POCFORGE / RESEARCH

Technical research for real attack paths.

Offensive-security research covering application, API, cloud and AI security—with practical testing methodology, attack chains and defensive guidance.

RESEARCH LIBRARY
8+
technical security studies

Research library

RESEARCH02 / DESKTOP APPSEC · DEEP DIVE

Electron Security Deep Dive: Renderer-to-Node Trust Boundaries

A practical Electron security methodology covering renderer isolation, preload bridges, IPC, navigation, file handling, plugin loading and desktop impact.

18 MIN READTECHNICAL DEEP DIVE↗
RESEARCH04 / CLOUD SECURITY · DEEP DIVE

Cloud IAM Attack Paths: From a Low-Privilege Identity to Sensitive Data

A practical cloud penetration-testing methodology for tracing identity relationships, role assumptions, permissions and resource exposure into a measurable attack path.

16 MIN READTECHNICAL DEEP DIVE↗
RESEARCH04 / CLOUD SECURITY

Cloud Attack Paths: Identity Before Configuration

A practical method for tracing cloud weaknesses from an entry identity through role assumptions and permissions to sensitive resources and measurable impact.

12 min read↗
RESEARCH03 / APPLICATION SECURITY

Business Logic Flaws: The Bugs Scanners Miss

How offensive security testers model workflows, state transitions, replay, race conditions and client-controlled state to find vulnerabilities that signature-based tools rarely understand.

13 min read↗
RESEARCH02 / API SECURITY

BOLA: Testing Object-Level Authorization in APIs

A hands-on methodology for finding broken object-level authorization across REST and GraphQL APIs, with a focus on authorization decisions rather than parameter guessing.

11 min read↗
RESEARCH01 / API SECURITY · DEEP DIVE

API Authorization Attack Chains: From BOLA to Cross-Tenant Impact

A deep-dive methodology for validating API authorization boundaries, chaining object-level and function-level access control failures, and measuring tenant impact safely.

16 MIN READTECHNICAL DEEP DIVE↗
RESEARCH01 / AI SECURITY

When AI Agents Become the Attack Surface

A practical offensive-security guide to prompt injection, tool abuse, identity boundaries, data access and high-impact actions in agentic AI systems.

12 min read↗
RESEARCH03 / AI SECURITY · LAB GUIDE

AI Agent Security Lab: Testing Prompt Injection Through Tool Abuse

A controlled lab methodology for testing indirect prompt injection, tool authorization, excessive agency and identity boundaries in AI agents.

17 MIN READTECHNICAL DEEP DIVE↗
Research principle: technical content is designed to explain attack paths, validation methodology and defensive controls without relying on generic vulnerability definitions.