Desktops
Thick clients, local privilege boundaries and the update paths nobody audits.
- win32
- ipc
- privesc
independent offensive security
breaking stuff just to see how it works.
I take software apart to find out where it gives. Binaries, protocols, web stacks and the glue between them - the method does not change: read what is actually running rather than what the documentation claims, then keep pulling until something moves.
Work is authorised, scoped in writing, and written up so your own engineers can reproduce every finding without me in the room. Findings go to the vendor first and stay out of public view until a fix ships or the disclosure window closes. Scope drives the number, and the number is fixed before anything starts.
Five surfaces, one habit: find the boundary somebody assumed was solid, then show exactly how far across it an attacker gets.
Thick clients, local privilege boundaries and the update paths nobody audits.
Service daemons, auth boundaries and deploy scripts that grant more than anyone intended.
Hypervisors, container runtimes and the device models where guest input reaches host code.
Routing, segmentation and the management planes left reachable from the wrong side.
Undocumented services, forgotten listeners and ports no asset inventory admits to.
No bars, no percentages, no star ratings - a score against a skill is invented precision. Ask about any line here and you get a straight answer on how deep it goes.
Send the scope, the target class and a timeline. Encrypted if it is sensitive. You get a written answer with a fixed quote, or a clear no.
Work runs against the signed scope inside an agreed window. Anything critical reaches you the day it is found, not in the final report.
The quote is fixed before work starts. Half up front on engagements, the balance on delivery. Invoice, BTC or XMR - whichever suits your finance team.
120+
self-reported, 2019-2026
4200+
self-reported, 2019-2026
90+
vendor first, never brokered
6
sectors named, clients never
Round figures, self-reported across 2019-2026. None of it is an audited metric. Names, logos and anything that would identify a target stay behind the NDA - sector and engagement class is the most that is ever said in public, on this page or anywhere else.
The first command of any engagement is not an exploit. It is a check that the target list in front of me matches the one on the signed document, and a refusal to move if it does not.
The session beside this is illustrative - no live host is contacted, and nothing here runs against anything. It is what the opening five minutes of a scoped assessment actually look like, minus the parts that would identify a client. If you have something you want looked at, send it through the intake form.
whoami
rky - offensive security, independent. authorised work only.
cat scope.txt
targets: 2 · window: 14d · retest: included · signed: yes
in scope: one binary, one staging api. nothing else.
./triage --dry-run scope.txt
2 targets parsed · 0 hosts contacted · dry run, nothing sent
the harness refuses to move until scope.txt matches the signed copy.
next step
Send scope and a timeline. You get a written answer with a fixed quote, or a clear no.