Research
What we research
Four angles on one question: how does this software fail, and what does that cost the people running it?
Areas
Four ways into the same question
Each page owns the detail for that part of the work. Most projects touch more than one.
-
Exploit Development
We turn a flaw into something that runs, because that is the only way to know what it is worth.
-
Vulnerability Research
We look for flaws in software rather than waiting for somebody else's advisory to describe them.
-
Application & API Security Research
How web applications and the APIs behind them break, and what that means for the people running them.
-
Tooling
The small, sharp tools that come out of doing the other three.
Published
Nothing yet.
This company is new, it has published no advisories, and it is not going to pretend otherwise.
Work is under way. Until something is finished, reported, and through the window on our disclosure page, there is nothing here to read. A page of ambitions formatted to look like findings would be the first dishonest thing on this site.
-
Advisories
One per finding, with affected versions, the analysis and the full disclosure timeline.
-
Writeups
How the bug was found, what failed first, and what it says about its class.
-
Tools
Released when they are useful to somebody other than us, under a licence that says so.
The first one appears here, with its timeline attached.
How it runs
Target. Find. Prove. Disclose.
The sequence every project follows, including what happens when a window ends with nothing.
Where we stop
Testing an application you run is Skull Solutions
We research how classes of software fail, not your deployment. If you want your own application reviewed, that is a real service one link away.
Something you want looked at?
Tell us what the target is and what you need to know about it.