Blackstorm Security is a boutique offensive security research firm, founded in 2017 on a single principle: depth over breadth. We chose the hardest problems in the field — finding original vulnerabilities in modern, hardened software and turning them into reliable exploits — and we have done nothing else since.
That focus is deliberate. The security market is crowded with generalists. Very few teams can read a kernel driver, follow a bug from a crash to a working privilege escalation against current mitigations, and explain every step of it afterwards. That is the work we do, and it is the work we teach.
What We Do
We conduct vulnerability research and exploit development against iOS, Android, Google Chrome, Windows and hypervisors, delivering complete, documented capabilities to democratic governments and established brokers. The same expertise drives our reverse engineering and malware analysis practice, and our incident response and threat hunting work — because understanding how systems are broken is what makes it possible to investigate how they were broken.
Alongside that, we deliver more than twenty highly technical courses and a portfolio of professional certifications, taught by researchers who are actively doing this work, not describing it.
Research in the Open
We publish. Our research — the Exploiting Reversing (ERS) and Malware Analysis (MAS) series — runs to 19 articles and over 1,600 pages, released free of charge and used as reference material by researchers worldwide.
This matters more than it might appear. Anyone can claim expertise in this field; very few will publish their methodology in full detail, at length, where the whole community can check it. Our research is our credential, and it is available to anyone who wants to verify what we are capable of before hiring or training with us.
Books
Gray Hat Hacking, Seventh Edition. Alexandre Borges is one of the co-authors of the seventh edition, to be published by McGraw-Hill Education in mid-2027.
Writing for that audience demands exactly what our courses do: a technique explained precisely enough that a reader can reproduce it, rather than described well enough that it sounds convincing.
Where We Have Spoken
Our research is presented at the conferences where this field is actually argued out.
- DEF CON (USA)
- DEF CON China
- Hack In The Box
- NO HAT
- SANS
- CONFidence
- H2HC
- BSides
How We Work
Nothing we teach is theory we have not practised. Course material comes out of real engagements and real research. When we explain a technique, we have used it.
We prove our findings. A vulnerability is not reported until it is reduced to a root cause and demonstrated with working code. We deliver reproducible results, not speculation.
We are selective and we are discreet. Engagements are scoped individually, handled under strict terms, and never discussed. Given the nature of our work, we decline engagements that fall outside the scope we have defined for ourselves.
We keep improving. Every course is revised, every article is refined, and every technique is retested against current mitigations. Software changes constantly, and research that is not maintained becomes worthless quickly.
Our Mission
To provide differentiated services for companies and governments, and training for hackers.
From professionals to professionals.
To discuss an engagement, training, or a private class, write to us from your corporate email address: contact@blackstormsecurity.com