Research

What we research

Four angles on one question: how does this software fail, and what does that cost the people running it?

Areas

Four ways into the same question

Each page owns the detail for that part of the work. Most projects touch more than one.

  • Exploit Development

    We turn a flaw into something that runs, because that is the only way to know what it is worth.

  • Vulnerability Research

    We look for flaws in software rather than waiting for somebody else's advisory to describe them.

  • Application & API Security Research

    How web applications and the APIs behind them break, and what that means for the people running them.

  • Tooling

    The small, sharp tools that come out of doing the other three.

Published

Nothing yet.

This company is new, it has published no advisories, and it is not going to pretend otherwise.

Work is under way. Until something is finished, reported, and through the window on our disclosure page, there is nothing here to read. A page of ambitions formatted to look like findings would be the first dishonest thing on this site.

  • Advisories

    One per finding, with affected versions, the analysis and the full disclosure timeline.

  • Writeups

    How the bug was found, what failed first, and what it says about its class.

  • Tools

    Released when they are useful to somebody other than us, under a licence that says so.

The first one appears here, with its timeline attached.

How it runs

Target. Find. Prove. Disclose.

The sequence every project follows, including what happens when a window ends with nothing.

How research runsOur disclosure policy

Where we stop

Testing an application you run is Skull Solutions

We research how classes of software fail, not your deployment. If you want your own application reviewed, that is a real service one link away.

See the boundary

Something you want looked at?

Tell us what the target is and what you need to know about it.