Offensive security research · Melbourne, AU

We break complex software.
Then prove the impact.

Vulnerability research and exploit development targeting the software people, businesses, and critical systems depend on.

  • Enterprise
  • ICS / SCADA
  • IoT
  • File formats
357Published advisories
19Public exploits
300+RCE cases reported
18+Years publishing

Research practice

From attack surface
to working exploit.

We combine manual reverse engineering, purpose-built automation, and exploit engineering to turn subtle implementation flaws into clear, reproducible security impact.

01 / MAP

Reverse

Deconstruct proprietary software, protocols, parsers, and trust boundaries.

02 / FIND

Discover

Use targeted tooling and manual review to surface high-impact flaws.

03 / PROVE

Prove

Turn primitives into reproducible proof-of-concept exploits and full chains that establish true severity for the vendor.

04 / DELIVER

Disclose

Coordinate disclosure with the affected vendor through the Zero Day Initiative, or deliver verified findings to the client who commissioned the research on their own products, under written authorisation.

Field notes

Selected research

View all research

Research track record

Most Prolific Researcher.
Built on repeatable results.

Recipient of the 2025 ZDI Vanguard Award, recognising more than 300 remote code execution vulnerabilities reported through the Zero Day Initiative.

Read the story

Research & engagements

Have a difficult target?

For vulnerability research, exploit development, R&D projects, or tailored security engagements undertaken under written authorisation.

rocco@tecsecurity.io