Research & Writeups
Security research, vulnerability analysis, and technical writeups from real engagements and lab work.
Building radio fingerprints from timing, power, and IQ features without decrypting a single voice frame. A passive analysis technique using commodity SDR hardware.
Read More →Auditing 158 MCP tools for injection vectors — prompt poisoning, parameter manipulation, and exfiltration paths.
Testing Samsung S24 resistance to concurrent deauth and CSA attacks with PMF enabled. Spoiler: the client is immune.
A methodical audit of a Cox residential segment — gateway, switch, NAS, smart TV, and everything in between.
Passive identification of DES-OFB, AES-256, and cleartext talkgroups using control channel metadata and ESS analysis.
Building pixel-perfect captive portals, deploying on a WiFi Pineapple, and documenting the detection signatures defenders should look for.
Configuring srsRAN on a USRP B210 to simulate a rogue eNodeB — and testing Rayhunter detection capabilities.
We do responsible disclosure. If you've found something, reach out.
Contact Us