Find it before they do

Hacker Bob is an open-source, Apache-2.0 autonomous offensive-security engine that continuously attacks a company's own systems. It has produced 15 credited CVE IDs across 8 projects, and our research is recognized in the Coordinated Vulnerability Disclosure Halls of Fame of VU Amsterdam, UvA, and HvA.
Credited findings

Where the bugs were

  • stable-diffusion.cpp
  • netatalk
  • libcupsfilters
  • libheif
  • OpenSSH
  • Samba
  • rpcbind
  • OpenEXR

Web applications & APIs

The surface every company exposes first — and the one agents can probe relentlessly without getting tired.

Open-source native code

Where the CVEs come from: memory-unsafe parsers, network daemons, and the code everyone trusts because everyone uses it.

Smart contracts

Code that holds money is code that gets attacked. Bob treats a contract like any other target — with receipts.

More

Dig deeper

Research site, the code, and the company — in that order.

Research site → · GitHub → · Engagements →