Research

Research is at the core of who we are and everything we do. Public output from the team: vulnerabilities we’ve disclosed, talks we’ve given and tools we’ve released, with the bigger bodies of work collected as projects.

Featured

Latest posts all 3 →

last: Oct 2024

post

Finding Vulnerability Variants at Scale

While performing a security audit, I discovered a file format vulnerability that took me down an unexpected rabbit hole. The bug was fairly straightforward but what made it interesting was its origin …

Franco Belman

post

Playing with Libmalloc in 2024

TL;DR In this post, I introduce a new tool called heapster that allows you to play with macOS libmalloc. I walk you through how to use this tool and a couple strange things I found along the way.

Josh Pitts

post

A Touch of Pwn - Part I

TL;DR Microsoft’s Offensive Research and Security Engineering (MORSE) asked us to evaluate the security of the top three fingerprint sensors embedded in laptops and used for Windows Hello fingerprint …

Jesse D'Aguanno, Timo Teräs

Latest advisories

Our first advisories are in coordinated disclosure and will appear here as they go public.

Talks all 5 →

last: Oct 2023

talk

NFC Hacking: The Easy Way

DEF CON 20 · Las Vegas, NV

Eddie Lee presents NFCProxy, a proof-of-concept tool that demonstrates insecurities in near field communication and contactless credit cards. The tool is also useful for NFC protocol analysis in …

slidestool Eddie Lee

talk

IRK: Crafting OS X Kernel Rootkits

Black Hat USA 2008 · Las Vegas, NV

Apple’s OS X operating system has been gaining in popularity. This presentation details how to manipulate the OS X kernel in order to hide an attacker’s activities and maintain access.

slides Jesse D'Aguanno

Tools all 3 →

last: Jan 2024

tool

heapster

Python

A tool for exploring the macOS libmalloc heap from LLDB: zones, magazines, free lists and the state of individual allocations, introduced in our libmalloc post.

sourcewrite-up Blackwing

tool

iBoot64Binja

Python

A Binary Ninja binary view for iBoot, SecureROM and similar Apple boot firmware. Point it at a raw image and it identifies the firmware, finds the load address and rebases the binary so analysis is …

source Jesse D'Aguanno

tool

NFCProxy

Java (Android) · archived

An Android app that proxies NFC transactions between a contactless card and a reader, for demonstrating relay attacks and analysing NFC protocols. Presented at DEF CON 20.

sourcetalk Eddie Lee

Themes

platform & os 8hardware & firmware 6applied cryptography 3