Offensive Intelligence &
Security Deep-Dives.
Hands-on vulnerability writeups, binary reverse-engineering walkthroughs, and practical defensive playbooks written directly by our security researchers.
Deep Dive: Reversing Android Keystore Implementations with Frida
A hands-on walkthrough showing how modern Android applications store sensitive tokens in the Keystore, how hardware-backed TEEs protect them, and how researchers hook Cipher.doFinal() using Frida runtime instrumentation.
Recent Intelligence & Articles
Showing 4 published research articles
Deep Dive: Reversing Android Keystore Implementations with Frida
A hands-on walkthrough showing how modern Android applications store sensitive tokens in the Keystore, how hardware-backed TEEs protect them, and how researchers hook Cipher.doFinal() using Frida runtime instrumentation.
The Developer's Guide to Prompt Injection: Anatomy of a Multi-Turn Jailbreak
Generative AI security is not just about polite prompts. We break down the exact mechanics of indirect prompt injection, delimiter overrides, and RAG data exfiltration vectors that bypass naive regex filters.
Extracting IoT Firmware with Binwalk & Auditing Hardcoded Shadow Hashes
Learn how hardware hackers dump SPI Flash chips, unpack SquashFS and JFFS2 filesystems with Binwalk, and crack legacy DES/MD5 shadow hashes found on commercial smart devices.
Hunting BOLA/IDOR in GraphQL Microservices: A Methodology
Broken Object Level Authorization (BOLA) remains the #1 vulnerability on modern APIs. Here is our step-by-step methodology for mapping authorization graphs and discovering cross-tenant data leaks in GraphQL.
