Scope over volume
Scanners find what is already known and named. The findings that matter come from sitting with a system long enough to ask questions a tool cannot frame.

NoctuaSec conducts authorized security assessments – authorization logic and access control, in web applications and in physical and hardware systems – alongside published research on cyber conflict and defense policy.
An assessment is only as good as the evidence behind it.
Scanners find what is already known and named. The findings that matter come from sitting with a system long enough to ask questions a tool cannot frame.
A narrow assessment done properly is worth more than broad coverage done quickly. We would rather examine one area to the end than survey five.
Service interfaces of electronic locks, RFID/NFC card cryptography, hardware memory extraction where authorized, compensating controls review. 5–9 days, on-site or with a sample unit provided.
Authorization logic, role and permission boundaries, privilege escalation, object-level access control, exposure of administrative functions. 4–6 days, remote, staging preferred.
Verification that reported vulnerabilities are resolved, bypass attempts against the implemented fixes, review of the updated access matrix. 1–2 days, remote.
Scoped consulting on authorization and access control design, threat modeling for a specific system, technical review of assessment scopes.

Nine days, authorized. Three vectors: electronic lock service interfaces (Onity HT series), RFID/NFC key card cryptography (MIFARE Ultralight C, 2K3DES), and EEPROM extraction over I2C. Several existing controls held. Of six findings, five are architectural and cannot be closed by configuration alone. Formal acknowledgment issued by the facility director.

Two weeks, authorized. An application handling patient medical records, operated by a development company on behalf of healthcare providers. Five findings — three critical, two high. Privilege escalation from a standard user account to full administrative takeover, exposing personal and medical data across the entire user base. Remediation initiated. Written acknowledgment from the CEO.

Two months, four-member team, mentored by Gynvael Coldwind (ex-Google, Dragon Sector). Full engagement lifecycle: OSINT, initial access, persistence, command-and-control. Custom tooling built in-house — a C# multi-stage backdoor with registry-key persistence, Telegram-based C2, and anti-sandbox evasion. All techniques mapped to MITRE ATT&CK, delivered with a structured debrief.
Convening, writing, and pro bono engagements where the work serves a clear public interest.
Statecraft, Big Tech & Global Defense
“The classical understanding of state sovereignty is being challenged. States now must actively ask for permission to use private capabilities for defensive purposes.”
The 2026 forum supported Superhumans Center.
A Ukrainian organization providing medical rehabilitation for individuals injured during the war.
Engagement inquiries are reviewed individually

We respond to every serious inquiry within two business days. Initial conversations are confidential and without obligation. Encrypted channels available on request.