AppSec
research lab

Weekly analyses of the vulnerabilities, exploits, and attack patterns that matter — what the bug is, who's exposed, and what to do about it before Monday. We track what attackers are doing, not what scanners flag.

research threads

What we research

Three threads: offensive, defensive, and in-the-wild exploits — published weekly in the hub.

5M+

Findings analyzed

20+

Teams we've worked with

80K+

Scans reviewed per month

700+

Detection rules designed
the team's track record

Decade-scale AppSec experience

Cumulative across our security engineers' careers — findings analyzed, scans reviewed, rules shipped in production. The experience we bring into the research.

Integrations

Tools we study

Our analyses cover the behavior, blind spots, and detection coverage of commercial and open-source security tools — so readers know what each one sees.

Whitepaper

Worth reading, even if we didn't write it

GitLab's whitepaper explains why four of the top six breach categories are application-based. Twenty minutes of your team's time.

Research hub

Latest analyses