Blackstorm Security is a specialized offensive research firm. Our core practice is vulnerability research and exploit development against modern, hardened targets — the work that demands deep platform internals knowledge, original research and engineering discipline.
Everything else we do grows out of that same expertise.
Vulnerability Research
Exploit Development & Acquisition
Reverse Engineering & Malware Analysis
Incident Response & Threat Hunting
Vulnerability Research and Exploit Development
We conduct original vulnerability research and develop reliable, fully weaponized exploits on the following platforms:
- iOS — userland and kernel research against current mitigations.
- Android — userland, kernel and privileged system services.
- Google Chrome — renderer exploitation, sandbox escape and full chains.
- Windows — kernel, userland and applications running on Windows.
- Hypervisors — guest-to-host escape research.
Our work covers the complete cycle: target selection and attack surface mapping, fuzzing and manual auditing, root cause analysis, exploitation strategy against modern mitigations, and delivery of a documented, reproducible and reliable capability.
Exploit Development and Acquisition
We develop capabilities exclusively for democratic governments and established brokers, under strictly defined engagement terms.
- Development of exploits under contract, according to the target and requirements defined by the client.
- Acquisition and brokering of exploits produced by our own research.
- Reliability engineering, mitigation bypass and long-term maintenance of delivered chains.
- Full technical documentation and reproduction environment provided with every delivery.
Every engagement is scoped individually and handled with the discretion this domain requires.
Reverse Engineering and Malware Analysis
Complete reverse engineering of binaries, drivers, firmware and malicious artifacts, including advanced threats that defeat conventional analysis.
- Static and dynamic analysis of complex and heavily obfuscated samples.
- Unpacking, deobfuscation and anti-analysis bypass.
- Reverse engineering of proprietary protocols, file formats and closed-source components.
- Capability assessment, attribution indicators and detailed technical reporting.
Incident Response and Threat Hunting
Investigation of intrusions and advanced threats, supported by the same low-level expertise we apply to research.
- Scoping interviews, identification and isolation of affected systems.
- Memory, disk, hibernation file, pagefile and network evidence acquisition.
- Forensic analysis and event correlation across memory, disk, network and malware artifacts.
- Firmware vulnerability assessment.
- Threat removal, technical reporting and executive presentation of results.
Technical Training
Highly technical training delivered by active researchers, covering vulnerability research, exploit development, reverse engineering, malware analysis and systems programming.
Our full course catalog, schedule and detailed syllabi are available on the training page.
How an Engagement Works
-
Non-disclosure agreement
Nothing technical is discussed before it is signed. This is absolute in exploit development work, and it protects both sides: your exposure stays confidential, and our methods stay ours. -
Scoping
Done case by case. There is no rate card, because the work varies too much for one — a single application audit and a full-chain capability against a hardened mobile platform have almost nothing in common in effort, duration or risk. We would rather spend time understanding the target properly than quote a number neither of us can stand behind. -
Delivery
The completed research or capability, a full written technical report documenting what was done and how, and — where it is useful — a presentation of the results to your technical team or leadership, so the findings are genuinely understood rather than filed.
Advisory and Lectures
- Executive and technical advisory on offensive security, research programs and capability development.
- Technical feasibility analysis and support for proofs of concept.
- Evaluation and formation of specialized technical teams.
- Lectures on technical topics, security awareness, and privacy and security.