Vulnerability Research
Long-form research against a target of your choosing: protocol fuzzing, baseband analysis and CVE-grade findings, written up in full and disclosed the way you want them disclosed.
- You want depth on one target, not breadth
- A protocol or component has never been looked at seriously
- You can fund weeks, not days
- You want tooling you keep afterwards
- You need a whole product tested quickly, that is a pentest
- You want a design signed off before release, that is an audit
How it runs.
You hear from us during, not only at the end. A finding that matters does not wait for the report.
Scoping
The target, the depth, the disclosure you want, and the stages with a go / no-go between them.
Analysis
Reverse engineering and instrumentation until we understand the target well enough to attack it.
Attack
Fuzzing, protocol abuse and exploit development where a finding warrants it.
Disclosure
A full write-up, the proof-of-concept tooling, and coordinated disclosure or CVE publication the way you want it.
What lands on your desk.
Something an engineer can act on and something a board can read, plus everything needed to reproduce a finding without calling us.
- Technical write-up
- The research in enough detail to reproduce and to act on
- Proof-of-concept tooling
- Yours to keep, documented
- Disclosure support
- Coordinated with vendors or kept private, your call
- CVE publication
- Where the finding warrants it and you agree
What we can attack.
Pick the rows that apply and we will tell you the days each one costs.
All services| Target | What that involves |
|---|---|
| Baseband and modems | Firmware in phones, vehicles, routers and gateways |
| Proprietary radio | Undocumented protocols, reversed and attacked |
| Protocol stacks | Fuzzing harnesses driven from the radio side |
| Mobile core | Signalling, interfaces and subscriber-side exposure |
Questions we get asked.
Who owns the findings?
You fund the work, you decide how it is disclosed. We ask only that our name stays on the research we did.
Can you commit to a CVE?
We can commit to the work. Whether it yields a CVE depends on what is there, and we say so up front.
Tell us what transmits. We will tell you what it leaks.
One call to scope it, a fixed proposal after. NDAs signed before we talk details, if that is how your procurement works.