The reading room

Research on AI attack techniques and offensive security

How we think about what we test, written up with the framework ids attached. Every piece answers its question in the first paragraph, cites its sources in the margin, and ends with what to do about it.

Published
8
Method
V1.0
Advisories
0

Published research

How we write

  1. Own lab, or already fixed

    We write about systems we built to be broken, or about public issues their vendors have already fixed. Never about a client.

  2. Ids checked at the source

    Every OWASP and MITRE ATLAS id is checked against the publisher’s own document before it is printed, with the edition attached.

  3. A source for every fact

    Every factual sentence carries a numbered note in the margin, and every note names a document you can open and check.

  4. Defensive by design

    We explain how a risk works, what it costs and how to test for it at the level of structure. No payloads, no recipes.

  5. Ends with the fix

    Every piece closes on the controls that would have stopped the attack, and on what they do not stop.

  6. Reviewed before launch

    A named security lead reviews each piece before it is published. Until then its byline says the review is pending.

Found a vulnerability in something we wrote about, or in this site? Our disclosure policy says how to reach us, and advisories explains how we publish our own.