// THREAT_RESEARCH // OFFSEC_DISPATCHES

Offensive Intelligence &
Security Deep-Dives.

Hands-on vulnerability writeups, binary reverse-engineering walkthroughs, and practical defensive playbooks written directly by our security researchers.

★ FEATURED RESEARCH REPORTLATEST_DISPATCH
Android SecuritySep 04, 20268 min read

Deep Dive: Reversing Android Keystore Implementations with Frida

A hands-on walkthrough showing how modern Android applications store sensitive tokens in the Keystore, how hardware-backed TEEs protect them, and how researchers hook Cipher.doFinal() using Frida runtime instrumentation.

#Android#Frida#Reverse Engineering#Keystore#Cryptography
DEX / SMALI REVERSING
Tested on AOSP 14 & StrongBox TEE
$ frida -U -f com.fintech.app
[*] Injected hook_cipher.js
[✓] Cipher.doFinal() intercepted

Recent Intelligence & Articles

Showing 4 published research articles

Android Security

Deep Dive: Reversing Android Keystore Implementations with Frida

A hands-on walkthrough showing how modern Android applications store sensitive tokens in the Keystore, how hardware-backed TEEs protect them, and how researchers hook Cipher.doFinal() using Frida runtime instrumentation.

#Android#Frida#Reverse Engineering
8 min read
Read
AI Security

The Developer's Guide to Prompt Injection: Anatomy of a Multi-Turn Jailbreak

Generative AI security is not just about polite prompts. We break down the exact mechanics of indirect prompt injection, delimiter overrides, and RAG data exfiltration vectors that bypass naive regex filters.

#LLM#Prompt Injection#AI Security
6 min read
Read
IoT Security

Extracting IoT Firmware with Binwalk & Auditing Hardcoded Shadow Hashes

Learn how hardware hackers dump SPI Flash chips, unpack SquashFS and JFFS2 filesystems with Binwalk, and crack legacy DES/MD5 shadow hashes found on commercial smart devices.

#IoT#Firmware#Binwalk
7 min read
Read
API Security

Hunting BOLA/IDOR in GraphQL Microservices: A Methodology

Broken Object Level Authorization (BOLA) remains the #1 vulnerability on modern APIs. Here is our step-by-step methodology for mapping authorization graphs and discovering cross-tenant data leaks in GraphQL.

#GraphQL#API Security#BOLA
6 min read
Read
COMMUNITY_DISPATCH

Never Miss a 0-Day Breakdown or Lab

We publish practical offensive research, exploit writeups, and defensive patches regularly. All tutorials are 100% free and community-driven.