solutions
We don’t just use tools — we build them. This is where we publish the offensive-security utilities, frameworks and research we develop in-house to push our engagements further. Open-source releases and write-ups land here as they ship.
agent_harness
Automated red-team harness for autonomous AI agents — orchestrates prompt-injection, tool-abuse and goal-hijack test suites against LLM-driven systems.
activesurface_mapper
Continuous external attack-surface discovery: subdomain, service and secret enumeration fused into a single live exposure graph.
activemcp_breaker
Test-bench for Model Context Protocol servers — fuzzes tool schemas and hunts confused-deputy and privilege-scope flaws in agent tool-chains.
betainjection_zoo
A living corpus of direct and indirect prompt-injection payloads and RAG-poisoning techniques, curated from live engagements.
researchmore tools and research via the blog.