// security tools & in-house research

solutions

Beyond client work, we build our own security tooling and research. This is where our Cyprus team publishes the offensive-security utilities and frameworks we develop in-house, along with write-ups and open-source releases as they ship.

// framework

agent_harness

In-house red-team harness for autonomous AI agents — runs prompt-injection, tool-abuse and goal-hijack suites against the LLM systems we assess for clients.

active
// recon

surface_mapper

Continuous external attack-surface discovery — subdomain, service and secret enumeration merged into a single live exposure view.

active
// exploitation

mcp_breaker

A test-bench for Model Context Protocol servers that fuzzes tool schemas and hunts confused-deputy and scope flaws in agent tool-chains.

beta
// utility

injection_zoo

A living library of direct and indirect prompt-injection and RAG-poisoning techniques, curated from real engagements.

research

more tools and research via the blog.