Research
Responsible disclosure, then publication.
Consultants spend a great deal of their time looking for vulnerabilities in commercial software, open source, hardware and firmware. We provide this free of charge to the companies involved, and assist them with fixes if they so require.

All vulnerability disclosures are handled in a responsible way, above and beyond industry standards, giving ample time to the companies involved to fix the flaws.
Consultants regularly participate in world-renowned hacking competitions such as Pwn2Own, where they have uncovered dozens of vulnerabilities, won hundreds of thousands of dollars in prizes, and outclassed teams from multinational corporations competing in the same events.
Since founding, consultants have made public over 200 vulnerabilities in well-known, widely used software. The full list is maintained on GitHub.
Pedigree on GitHubA sample of targets
Products and libraries our consultants have broken
- Cisco, Netgear, D-Link, Asus and other network devices
- SCADA and industrial-control software
- Cisco enterprise management software
- IBM enterprise management software
- HPE / Micro Focus enterprise management software
- Adobe Acrobat Reader
- SysAid Help Desk
- Novell ZENworks Configuration Management
- Kaseya Virtual System Administrator
- ManageEngine ServiceDesk, OpManager, Desktop Central and others
- ICU — International Components for Unicode (Android, Chrome, and hundreds of products)
- BMC Track-It! Service Desk
- VLC media player
- Poppler PDF library
- Apple QuickTime Player
- X.Org display server
- Several content-management systems
And many others. All of these were found using the same combination of techniques on which our services are based.
Want that same research applied to your product?
Short engagements, senior consultants, and work we actually sign our names to.