Target modelling
Establish the trust boundaries, the attacker-reachable surface, and the invariants the code believes it holds. Research without a threat model finds noise.
- 02
Analysis
Static review and reverse engineering to locate candidate bug classes, then harness construction to reach them reliably.
- 03
Triage and proof
Crashes are deduplicated, root-caused and driven to a demonstration of impact. A crash without a reachable path is reported as exactly that.
- 04
Disclosure
Advisories, vendor coordination, and an agreed embargo. We do not publish before a fix or an agreed deadline.
Typical scope
- Source-assisted and black-box binary review
- Reverse engineering of native and managed binaries
- Protocol and file-format analysis
- Coverage-guided fuzzing with custom harnesses
- Cryptographic implementation review
- Firmware and embedded targets

