Technical research for real attack paths.
Offensive-security research covering application, API, cloud and AI security—with practical testing methodology, attack chains and defensive guidance.
Electron Security Deep Dive: Renderer-to-Node Trust Boundaries
A practical Electron security methodology covering renderer isolation, preload bridges, IPC, navigation, file handling, plugin loading and desktop impact.
Read research →Electron Security Deep Dive: Renderer-to-Node Trust Boundaries
A practical Electron security methodology covering renderer isolation, preload bridges, IPC, navigation, file handling, plugin loading and desktop impact.
Cloud IAM Attack Paths: From a Low-Privilege Identity to Sensitive Data
A practical cloud penetration-testing methodology for tracing identity relationships, role assumptions, permissions and resource exposure into a measurable attack path.
Cloud Attack Paths: Identity Before Configuration
A practical method for tracing cloud weaknesses from an entry identity through role assumptions and permissions to sensitive resources and measurable impact.
Business Logic Flaws: The Bugs Scanners Miss
How offensive security testers model workflows, state transitions, replay, race conditions and client-controlled state to find vulnerabilities that signature-based tools rarely understand.
BOLA: Testing Object-Level Authorization in APIs
A hands-on methodology for finding broken object-level authorization across REST and GraphQL APIs, with a focus on authorization decisions rather than parameter guessing.
API Authorization Attack Chains: From BOLA to Cross-Tenant Impact
A deep-dive methodology for validating API authorization boundaries, chaining object-level and function-level access control failures, and measuring tenant impact safely.
When AI Agents Become the Attack Surface
A practical offensive-security guide to prompt injection, tool abuse, identity boundaries, data access and high-impact actions in agentic AI systems.
AI Agent Security Lab: Testing Prompt Injection Through Tool Abuse
A controlled lab methodology for testing indirect prompt injection, tool authorization, excessive agency and identity boundaries in AI agents.
