Blackstorm Security is a boutique research firm specialized in vulnerability research and exploit development against iOS, Android, Google Chrome, Windows and hypervisors — and we teach the same discipline we practise. Our training has become the reference in the field.
What we do
Original research first. Everything else we offer is built on the same low-level expertise.
Vulnerability Research & Exploit Development
Attack surface mapping, fuzzing, manual auditing, root cause analysis and reliable exploitation against current mitigations.
Exploit Development & Acquisition
Capabilities developed exclusively for democratic governments and established brokers, under strictly defined engagement terms.
Reverse Engineering & Malware Analysis
Binaries, drivers, firmware and heavily obfuscated threats that defeat conventional analysis.
Incident Response & Threat Hunting
Intrusions and advanced threats investigated with the same low-level expertise we apply to breaking systems.
Learn to break what everyone else trusts
More than twenty deeply technical courses in vulnerability research, exploit development, reverse engineering and malware analysis — taught by researchers who are actively doing this work, not describing it. Online or in-person, in English or Portuguese, with certification for completed tracks.
Vulnerability Research & Exploitation
Windows Exploit Development 1–3, Fuzzing, Secure Code, Assembly.
Reverse Engineering
Assembly x64/x86, Malware Analysis 1–3, Malicious Documents, Non-Binary Analysis.
Mobile Security Research
iOS Security Research, Android Security Research, ARM Assembly.
Windows Internals & Programming
Windows Internals, C Windows System Programming 1–2.
Incident Response & Threat Hunting
IR and Threat Hunting 1–2, Ransomware Investigation, Network Threat Analysis, Crash Dump Analysis.
Certification
Prove real-world capability. Exams across threat hunting, reverse engineering, mobile and exploit development tracks.
The work behind all of it
Our services and our courses come from the same place: original research, published openly and free of charge. Nothing we teach or deliver is theory we have not practised ourselves. These are the most recent releases — open any card for the full briefing and the PDF.
Exploitation Techniques | CVE-2024-30085 (part 03)
Closes the CVE-2024-30085 exploitation arc with two editions that move beyond token stealing and I/O Ring. The PreviousMode edition flips a single byte in …
Exploitation Techniques | CVE-2024-30085 (part 02)
Focuses exclusively on two further I/O Ring exploit variations against the same cldflt.sys vulnerability. Technique 02 uses I/O Ring for both read and write, …
Exploitation Techniques | CVE-2024-30085 (part 01)
Continues the cldflt.sys minifilter analysis begun in ERS 06, reusing the same n-day as a reference platform for new exploitation techniques rather than introducing …
A Deep Dive Into Exploiting a Minifilter Driver (N-day)
A fully practical, end-to-end exploitation of a real Windows minifilter driver: CVE-2024-30085, a heap buffer overflow in cldflt.sys fixed by KB5039212. It covers …
Hyper-V (part 01)
The first installment of a multi-part series on hypervisors, establishing a working understanding of hypervisor concepts using Microsoft Hyper-V as the reference …
macOS/iOS (part 01)
An introductory review of macOS and iOS internals aimed at vulnerability research. It covers acquiring and unpacking IPSW firmware, extracting and parsing the …
Chrome (part 01)
An introductory, step-by-step study of Google Chrome and in particular its V8 JavaScript and WebAssembly engine. It covers building V8 and the d8 shell from source …
Windows Kernel Drivers (part 02)
A step-by-step patch-diffing walkthrough built around CVE-2022-35804, the SMB Client and Server remote code execution vulnerability. It documents the full workflow: …
Bring us the problem nobody else could solve
Scanners produce findings. Finding a vulnerability nobody has found before, proving it is exploitable, and understanding exactly what an attacker could do with it is a different discipline — and it is the only one we practise.
- Exploit development and vulnerability research — full-chain research against iOS, Android, Chrome, Windows and hypervisors, delivered as reliable, documented capabilities.
- Reverse engineering and malware analysis — the threats that defeat conventional analysis — packed, obfuscated, kernel-resident, or buried in firmware.
- Incident response and threat hunting — intrusions investigated with the same low-level expertise we apply to breaking systems in the first place.
If your problem needs researchers rather than a report, we should talk. Every engagement is scoped individually and handled with complete discretion.