// r&d — internal tooling

our developments

We don't just use tools — we build them. Below is a selection of the offensive frameworks, agents and research projects developed in-house to push our engagements further.

// framework

agent_harness

Automated red-team harness for autonomous AI agents — orchestrates prompt-injection, tool-abuse and goal-hijack test suites against LLM-driven systems.

active
// recon

surface_mapper

Continuous external attack-surface discovery: subdomain, service and secret enumeration fused into a single live exposure graph.

active
// exploitation

mcp_breaker

Test-bench for Model Context Protocol servers — fuzzes tool schemas and hunts confused-deputy and privilege-scope flaws in agent tool-chains.

beta
// research

injection_zoo

A living corpus of direct and indirect prompt-injection payloads and RAG-poisoning techniques, curated from live engagements.

research

more tooling released via the blog.